<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel xmlns:atom="http://www.w3.org/2005/Atom"><title>Blogwitch</title><link>http://bogwitch.blog.co.uk/</link><atom:link xmlns:atom="http://www.w3.org/2005/Atom" rel="self" href="http://bogwitch.blog.co.uk/feed/rss2/posts/"/><description></description><language>en-EU</language><generator>MokoFeed</generator><ttl>10</ttl><image><title>Blogwitch</title><link>http://bogwitch.blog.co.uk/</link><url>http://data5.blog.de/design/preview/90/cb363726741b8da7ed6be84e228627_160x200.jpg</url></image><item><title>USBDumper - analysis</title><link>http://bogwitch.blog.co.uk/2006/10/04/usbdumper_analysis~1187123/</link><guid isPermaLink="false">tag:bogwitch.blog.co.uk,2006-10-04:/2006/10/04/usbdumper_analysis~1187123/</guid><pubDate>Wed, 04 Oct 2006 14:05:01 +0200</pubDate><description>	&lt;p&gt;Test platform MS Win2k.&lt;br&gt;
The executable is distributed with source code. I did not re-compile but gave the source a very cursory glance over. Nothing immeditately jumped out at me but remember, I am not a hugely experienced programmer.&lt;br&gt;
InCtrl5 listed no registry entries changed and no files added. The USBDumper executable is clearly visible in Task Manager.&lt;br&gt;
The process has not shown any signs thus far of attempting to access any network facilities.&lt;br&gt;
It does what it claims. In the directory from which it was executed, it creates a folder of todays date and copies the information from the USB memory device into it. If the folder exists the files from the key are copied into it.&lt;br&gt;
It does not always work. My Dell 16MB key - it always copies the data off. My 1GB key - no joy. Both are FAT formatted, I will need to find my NTFS formatted key before I can test.&lt;/p&gt;
	&lt;p&gt;Requires a little more investigation.&lt;/p&gt;
&lt;p&gt; &lt;small&gt; &lt;a href="http://bogwitch.blog.co.uk/2006/10/04/usbdumper_analysis~1187123/#comments"&gt;Comments&lt;/a&gt; &lt;/small&gt; &lt;/p&gt;</description><category>usbdumper</category><category>inctrl5</category><category>analysis</category><comments>http://bogwitch.blog.co.uk/2006/10/04/usbdumper_analysis~1187123/#comments</comments></item><item><title>Not happy with McAfee</title><link>http://bogwitch.blog.co.uk/2006/10/03/not_happy_with_mcafee~1184688/</link><guid isPermaLink="false">tag:bogwitch.blog.co.uk,2006-10-03:/2006/10/03/not_happy_with_mcafee~1184688/</guid><pubDate>Tue, 03 Oct 2006 18:26:59 +0200</pubDate><description>	&lt;p&gt;OK, McAfee has been detecting the 'psexec.exe' tool from Sysinternals (http://www.sysinternals.com) as 'Unwanted Programs' and as default, automatically deleting it. Since I am using a corporate license at work, I do not have a support contract number easily available to me so I emailed 'Customer Service' to explain that they were detecting (now) Microsoft software as malware. Apparently it is a job for technical support and they were unable, or more likely unwilling, to pass the information on.&lt;br&gt;
So, that will be the last time I contact McAfee directly and they will be removed from my malicious code submission list. I don't suppose they are bothered.&lt;/p&gt;
&lt;p&gt; &lt;small&gt; &lt;a href="http://bogwitch.blog.co.uk/2006/10/03/not_happy_with_mcafee~1184688/#comments"&gt;Comments&lt;/a&gt; &lt;/small&gt; &lt;/p&gt;</description><category>poor-customer-service</category><category>psexec</category><category>sysinternals</category><category>mcafee</category><category>false-detection</category><comments>http://bogwitch.blog.co.uk/2006/10/03/not_happy_with_mcafee~1184688/#comments</comments></item><item><title>USBDumper</title><link>http://bogwitch.blog.co.uk/2006/10/03/usbdumper~1184280/</link><guid isPermaLink="false">tag:bogwitch.blog.co.uk,2006-10-03:/2006/10/03/usbdumper~1184280/</guid><pubDate>Tue, 03 Oct 2006 16:22:40 +0200</pubDate><description>	&lt;p&gt;Not the easiest bit of software to find, I got it here: &lt;a href="http://www.secuobs.com/USBDumper.rar"&gt;http://www.secuobs.com/USBDumper.rar&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;I have not subjected it to my usual testing as my sandbox is not available to me right now, I'll get it tested hopefully by tomorrow. Until then, treat as highly suspicious!&lt;/p&gt;
&lt;p&gt; &lt;small&gt; &lt;a href="http://bogwitch.blog.co.uk/2006/10/03/usbdumper~1184280/#comments"&gt;Comments&lt;/a&gt; &lt;/small&gt; &lt;/p&gt;</description><category>usbdumper</category><category>security</category><comments>http://bogwitch.blog.co.uk/2006/10/03/usbdumper~1184280/#comments</comments></item><item><title>Infomation Assurance</title><link>http://bogwitch.blog.co.uk/2006/09/12/infomation_assurance~1119758/</link><guid isPermaLink="false">tag:bogwitch.blog.co.uk,2006-09-12:/2006/09/12/infomation_assurance~1119758/</guid><pubDate>Tue, 12 Sep 2006 17:25:28 +0200</pubDate><description>	&lt;p&gt;I am on an Information Assurance course this week so I doub't I'll see any new software this week.&lt;/p&gt;
	&lt;p&gt;I was pointed to Google mirror today.&lt;/p&gt;
	&lt;p&gt;&lt;a href="http://elgoog.rb-hosting.de/index.cgi"&gt;http://elgoog.rb-hosting.de/index.cgi&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;When I get back to work, I'd better check our content filter has this at least categorised and hopefully blocked!
&lt;/p&gt;
&lt;p&gt; &lt;small&gt; &lt;a href="http://bogwitch.blog.co.uk/2006/09/12/infomation_assurance~1119758/#comments"&gt;Comments&lt;/a&gt; &lt;/small&gt; &lt;/p&gt;</description><category>weblink</category><comments>http://bogwitch.blog.co.uk/2006/09/12/infomation_assurance~1119758/#comments</comments></item><item><title>HIjackThis</title><link>http://bogwitch.blog.co.uk/2006/09/07/hijackthis~1106741/</link><guid isPermaLink="false">tag:bogwitch.blog.co.uk,2006-09-07:/2006/09/07/hijackthis~1106741/</guid><pubDate>Thu, 07 Sep 2006 23:57:04 +0200</pubDate><description>	&lt;p&gt;&lt;a href="http://www.merijn.org/files/hijackthis.zip"&gt;http://www.merijn.org/files/hijackthis.zip&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;HijackThis, don't forget ibprocman while you're there.
&lt;/p&gt;
&lt;p&gt; &lt;small&gt; &lt;a href="http://bogwitch.blog.co.uk/2006/09/07/hijackthis~1106741/#comments"&gt;Comments&lt;/a&gt; &lt;/small&gt; &lt;/p&gt;</description><category>investigate</category><comments>http://bogwitch.blog.co.uk/2006/09/07/hijackthis~1106741/#comments</comments></item><item><title>Tiny KeyLogger</title><link>http://bogwitch.blog.co.uk/2006/09/07/tiny_keylogger~1105168/</link><guid isPermaLink="false">tag:bogwitch.blog.co.uk,2006-09-07:/2006/09/07/tiny_keylogger~1105168/</guid><pubDate>Thu, 07 Sep 2006 14:58:11 +0200</pubDate><description>	&lt;p&gt;&lt;a href="http://home.rochester.rr.com/artcfox/TinyKL/TinyKL.exe"&gt;http://home.rochester.rr.com/artcfox/TinyKL/TinyKL.exe&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;Watch out! Make sure you have written consent for the installation of ANY keylogger. This one is great as it's: 1. free 2. small 3. can be easily renamed.&lt;/p&gt;
	&lt;p&gt;Downside is, some AV software identifies it as a virus/ malware.
&lt;/p&gt;
&lt;p&gt; &lt;small&gt; &lt;a href="http://bogwitch.blog.co.uk/2006/09/07/tiny_keylogger~1105168/#comments"&gt;Comments&lt;/a&gt; &lt;/small&gt; &lt;/p&gt;</description><category>keylogger</category><category>monitor</category><comments>http://bogwitch.blog.co.uk/2006/09/07/tiny_keylogger~1105168/#comments</comments></item><item><title>Atguard personal firewall</title><link>http://bogwitch.blog.co.uk/2006/09/06/atguard_personal_firewall~1103580/</link><guid isPermaLink="false">tag:bogwitch.blog.co.uk,2006-09-06:/2006/09/06/atguard_personal_firewall~1103580/</guid><pubDate>Wed, 06 Sep 2006 22:17:26 +0200</pubDate><description>	&lt;p&gt;&lt;a href="http://www.es.embnet.org/Services/ftp/misc/Crypt/ftp.hacktic.nl/security/firewall/at_guard/atgd322.exe"&gt;http://www.es.embnet.org/Services/ftp/misc/Crypt/ftp.hacktic.nl/security/firewall/at_guard/atgd322.exe&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;NB AtGuard will probably seriously affect your http transfers with Windows2000 SP4 unless you copy the SP3 tcpip.sys over the SP4 versions. I've read that it loses the logging function under XP too but I'm not using XP so I don't care!
&lt;/p&gt;
&lt;p&gt; &lt;small&gt; &lt;a href="http://bogwitch.blog.co.uk/2006/09/06/atguard_personal_firewall~1103580/#comments"&gt;Comments&lt;/a&gt; &lt;/small&gt; &lt;/p&gt;</description><category>firewall</category><category>atguard</category><comments>http://bogwitch.blog.co.uk/2006/09/06/atguard_personal_firewall~1103580/#comments</comments></item><item><title>Inctrl5</title><link>http://bogwitch.blog.co.uk/2006/09/06/inctrl5~1103533/</link><guid isPermaLink="false">tag:bogwitch.blog.co.uk,2006-09-06:/2006/09/06/inctrl5~1103533/</guid><pubDate>Wed, 06 Sep 2006 22:00:52 +0200</pubDate><description>	&lt;p&gt;&lt;a href="http://www.devhood.com/tools/tool_details.aspx?tool_id=432"&gt;http://www.devhood.com/tools/tool_details.aspx?tool_id=432&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;Inctrl5 - system changes monitor.&lt;/p&gt;
&lt;p&gt; &lt;small&gt; &lt;a href="http://bogwitch.blog.co.uk/2006/09/06/inctrl5~1103533/#comments"&gt;Comments&lt;/a&gt; &lt;/small&gt; &lt;/p&gt;</description><category>monitor</category><category>inctrl5</category><comments>http://bogwitch.blog.co.uk/2006/09/06/inctrl5~1103533/#comments</comments></item><item><title>Why am I trying to blog again?</title><link>http://bogwitch.blog.co.uk/2006/09/06/why_am_i_trying_to_blog_again~1103515/</link><guid isPermaLink="false">tag:bogwitch.blog.co.uk,2006-09-06:/2006/09/06/why_am_i_trying_to_blog_again~1103515/</guid><pubDate>Wed, 06 Sep 2006 21:53:37 +0200</pubDate><description>	&lt;p&gt;Yes again. I started a blog before, updated it only a couple of times and now I can't even remember where it was!&lt;br&gt;
OK, so this time I'm planning to go for a security type blog. I'm not intending to publish this to anyone in particular but if you find the information helpful, so much the better.&lt;br&gt;
The real purpose of this will be to keep a record of stuff I need that I can access from wherever I am.
&lt;/p&gt;
&lt;p&gt; &lt;small&gt; &lt;a href="http://bogwitch.blog.co.uk/2006/09/06/why_am_i_trying_to_blog_again~1103515/#comments"&gt;Comments&lt;/a&gt; &lt;/small&gt; &lt;/p&gt;</description><category>intro</category><comments>http://bogwitch.blog.co.uk/2006/09/06/why_am_i_trying_to_blog_again~1103515/#comments</comments></item></channel></rss>
