<feed version="0.3"
      xmlns="http://purl.org/atom/ns#"
      xmlns:dc="http://purl.org/dc/elements/1.1/">
  <author>
    <name>F-Secure Antivirus Research Team</name>
    <email>weblog\@PLEASE-REMOVE-THIS.f-secure.com</email>
  </author>
  <copyright mode="escaped"
             type="text/html">Copyright (c) 2007 F-Secure Corporation. All Rights Reserved.</copyright>
  <entry>
    <id>tag:www.f-secure.com,2013-05-17:%2Fweblog%2Farchives%2F00002556.html</id>
    <author>
      <name>F-Secure Antivirus Research Team</name>
      <email>weblog\@PLEASE-REMOVE-THIS.f-secure.com</email>
    </author>
    <content mode="escaped"
             type="text/html"> 			 			BBC News has a 13 minute report that&amp;apos;s worth a view.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;a href=&amp;quot;http://www.bbc.co.uk/news/technology-22526025&amp;quot;&amp;gt;&amp;lt;img width=&amp;quot;538&amp;quot; height=&amp;quot;544&amp;quot; border=&amp;quot;0&amp;quot; src=&amp;quot;http://www.f-secure.com/weblog/archives/BBC_LulzSec_Interview.png&amp;quot; alt=&amp;quot;LulzSec hacker: Internet is a world devoid of empathy&amp;quot; /&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;a href=&amp;quot;http://www.bbc.co.uk/news/technology-22526025&amp;quot;&amp;gt;LulzSec hacker: &amp;apos;Internet is a world devoid of empathy&amp;apos;&amp;lt;/a&amp;gt; 			 &amp;lt;p&amp;gt;On 17/05/13 At 12:54 PM&amp;lt;/p&amp;gt;</content>
    <issued>2013-05-17T12:56:56Z</issued>
    <link href="http://www.f-secure.com/weblog/archives/00002556.html"
          rel="alternate"
          type="text/html" />
    <modified>2013-05-17T12:56:56Z</modified>
    <title mode="escaped"
           type="text/html">BBC News: LulzSec Hacker Interview</title>
  </entry>
  <entry>
    <id>tag:www.f-secure.com,2013-05-17:%2Fweblog%2Farchives%2F00002555.html</id>
    <author>
      <name>F-Secure Antivirus Research Team</name>
      <email>weblog\@PLEASE-REMOVE-THIS.f-secure.com</email>
    </author>
    <content mode="escaped"
             type="text/html"> 			 			&amp;lt;img width=&amp;quot;540&amp;quot; height=&amp;quot;331&amp;quot; border=&amp;quot;1&amp;quot; src=&amp;quot;http://www.f-secure.com/weblog/archives/lulzsec_tw.PNG&amp;quot; alt=&amp;quot;LulzSec Twitter&amp;quot;&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;LulzSec &amp;amp;ndash; the rockband of hacker groups &amp;amp;ndash; had three of their six members sentenced today in London.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;LulzSec made headlines during their &amp;quot;50 days of Lulz&amp;quot; in May-June 2011, during which they attacked Fox, PBS, Sony, Nintendo, Sega, Minecraft, Infragard, NHS, US Senate, SOCA and CIA. They also recorded and published a conference call between US and European law enforcement officials, discussing police tactics against LulzSec.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;LulzSec was different from most other attackers, as they weren&amp;apos;t doing their attacks to make money or to protest. They did it for Teh Lulz. Also, they had no sense of self-preservation, which led to taking them down.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;LulzSec had 6 core members: &amp;lt;br /&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Topiary aka Jake Davis (&amp;lt;a href=&amp;quot;https://twitter.com/aTopiary&amp;quot;&amp;gt;@aTopiary&amp;lt;/a&amp;gt;), UK&amp;lt;br /&amp;gt;&amp;lt;li&amp;gt;T-Flow aka Mustafa Al-Bassam (&amp;lt;a href=&amp;quot;https://twitter.com/let_it_tflow&amp;quot;&amp;gt;@let_it_tflow&amp;lt;/a&amp;gt;), UK&amp;lt;br /&amp;gt;&amp;lt;li&amp;gt;Kayla aka Ryan Ackroyd (&amp;lt;a href=&amp;quot;https://twitter.com/lolspoon&amp;quot;&amp;gt;@lolspoon&amp;lt;/a&amp;gt;), UK&amp;lt;br /&amp;gt;&amp;lt;li&amp;gt;Sabu aka Hector Monsegur (&amp;lt;a href=&amp;quot;https://twitter.com/anonymouSabu&amp;quot;&amp;gt;@anonymouSabu&amp;lt;/a&amp;gt;), United States&amp;lt;br /&amp;gt;&amp;lt;li&amp;gt;Pwnsauce aka Darren Martyn (&amp;lt;a href=&amp;quot;https://twitter.com/_pwnsauce&amp;quot;&amp;gt;*_pwnsauce&amp;lt;/a&amp;gt;) Ireland&amp;lt;br /&amp;gt;&amp;lt;li&amp;gt;AVunit (&amp;lt;a href=&amp;quot;https://twitter.com/AvunitAnon&amp;quot;&amp;gt;@AvunitAnon&amp;lt;/a&amp;gt;), identity unknown&amp;lt;/ul&amp;gt;&amp;lt;br /&amp;gt;The first three were sentenced today.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Jake Davis got a 24 month sentence. He will serve 12 months in a young offenders institute&amp;lt;br /&amp;gt;&amp;lt;li&amp;gt;Mustafa Al-Bassam got a 20 month sentence, suspended for two years and 300 hours of community work.&amp;lt;br /&amp;gt;&amp;lt;li&amp;gt;Ryan Ackroyd got a 30 month sentence. He will serve 15 months.&amp;lt;/ul&amp;gt;&amp;lt;br /&amp;gt;A botnet master associated with Lulzsec was sentenced at the same time: Ryan Cleary (aka Viral). He got a 32 month sentence. He will serve 16 months.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;Sabu was arrested in June 2011. He pleaded guilty and has been working with FBI since. He&amp;apos;s yet to be sentenced.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;Darren Martyn was indicted in March 2012. He&amp;apos;s yet to be sentenced.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;So, five of the LulzSec six has been caught. The remaining mystery is the 6th member: Avunit. &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;Who was Avunit? How come none of the  other members have given him up? &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;We have no idea who Avunit is. We have no identity. We don&amp;apos;t even know which continent he is from.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;P.S. Obligatory &amp;lt;a href=&amp;quot;http://cwacht.github.io/nyancat/&amp;quot;&amp;gt;nyan.cat&amp;lt;/a&amp;gt;.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;hr&amp;gt; 			 &amp;lt;p&amp;gt;On 16/05/13 At 01:32 PM&amp;lt;/p&amp;gt;</content>
    <issued>2013-05-17T12:56:56Z</issued>
    <link href="http://www.f-secure.com/weblog/archives/00002555.html"
          rel="alternate"
          type="text/html" />
    <modified>2013-05-17T12:56:56Z</modified>
    <title mode="escaped"
           type="text/html">LulzSec Sentencing in UK</title>
  </entry>
  <entry>
    <id>tag:www.f-secure.com,2013-05-17:%2Fweblog%2Farchives%2F00002554.html</id>
    <author>
      <name>F-Secure Antivirus Research Team</name>
      <email>weblog\@PLEASE-REMOVE-THIS.f-secure.com</email>
    </author>
    <content mode="escaped"
             type="text/html"> 			 			The &amp;lt;a href=&amp;quot;http://www.oslofreedomforum.com/&amp;quot;&amp;gt;Oslo Freedom Forum&amp;lt;/a&amp;gt; is an annual event &amp;quot;exploring how best to challenge authoritarianism and promote free and open societies.&amp;quot; This year&amp;apos;s conference (which took place May 13-15) had a workshop for freedom of speech activists on how to secure their devices against government monitoring. During the workshop, &amp;lt;a href=&amp;quot;https://twitter.com/ioerror&amp;quot;&amp;gt;Jacob Appelbaum&amp;lt;/a&amp;gt; actually discovered a new and previously unknown backdoor on an African activist&amp;apos;s Mac.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;Our Mac analyst (Brod) is currently investigating the sample.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;It&amp;apos;s signed with an Apple &amp;lt;a href=&amp;quot;https://developer.apple.com/resources/developer-id/&amp;quot;&amp;gt;Developer ID&amp;lt;/a&amp;gt;.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;img width=&amp;quot;585&amp;quot; height=&amp;quot;282&amp;quot; border=&amp;quot;0&amp;quot; src=&amp;quot;http://www.f-secure.com/weblog/archives/KITM_Apple_Developer_ID.png&amp;quot; alt=&amp;quot;Developer ID&amp;quot; /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;The launch point:&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;img width=&amp;quot;668&amp;quot; height=&amp;quot;504&amp;quot; border=&amp;quot;0&amp;quot; src=&amp;quot;http://www.f-secure.com/weblog/archives/KITM_launchpoint.png&amp;quot; alt=&amp;quot;Launch point&amp;quot; /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;It dumps screenshots into a folder called MacApp:&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;img width=&amp;quot;768&amp;quot; height=&amp;quot;378&amp;quot; border=&amp;quot;0&amp;quot; src=&amp;quot;http://www.f-secure.com/weblog/archives/KITM_screenshot_dump_folder.png&amp;quot; alt=&amp;quot;Screenshot dump folder&amp;quot; /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;Functions:&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;img width=&amp;quot;399&amp;quot; height=&amp;quot;534&amp;quot; border=&amp;quot;0&amp;quot; src=&amp;quot;http://www.f-secure.com/weblog/archives/KITM_Functions.png&amp;quot; alt=&amp;quot;Functions&amp;quot; /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;There are two C&amp;amp;amp;C servers related to this sample:&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;img width=&amp;quot;535&amp;quot; height=&amp;quot;310&amp;quot; border=&amp;quot;0&amp;quot; src=&amp;quot;http://www.f-secure.com/weblog/archives/KITM_domaintools_securitytable_org.png&amp;quot; alt=&amp;quot;DomainTools, securitytable.org&amp;quot; /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;i&amp;gt;securitytable.org&amp;lt;/i&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;img width=&amp;quot;510&amp;quot; height=&amp;quot;310&amp;quot; border=&amp;quot;0&amp;quot; src=&amp;quot;http://www.f-secure.com/weblog/archives/KITM_domaintools_docforum_info.png&amp;quot; alt=&amp;quot;DomainTools, docforum.info&amp;quot; /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;i&amp;gt;docsforum.info&amp;lt;/i&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;One C&amp;amp;amp;C doesn&amp;apos;t currently resolve, and the other:&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;img width=&amp;quot;510&amp;quot; height=&amp;quot;310&amp;quot; border=&amp;quot;0&amp;quot; src=&amp;quot;http://www.f-secure.com/weblog/archives/KITM_docsforum_info.png&amp;quot; alt=&amp;quot;docsforum.info&amp;quot; /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;i&amp;gt;Forbidden&amp;lt;/i&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;Our detection is called: Backdoor: OSX/KitM.A. (SHA1: 4395a2da164e09721700815ea3f816cddb9d676e) 			 &amp;lt;p&amp;gt;On 16/05/13 At 12:29 PM&amp;lt;/p&amp;gt;</content>
    <issued>2013-05-17T12:56:56Z</issued>
    <link href="http://www.f-secure.com/weblog/archives/00002554.html"
          rel="alternate"
          type="text/html" />
    <modified>2013-05-17T12:56:56Z</modified>
    <title mode="escaped"
           type="text/html">Mac Spyware Found at Oslo Freedom Forum</title>
  </entry>
  <entry>
    <id>tag:www.f-secure.com,2013-05-17:%2Fweblog%2Farchives%2F00002553.html</id>
    <author>
      <name>F-Secure Antivirus Research Team</name>
      <email>weblog\@PLEASE-REMOVE-THIS.f-secure.com</email>
    </author>
    <content mode="escaped"
             type="text/html"> 			 			Our &amp;lt;a href=&amp;quot;http://www.f-secure.com/static/doc/labs_global/Research/Mobile_Threat_Report_Q1_2013.pdf&amp;quot;&amp;gt;Mobile Threat Report Q1 2013&amp;lt;/a&amp;gt; is now publicly available.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;img width=&amp;quot;580&amp;quot; height=&amp;quot;735&amp;quot; border=&amp;quot;1&amp;quot; src=&amp;quot;http://www.f-secure.com/weblog/archives/Mobile_Threat_Count_Q1_2013jpg.jpg&amp;quot; alt=&amp;quot;Mobile Threat Count, Q1 2013&amp;quot; /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;All of our &amp;lt;a href=&amp;quot;http://www.f-secure.com/en/web/labs_global/whitepapers/reports&amp;quot;&amp;gt;past reports&amp;lt;/a&amp;gt; are also available in the &amp;quot;&amp;lt;a href=&amp;quot;http://www.f-secure.com/en/web/labs_global/&amp;quot;&amp;gt;Labs&amp;lt;/a&amp;gt;&amp;quot; section of f-secure.com. 			 &amp;lt;p&amp;gt;On 15/05/13 At 12:45 PM&amp;lt;/p&amp;gt;</content>
    <issued>2013-05-17T12:56:56Z</issued>
    <link href="http://www.f-secure.com/weblog/archives/00002553.html"
          rel="alternate"
          type="text/html" />
    <modified>2013-05-17T12:56:56Z</modified>
    <title mode="escaped"
           type="text/html">Download: Mobile Threat Report Q1 2013</title>
  </entry>
  <entry>
    <id>tag:www.f-secure.com,2013-05-17:%2Fweblog%2Farchives%2F00002552.html</id>
    <author>
      <name>F-Secure Antivirus Research Team</name>
      <email>weblog\@PLEASE-REMOVE-THIS.f-secure.com</email>
    </author>
    <content mode="escaped"
             type="text/html"> 			 			F-Secure Labs Webinar: Mobile Threat Report Q1 2013&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;iframe width=&amp;quot;720&amp;quot; height=&amp;quot;405&amp;quot; src=&amp;quot;http://www.youtube.com/embed/7cfR1gPYlV0?rel=0&amp;quot; frameborder=&amp;quot;0&amp;quot; allowfullscreen&amp;gt;&amp;lt;/iframe&amp;gt; 			 &amp;lt;p&amp;gt;On 13/05/13 At 01:51 PM&amp;lt;/p&amp;gt;</content>
    <issued>2013-05-17T12:56:56Z</issued>
    <link href="http://www.f-secure.com/weblog/archives/00002552.html"
          rel="alternate"
          type="text/html" />
    <modified>2013-05-17T12:56:56Z</modified>
    <title mode="escaped"
           type="text/html">Webinar: Embedded</title>
  </entry>
  <entry>
    <id>tag:www.f-secure.com,2013-05-17:%2Fweblog%2Farchives%2F00002551.html</id>
    <author>
      <name>F-Secure Antivirus Research Team</name>
      <email>weblog\@PLEASE-REMOVE-THIS.f-secure.com</email>
    </author>
    <content mode="escaped"
             type="text/html"> 			 			It&amp;apos;s time to schedule another F-Secure Labs &amp;lt;a href=&amp;quot;http://www.f-secure.com/weblog/archives/00002518.html&amp;quot;&amp;gt;webinar&amp;lt;/a&amp;gt;!&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;We&amp;apos;re trying out Google&amp;apos;s &amp;quot;Hangouts On Air&amp;quot; this go-around:&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;a href=&amp;quot;https://plus.google.com/events/caqm7s6qtnjf4g0n4lushl5n0v4&amp;quot;&amp;gt;&amp;lt;img width=&amp;quot;768px × 427px&amp;quot; height=&amp;quot;427&amp;quot; border=&amp;quot;0&amp;quot; src=&amp;quot;http://www.f-secure.com/weblog/archives/MTR_GoogleHangout_May13.png&amp;quot; alt=&amp;quot;Google Hangout Webinar, May13&amp;quot; /&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;Details: &amp;lt;a href=&amp;quot;https://plus.google.com/events/caqm7s6qtnjf4g0n4lushl5n0v4&amp;quot;&amp;gt;F-Secure Labs Threat Report Preview Webinar&amp;lt;/a&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;Hope to see you there. 			 &amp;lt;p&amp;gt;On 10/05/13 At 05:43 PM&amp;lt;/p&amp;gt;</content>
    <issued>2013-05-17T12:56:56Z</issued>
    <link href="http://www.f-secure.com/weblog/archives/00002551.html"
          rel="alternate"
          type="text/html" />
    <modified>2013-05-17T12:56:56Z</modified>
    <title mode="escaped"
           type="text/html">Webinar: Monday, May 13th</title>
  </entry>
  <entry>
    <id>tag:www.f-secure.com,2013-05-17:%2Fweblog%2Farchives%2F00002550.html</id>
    <author>
      <name>F-Secure Antivirus Research Team</name>
      <email>weblog\@PLEASE-REMOVE-THIS.f-secure.com</email>
    </author>
    <content mode="escaped"
             type="text/html"> 			 			Let&amp;apos;s say you want to hack &amp;lt;a href=&amp;quot;http://en.wikipedia.org/wiki/Jack_Dorsey&amp;quot;&amp;gt;Jack Dorsey&amp;lt;/a&amp;gt;&amp;apos;s online banking account. Where to start? His username?&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;Challenging&amp;amp;hellip; his online banking username is a secret. But how about his Twitter account?&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;Oh, that&amp;apos;s easy. It&amp;apos;s @&amp;lt;a href=&amp;quot;https://twitter.com/jack&amp;quot;&amp;gt;jack&amp;lt;/a&amp;gt;.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;That&amp;apos;s the problem with &amp;quot;social&amp;quot; usernames &amp;amp;mdash; they&amp;apos;re meant to be known.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;img width=&amp;quot;539&amp;quot; height=&amp;quot;210&amp;quot; border=&amp;quot;0&amp;quot; src=&amp;quot;http://www.f-secure.com/weblog/archives/Twitter_Password_Jack01.png&amp;quot; alt=&amp;quot;Twitter&amp;apos;s Password Fails&amp;quot; /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;Another problem, Twitter appears to validate e-mail addresses:&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;img width=&amp;quot;610&amp;quot; height=&amp;quot;390&amp;quot; border=&amp;quot;0&amp;quot; src=&amp;quot;http://www.f-secure.com/weblog/archives/Twitter_Password_Jack02.png&amp;quot; alt=&amp;quot;Twitter&amp;apos;s Password Fails&amp;quot; /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;Looks like nobody&amp;apos;s home at jackd@twitter.com:&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;img width=&amp;quot;610&amp;quot; height=&amp;quot;390&amp;quot; border=&amp;quot;0&amp;quot; src=&amp;quot;http://www.f-secure.com/weblog/archives/Twitter_Password_Jack03.png&amp;quot; alt=&amp;quot;Twitter&amp;apos;s Password Fails&amp;quot; /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;Twitter&amp;apos;s settings include an option to require &amp;quot;personal&amp;quot; infomation such as an e-mail or phone number:&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;img width=&amp;quot;529&amp;quot; height=&amp;quot;129&amp;quot; border=&amp;quot;0&amp;quot; src=&amp;quot;http://www.f-secure.com/weblog/archives/Twitter_Password_Jack04.png&amp;quot; alt=&amp;quot;Twitter&amp;apos;s Password Fails&amp;quot; /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;But that&amp;apos;s less than useless if Twitter won&amp;apos;t actually let you add your number:&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;img width=&amp;quot;529&amp;quot; height=&amp;quot;306&amp;quot; border=&amp;quot;0&amp;quot; src=&amp;quot;http://www.f-secure.com/weblog/archives/Twitter_Password_Jack05.png&amp;quot; alt=&amp;quot;Twitter&amp;apos;s Password Fails&amp;quot; /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;And just how &amp;quot;personal&amp;quot; is a phone number anyway?&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;img width=&amp;quot;547&amp;quot; height=&amp;quot;505&amp;quot; border=&amp;quot;0&amp;quot; src=&amp;quot;http://www.f-secure.com/weblog/archives/Twitter_Password_Jack06.png&amp;quot; alt=&amp;quot;Twitter&amp;apos;s Password Fails&amp;quot; /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;Two-factor authentication?&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;Sure.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;But Twitter should first stop validating e-mail addresses.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;And then maybe it could add an option to disallow logins via the publicly known username.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;b&amp;gt;Edited to add&amp;lt;/b&amp;gt;: On second thought&amp;amp;hellip;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;How about this?&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;Twitter should stop validating e-mailing addresses in its password reset form.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;And then, discriminate between using e-mail  and username. &amp;lt;b&amp;gt;If an account is accessed with the username&amp;lt;/b&amp;gt; &amp;amp;mdash; &amp;lt;b&amp;gt;don&amp;apos;t provide access to the account settings!&amp;lt;/b&amp;gt; The e-mail address (alias) could then be used only by account &amp;quot;adminstrators&amp;quot;.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;Example: regular @&amp;lt;a href=&amp;quot;https://twitter.com/ap&amp;quot;&amp;gt;AP&amp;lt;/a&amp;gt; staff could login with &amp;quot;AP&amp;quot; &amp;amp;mdash; no settings for them! They could Tweet, but would be restricted from making changes to the account. But the @AP &amp;quot;admin&amp;quot;, some guy in the IT department, that person could login using the &amp;quot;secret&amp;quot; e-mail address and would be able to change account settings (and lockdown the account in case of a breach).&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;Discriminating between e-mail and username &amp;amp;mdash; a way to distinguish between &amp;quot;admins&amp;quot; and &amp;quot;users&amp;quot;. 			 &amp;lt;p&amp;gt;On 07/05/13 At 12:51 PM&amp;lt;/p&amp;gt;</content>
    <issued>2013-05-17T12:56:56Z</issued>
    <link href="http://www.f-secure.com/weblog/archives/00002550.html"
          rel="alternate"
          type="text/html" />
    <modified>2013-05-17T12:56:56Z</modified>
    <title mode="escaped"
           type="text/html">Twitter&amp;apos;s Password Fails</title>
  </entry>
  <entry>
    <id>tag:www.f-secure.com,2013-05-17:%2Fweblog%2Farchives%2F00002549.html</id>
    <author>
      <name>F-Secure Antivirus Research Team</name>
      <email>weblog\@PLEASE-REMOVE-THIS.f-secure.com</email>
    </author>
    <content mode="escaped"
             type="text/html"> 			 			Malaysia&amp;apos;s 2013 general elections are scheduled for Sunday, May 5, 2013. Political news coverage is currently inundating all news outlets, including social networking sites, as the country&amp;apos;s political parties go into high gear in the final run-up to polling day.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;The huge media interest creates an opportunity for malware writers to gain new victims using established social engineering techniques &amp;amp;mdash; and sure enough, this week Citizen Lab released &amp;lt;a href=&amp;quot;https://citizenlab.org/storage/finfisher/final/fortheireyesonly.pdf&amp;quot;&amp;gt;a report&amp;lt;/a&amp;gt; indicating that a sample of the sophisticated FinFisher (a.k.a. FinSpy) surveillance malware was discovered in a document crafted specifically for this event.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;The malware was distributed in a booby-trapped Malay-language Microsoft Word document named &amp;quot;SENARAI CADANGAN CALON PRU KE-13 MENGIKUT NEGERI.doc&amp;quot; (In English: &amp;quot;List of proposed candidates for 13th General Elections according to states&amp;quot;).&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;img Width=&amp;quot;768&amp;quot; height=&amp;quot;628&amp;quot; border=&amp;quot;0&amp;quot; src=&amp;quot;http://www.f-secure.com/weblog/archives/finspy_malaysia.jpg&amp;quot; alt=&amp;quot;SENARAI CADANGAN CALON PRU KE-13 MENGIKUT NEGERI.doc&amp;quot; /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;The report speculates that the attack document is targeting Malaysians looking for more information related to one of the most closely contested elections in the country&amp;apos;s history. F-Secure detects the document in question as Trojan:W32/FinSpy.D.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;Finfisher is produced by an European company called the Gamma Group. As we mentioned in a &amp;lt;a href=&amp;quot;http://www.f-secure.com/weblog/archives/00002279.html&amp;quot;&amp;gt;previous post&amp;lt;/a&amp;gt;, the company was present at the ISS World 2011 gathering hosted in Kuala Lumpur, Malaysia. The ISS event serves as a trade fair for surveillance software (attendance is by &amp;quot;invitation&amp;quot; or if you are a &amp;quot;telco service provider, government employees or law enforcement officer&amp;quot;).&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;img widht=&amp;quot;760&amp;quot;height=&amp;quot;485&amp;quot; border=&amp;quot;0&amp;quot; src=&amp;quot;http://www.f-secure.com/weblog/archives/iss_kul_5.png&amp;quot; alt=&amp;quot;ISS World Kuala Lumpur&amp;quot; /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;Additionally, there have been reports alleging that multiple news and social media sites, including YouTube, Facebook, and Malaysiakini (a popular Malaysian online news site) have been subjected to various forms of disruption, including defacements, denial of service attacks, and filtering.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;F-Secure Labs is observing the situation. We saw a rise in malware detections during April 2013 in Malaysia. However, we don&amp;apos;t really know if the increase was due to election-related activity or something else.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;img width=&amp;quot;768&amp;quot; height=&amp;quot;233&amp;quot; border=&amp;quot;0&amp;quot; src=&amp;quot;http://www.f-secure.com/weblog/archives/malaysia_detections.png&amp;quot; alt=&amp;quot;Malaysia, detections&amp;quot; /&amp;gt; 			 &amp;lt;p&amp;gt;On 03/05/13 At 11:57 AM&amp;lt;/p&amp;gt;</content>
    <issued>2013-05-17T12:56:56Z</issued>
    <link href="http://www.f-secure.com/weblog/archives/00002549.html"
          rel="alternate"
          type="text/html" />
    <modified>2013-05-17T12:56:56Z</modified>
    <title mode="escaped"
           type="text/html">Online Activities Related to Elections in Malaysia</title>
  </entry>
  <entry>
    <id>tag:www.f-secure.com,2013-05-17:%2Fweblog%2Farchives%2F00002548.html</id>
    <author>
      <name>F-Secure Antivirus Research Team</name>
      <email>weblog\@PLEASE-REMOVE-THIS.f-secure.com</email>
    </author>
    <content mode="escaped"
             type="text/html"> 			 			Facebook has gradually added different tags to its &amp;quot;Status&amp;quot; updates.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;Currently, most users have the ability to tag: who, when and where.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;img width=&amp;quot;433&amp;quot; height=&amp;quot;160&amp;quot; border=&amp;quot;1&amp;quot; src=&amp;quot;http://www.f-secure.com/weblog/archives/Facebook_WhatTag01.png&amp;quot; alt=&amp;quot;Facebook, What tags&amp;quot; /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;Those options could soon include: what. (Roll out is limited at the moment.)&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;img width=&amp;quot;534&amp;quot; height=&amp;quot;176&amp;quot; border=&amp;quot;1&amp;quot; src=&amp;quot;http://www.f-secure.com/weblog/archives/Facebook_WhatTag02.png&amp;quot; alt=&amp;quot;Facebook, What tags&amp;quot; /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;And not just what you are doing &amp;amp;mdash; but what you&amp;apos;re feeling.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;img width=&amp;quot;534&amp;quot; height=&amp;quot;389&amp;quot; border=&amp;quot;1&amp;quot; src=&amp;quot;http://www.f-secure.com/weblog/archives/Facebook_WhatTag03.png&amp;quot; alt=&amp;quot;Facebook, What tags&amp;quot; /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;As long as everybody you&amp;apos;re friends with gets the joke&amp;amp;hellip;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;img width=&amp;quot;534&amp;quot; height=&amp;quot;176&amp;quot; border=&amp;quot;1&amp;quot; src=&amp;quot;http://www.f-secure.com/weblog/archives/Facebook_WhatTag04.png&amp;quot; alt=&amp;quot;Facebook, What tags&amp;quot; /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;amp;hellip;you should be safe.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;img width=&amp;quot;510&amp;quot; height=&amp;quot;205&amp;quot; border=&amp;quot;1&amp;quot; src=&amp;quot;http://www.f-secure.com/weblog/archives/Facebook_WhatTag05.png&amp;quot; alt=&amp;quot;Facebook, What tags&amp;quot; /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;But let&amp;apos;s say your boss mistakes &amp;quot;a pan galactic gargle blaster&amp;quot; for a real drink and reprimands you for drinking alcohol on the job.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;That could leave you feeling quite annoyed.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;img width=&amp;quot;533&amp;quot; height=&amp;quot;360&amp;quot; border=&amp;quot;1&amp;quot; src=&amp;quot;http://www.f-secure.com/weblog/archives/Facebook_WhatTag06.png&amp;quot; alt=&amp;quot;Facebook, What tags&amp;quot; /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;a href=&amp;quot;https://www.facebook.com/help/427780037309149/&amp;quot;&amp;gt;How do I share my feelings or what I&amp;apos;m doing in a status update?&amp;lt;/a&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;Carefully.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;hr&amp;gt; 			 &amp;lt;p&amp;gt;On 30/04/13 At 12:06 PM&amp;lt;/p&amp;gt;</content>
    <issued>2013-05-17T12:56:56Z</issued>
    <link href="http://www.f-secure.com/weblog/archives/00002548.html"
          rel="alternate"
          type="text/html" />
    <modified>2013-05-17T12:56:56Z</modified>
    <title mode="escaped"
           type="text/html">Facebook is Testing Tags For &amp;quot;What&amp;quot;</title>
  </entry>
  <entry>
    <id>tag:www.f-secure.com,2013-05-17:%2Fweblog%2Farchives%2F00002547.html</id>
    <author>
      <name>F-Secure Antivirus Research Team</name>
      <email>weblog\@PLEASE-REMOVE-THIS.f-secure.com</email>
    </author>
    <content mode="escaped"
             type="text/html"> 			 			&amp;lt;img width=&amp;quot;444&amp;quot; height=&amp;quot;411&amp;quot; border=&amp;quot;1&amp;quot; src=&amp;quot;http://www.f-secure.com/weblog/archives/fog_of_cd.jpg&amp;quot; alt=&amp;quot;The Fog of Cyber Defence&amp;quot;&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;The Finnish National Defence University has published a 250-page book called The Fog of Cyber Defence. The book discusses cyber warfare, cyber arms race, and cyber defense from a Nordic viewpoint.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;The book was written by twenty authors:&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;Insights into Cyberspace, Cyber Security, and Cyberwar in the Nordic Countries - (Jari Rantapelkonen &amp;amp;amp; Harry Kantola)&amp;lt;br /&amp;gt;Sovereignty in the Cyber Domain - (Topi Tuukkanen)&amp;lt;br /&amp;gt;Cyberspace, the Role of State, and Goal of Digital Finland - (Jari Rantapelkonen &amp;amp;amp; Saara Jantunen)&amp;lt;br /&amp;gt;Exercising Power in Social Media - (Margarita Jaitner)&amp;lt;br /&amp;gt;Victory in Exceptional War: The Estonian Main Narrative of the Cyber Attacks in 2007 - (Kari Alenius)&amp;lt;br /&amp;gt;The Origins and the Future of Cyber Security in the Finnish Defence Forces - (Anssi Kärkkäinen)&amp;lt;br /&amp;gt;Norwegian Cyber Security: How to Build a Resilient Cyber Society in a Small Nation - (Kristin Hemmer Mørkestøl)&amp;lt;br /&amp;gt;Cyber Security in Sweden from the Past to the Future - (Roland Heickerö)&amp;lt;br /&amp;gt;A Rugged Nation - (Simo Huopio)&amp;lt;br /&amp;gt;Contaminated Rather than Classified: CIS Design Principles to Support Cyber Incident Response Collaboration - (Erka Koivunen)&amp;lt;br /&amp;gt;Cyberwar: Another Revolution in Military Affairs? - (Tero Palokangas)&amp;lt;br /&amp;gt;What Can We Say About Cyberwar Based on Cybernetics? - (Sakari Ahvenainen)&amp;lt;br /&amp;gt;The Emperor&amp;apos;s Digital Clothes: Cyberwar and the Application of Classical Theories of War - (Jan Hanska)&amp;lt;br /&amp;gt;Theoretical Offensive Cyber Militia Models - (Rain Ottis)&amp;lt;br /&amp;gt;Offensive Cyber Capabilities are Needed Because of Deterrence - (Jarno Limnéll)&amp;lt;br /&amp;gt;Threats Concerning the Usability of Satellite Communications in Cyberwarfare Environment - (Jouko Vankka &amp;amp;amp; Tapio Saarelainen)&amp;lt;br /&amp;gt;The Care and Maintenance of Cyberweapons - (Timo Kiravuo &amp;amp;amp; Mikko Särelä)&amp;lt;br /&amp;gt;The Exploit Marketplace - (Mikko Hyppönen)&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;The Fog of Cyber Defence can be downloaded as a PDF file from &amp;lt;a href=&amp;quot;http://www.doria.fi/bitstream/handle/10024/88689/The%20Fog%20of%20Cyber%20Defence%20NDU%202013.pdf?sequence=1&amp;quot;&amp;gt;http://urn.fi/URN:ISBN:978-951-25-2431-0&amp;lt;/a&amp;gt; 			 &amp;lt;p&amp;gt;On 30/04/13 At 06:53 AM&amp;lt;/p&amp;gt;</content>
    <issued>2013-05-17T12:56:56Z</issued>
    <link href="http://www.f-secure.com/weblog/archives/00002547.html"
          rel="alternate"
          type="text/html" />
    <modified>2013-05-17T12:56:56Z</modified>
    <title mode="escaped"
           type="text/html">The Fog of Cyber Defence</title>
  </entry>
  <entry>
    <id>tag:www.f-secure.com,2013-05-17:%2Fweblog%2Farchives%2F00002546.html</id>
    <author>
      <name>F-Secure Antivirus Research Team</name>
      <email>weblog\@PLEASE-REMOVE-THIS.f-secure.com</email>
    </author>
    <content mode="escaped"
             type="text/html"> 			 			We spotted a new variant of the documents used in the cyber attacks against Uyghur back in &amp;lt;a href=&amp;quot;http://www.securelist.com/en/blog/208194116/Cyber_Attacks_Against_Uyghur_Mac_OS_X_Users_Intensify&amp;quot;&amp;gt;February&amp;lt;/a&amp;gt;.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;This variant was first submitted to &amp;lt;a href=&amp;quot;https://www.virustotal.com/en/file/e7671740298c5af7c38f599f17a8516180681fb48fd4fb9ac977b1257282219d/analysis/&amp;quot;&amp;gt;VirusTotal&amp;lt;/a&amp;gt; on April 11 from China. This time it uses IUHRDF, which may be a reference to &amp;lt;a href=&amp;quot;http://iuhrdf.org/&amp;quot;&amp;gt;International Uyghur Human Rights &amp;amp;amp; Democracy Foundation&amp;lt;/a&amp;gt;, instead of Captain as the author:&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;img border=&amp;quot;0&amp;quot; src=&amp;quot;http://www.f-secure.com/weblog/archives/callme_doc.png&amp;quot; alt=&amp;quot;Properties of poadasjkdasuodrr.doc&amp;quot;  height=&amp;quot;515&amp;quot; width=&amp;quot;377&amp;quot;/&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;The payload is still the same besides using different filenames and command and control server.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;It uses &amp;quot;alma.apple.cloudns.org&amp;quot; as the command and control server:&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;img border=&amp;quot;1&amp;quot; src=&amp;quot;http://www.f-secure.com/weblog/archives/callme_c&amp;amp;amp;c.png&amp;quot; alt=&amp;quot;Command and control server name&amp;quot; height=&amp;quot;61&amp;quot; width=&amp;quot;754&amp;quot; /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;It creates the following copy of itself and launch point:&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;~/Library/Application Support/.realPlayerUpdate&amp;lt;br /&amp;gt;~/library/launchagents/realPlayerUpdate.plist&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;Or it may create the following instead (when executed with &amp;lt;a href=&amp;quot;http://www.f-secure.com/weblog/archives/callme_filenames.png&amp;quot;&amp;gt;2&amp;lt;/a&amp;gt; &amp;lt;a href=&amp;quot;http://www.f-secure.com/weblog/archives/callme_launchpoints.png&amp;quot;&amp;gt;parameters&amp;lt;/a&amp;gt;):&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;/Library/Application Support/.realPlayerUpdate&amp;lt;br /&amp;gt;/library/LaunchDaemons/realPlayerUpdate.plist&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;It remains pretty much the same malware and is generically detected as Backdoor:OSX/CallMe.A since February.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;MD5: ee84c5d626bf8450782f24fd7d2f3ae6 - poadasjkdasuodrr.doc &amp;lt;br /&amp;gt;MD5: 544539ea546e88ff462814ba96afef1a - .realPlayerUpdate 			 &amp;lt;p&amp;gt;On 25/04/13 At 01:39 PM&amp;lt;/p&amp;gt;</content>
    <issued>2013-05-17T12:56:56Z</issued>
    <link href="http://www.f-secure.com/weblog/archives/00002546.html"
          rel="alternate"
          type="text/html" />
    <modified>2013-05-17T12:56:56Z</modified>
    <title mode="escaped"
           type="text/html">Another Document Targeting Uyghur Mac Users</title>
  </entry>
  <entry>
    <id>tag:www.f-secure.com,2013-05-17:%2Fweblog%2Farchives%2F00002545.html</id>
    <author>
      <name>F-Secure Antivirus Research Team</name>
      <email>weblog\@PLEASE-REMOVE-THIS.f-secure.com</email>
    </author>
    <content mode="escaped"
             type="text/html"> 			 			Fun Fact!&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;Among the trusted root certificates used by Mac OS X, &amp;lt;a href=&amp;quot;http://support.apple.com/kb/ht5012&amp;quot;&amp;gt;iOS 5 and iOS 6&amp;lt;/a&amp;gt;&amp;amp;hellip;&amp;lt;br /&amp;gt;&amp;lt;img width=&amp;quot;627&amp;quot; height=&amp;quot;546&amp;quot; border=&amp;quot;0&amp;quot; src=&amp;quot;http://www.f-secure.com/weblog/archives/DoD_CLASS_3_Root_CA.png&amp;quot; alt=&amp;quot;DoD_CLASS_3_Root_CA&amp;quot; /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;img width=&amp;quot;627&amp;quot; height=&amp;quot;546&amp;quot; border=&amp;quot;0&amp;quot; src=&amp;quot;http://www.f-secure.com/weblog/archives/DoD_Root_CA_2.png&amp;quot; alt=&amp;quot;DoD_Root_CA_2&amp;quot; /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;img width=&amp;quot;655&amp;quot; height=&amp;quot;390&amp;quot; border=&amp;quot;0&amp;quot; src=&amp;quot;http://www.f-secure.com/weblog/archives/iOS_DoD_certs.png&amp;quot; alt=&amp;quot;iOS_DoD_certs&amp;quot; /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;amp;hellip;are two from the United States Department of Defense (DoD).&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;Interesting, no? 			 &amp;lt;p&amp;gt;On 24/04/13 At 06:39 PM&amp;lt;/p&amp;gt;</content>
    <issued>2013-05-17T12:56:56Z</issued>
    <link href="http://www.f-secure.com/weblog/archives/00002545.html"
          rel="alternate"
          type="text/html" />
    <modified>2013-05-17T12:56:56Z</modified>
    <title mode="escaped"
           type="text/html">Apple&amp;apos;s Root Certs Include the DoD</title>
  </entry>
  <entry>
    <id>tag:www.f-secure.com,2013-05-17:%2Fweblog%2Farchives%2F00002544.html</id>
    <author>
      <name>F-Secure Antivirus Research Team</name>
      <email>weblog\@PLEASE-REMOVE-THIS.f-secure.com</email>
    </author>
    <content mode="escaped"
             type="text/html"> 			 			A few days after Oracle released its critical &amp;lt;a href=&amp;quot;http://www.oracle.com/technetwork/topics/security/javacpuapr2013-1928497.html&amp;quot;&amp;gt;patch for Java&amp;lt;/a&amp;gt;, and &amp;lt;a href=&amp;quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2423&amp;quot;&amp;gt;CVE-2013-2423&amp;lt;/a&amp;gt; is already being exploited. Upon checking the history, the exploitation seems to have begun on April 21st and is still actively happening (as of this post):&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;img border=&amp;quot;0&amp;quot; src=&amp;quot;http://www.f-secure.com/weblog/archives/url_list.png&amp;quot; alt=&amp;quot;url_list (122k image)&amp;quot; height=&amp;quot;175&amp;quot; width=&amp;quot;768&amp;quot; /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;For a closer look, the image below contains a comparison of the classes found in the &amp;lt;a href=&amp;quot;http://www.metasploit.com/modules/exploit/multi/browser/java_jre17_reflection_types&amp;quot;&amp;gt;Metasploit module&amp;lt;/a&amp;gt; and that of the ITW sample:&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;img border=&amp;quot;0&amp;quot; src=&amp;quot;http://www.f-secure.com/weblog/archives/Metasploit.png&amp;quot; alt=&amp;quot;Metasploit (95k image)&amp;quot; height=&amp;quot;330&amp;quot; width=&amp;quot;550&amp;quot; /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;Interestingly, the Metasploit module was published on the 20th, and as mentioned earlier, the exploit was seen in the wild the day after.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;Information about the PoC can be found &amp;lt;a href=&amp;quot;http://weblog.ikvm.net/PermaLink.aspx?guid=acd2dd6d-1028-4996-95df-efa42ac237f0&amp;quot;&amp;gt;here&amp;lt;/a&amp;gt;.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;Files are detected as Exploit:Java/Majava.B.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;i&amp;gt;Sample hashes:&amp;lt;br /&amp;gt;1a3386cc00b9d3188aae69c1a0dfe6ef3aa27bfa&amp;lt;br /&amp;gt;23acb0bee1efe17aae75f8138f885724ead1640f&amp;lt;br /&amp;gt;&amp;lt;/i&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;Post by &amp;amp;mdash; Karmina and @&amp;lt;a href=&amp;quot;http://twitter.com/TimoHirvonen&amp;quot;&amp;gt;Timo&amp;lt;/a&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;hr&amp;gt; 			 &amp;lt;p&amp;gt;On 23/04/13 At 02:36 PM&amp;lt;/p&amp;gt;</content>
    <issued>2013-05-17T12:56:56Z</issued>
    <link href="http://www.f-secure.com/weblog/archives/00002544.html"
          rel="alternate"
          type="text/html" />
    <modified>2013-05-17T12:56:56Z</modified>
    <title mode="escaped"
           type="text/html">CVE-2013-2423 Java Vulnerability Exploit ITW</title>
  </entry>
  <entry>
    <id>tag:www.f-secure.com,2013-05-17:%2Fweblog%2Farchives%2F00002543.html</id>
    <author>
      <name>F-Secure Antivirus Research Team</name>
      <email>weblog\@PLEASE-REMOVE-THIS.f-secure.com</email>
    </author>
    <content mode="escaped"
             type="text/html"> 			 			&amp;lt;a href=&amp;quot;http://www.infosec.co.uk&amp;quot;&amp;gt;Infosecurity Europe 2013&amp;lt;/a&amp;gt; opened its doors today. And tomorrow&amp;amp;hellip;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;Our own &amp;lt;a href=&amp;quot;https://twitter.com/mikko&amp;quot;&amp;gt;Mikko Hypponen&amp;lt;/a&amp;gt; will be inducted into Infosec&amp;apos;s &amp;lt;a href=&amp;quot;http://www.infosec.co.uk/en/Education-Programme/fame/&amp;quot;&amp;gt;Hall of Fame&amp;lt;/a&amp;gt;.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;img width=&amp;quot;650&amp;quot; height=&amp;quot;390&amp;quot; border=&amp;quot;0&amp;quot; src=&amp;quot;http://www.f-secure.com/weblog/archives/InfoSecHallFame2013.png&amp;quot; alt=&amp;quot;Infosecurity Europe&amp;apos;s Hall of Fame 2013&amp;quot; /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;Congratulations Mikko!&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;Session details &amp;lt;a href=&amp;quot;http://www.infosec.co.uk/en/Sessions/1258/The-Infosecurity-Europe-Hall-of-Fame-2013&amp;quot;&amp;gt;here&amp;lt;/a&amp;gt;. 			 &amp;lt;p&amp;gt;On 23/04/13 At 12:42 PM&amp;lt;/p&amp;gt;</content>
    <issued>2013-05-17T12:56:56Z</issued>
    <link href="http://www.f-secure.com/weblog/archives/00002543.html"
          rel="alternate"
          type="text/html" />
    <modified>2013-05-17T12:56:56Z</modified>
    <title mode="escaped"
           type="text/html">Infosec&amp;apos;s Hall of Fame 2013</title>
  </entry>
  <generator url="http://search.cpan.org/dist/XML-Atom-SimpleFeed"
             version="0.7">XML::Atom::SimpleFeed</generator>
  <link href="http://www.f-secure.com/weblog"
        rel="alternate"
        type="text/html" />
  <modified>2013-05-17T12:56:56Z</modified>
  <tagline mode="escaped"
           type="text/html">Weblog of F-Secure Antivirus Research Team</tagline>
  <title mode="escaped"
         type="text/html">F-Secure Antivirus Research Weblog</title>
</feed>
