Category Archives: IT Security

Any security related topics such as posts about vulnerabilities, malware, rootkits

WinDirStat detected as a trojan

Read here …

Posted in EN, IT Security, Software | Leave a comment

Good job, Chris!

This is the first release of the new JEDI Windows API (JWA) and JEDI Windows Security Code Library (JWSCL). JWA is known as the JEDI Windows API header conversions. JWA can be compiled into one jwaWindows unit. There is no … Continue reading

Posted in EN, IT Security, Programming | 1 Comment

God save the … encrypted data

As Hitzi writes in his blog – thanks for the pointer, by the way 😉 – it is formally possible for authorities in Great Britain to force someone to provide his data in decrypted form or at least provide the … Continue reading

Posted in EN, IT Security, Thoughts | Leave a comment

Hallo aus Wien

Einige werden es bereits aus privaten Konversationen wissen, der Rest weiß es eben jetzt … ich halte mich als einer von sieben Vertretern von FRISK Software in Wien bei der Virus Bulletin Konferenz 2007 auf. Hier trifft man nette Leute … Continue reading

Posted in /dev/null, DE, IT Security, Reversing, Software | Leave a comment

Cool, LS at Virus Bulletin Conference

… although LS is not quite in the AV-business (yet? ), they promise – i.e. their CEO, Jason King, promises – that LS will show up at the Virus Bulletin Conference in Vienna in September. What a lucky occasion. So … Continue reading

Posted in EN, IT Security, Lava-watch | Leave a comment

Joanna Rutkowska gets serious ;)

She and a partner, Alexander Tereshkin, have published the source to BluePill, or rather a rewrite called New BluePill (NBP), since Rutkowska’s previous employer owns the rights to the original one: http://www.bluepillproject.org The source is a little flawed, at least … Continue reading

Posted in DDKWizard/DDKBUILD, EN, IT Security, Programming, Reversing | Comments Off on Joanna Rutkowska gets serious ;)

Gute Neuigkeiten

Heise meldet: unter dem Titel “GDatas Antivirenlösungen für Unternehmen ohne Kaspersky-Scanner” … “[…] Stattdessen setzen die Produkte für Unternehmen in den aktuellen Versionen auf die F-Prot-Engine von Frisk […]”. Ich wußte es ja schon ein Weilchen, aber da es jetzt … Continue reading

Posted in DE, FSI/F-Prot, IT Security, Software | Comments Off on Gute Neuigkeiten

No it wasn’t an April Fool’s joke

Michał ‘GiM’ Spadliński, a Polish blogger wrote in his article “Czy Redpill Joanny Rutkowskiej jest poprawny?“: Oliver Schneider (Reverse Engineer pracujący dla F-Prota) opublikował […] artykuł, datowany na pierwszego kwietnia, który wcale nie wygląda na prima aprilisowy żart. This made … Continue reading

Posted in EN, IT Security, Programming, Reversing, Software | Comments Off on No it wasn’t an April Fool’s joke

Battle of the titans?

Ptacek, Lawson and Ferrie – well-known security specialists – joined up to challenge Rutkowska and prove that her virtualization rootkit BluePill (up to now AMD-specific) is detectable regardless of her claims. The above link leads to her official reply to … Continue reading

Posted in EN, IT Security, Programming, Reversing | Comments Off on Battle of the titans?

What the heck, Kaspersky???

… here Kaspersky claims: An advisory has recently been published on rootkit.com regarding a vulnerability in KAV 7.0. Unfortunately, the authors of this material chose not to adhere to industry standard practice, and contact the vendor prior to disclosing vulnerability … Continue reading

Posted in EN, IT Security, Reversing, Software | Leave a comment

Realtime protection

The term “Realtime protection” has been overused in recent years and used in a completely wrong sense ever since it was invented. To make sure to not be misunderstood – yes, even the company I work for has used the … Continue reading

Posted in EN, IT Security | Comments Off on Realtime protection

AV-workshop presentations available

As some of you may know, FRISK Software had invited professionals from the AV industry and AV testers to attend the “International Antivirus Testing Workshop” this week in Reykjavik. The workshop was held on tuesday and wednesday and I had … Continue reading

Posted in EN, FSI/F-Prot, Island/Iceland/Ísland, IT Security, Software | Leave a comment

Wicked stuff!

Ilfak posted a nice demo clip on his blog: “Decompilation gets real”. This is really a dream of many reversers and could really speed up the analysis of many samples. // Oliver

Posted in EN, IT Security, Reversing, Software | Leave a comment

Redpill getting colorless? (continued)

In my previous article from November last year I challenged the claims of Joanna Rutkowska concerning Redpill. A recent article in the German computer magazine iX (April 2007) mentioned Rutkowska’s findings again so that I decided to review the tool, … Continue reading

Posted in EN, IT Security, Programming, Reversing, Software | Leave a comment

PuTTY Key Generator

To create a public/private key pair for use in PuTTY (i.e. OpenSSH and so on) use the following method.

Posted in EN, IT Security | Leave a comment

Eugene Kaspersky worried about increase of malware

Read the article by yourself on Heise: Kasperskys worry about malware and hit out at Microsoft. I would therefore like to see a kind of internet Interpol. Even the best security software will, on its own, soon no longer be … Continue reading

Posted in EN, IT Security, Software | Leave a comment

Is that an official statement, LS?

I wonder whether this is an official statement on behalf of Lavasoft. Alright, there have been other statements from the PR spokesperson which are not much better, but this one is really frightening (emphasis mine): That being said, we are … Continue reading

Posted in EN, IT Security, Lava-watch, Software | Leave a comment

Good point(s)

Microsoft Virtualization Licensing and Distribution Terms … from the competitor’s perspective. // Oliver

Posted in EN, IT Security, Software, Thoughts | Leave a comment

Fairness, where fairness is due

In this article back in November 2006 I complained about the way the security flaw was reported. This was apparently fixed. So in I think it is only fair to publish that fact here as well. My apologies for the … Continue reading

Posted in EN, IT Security, Software | Leave a comment

Something interesting on Corrine’s blog

That’s how a privacy company treats the email address of customers and (ordinary) newsletter subscribers. // Oliver

Posted in EN, IT Security, Lava-watch, Software | Leave a comment