<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.2.3" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>
<channel>
	<title>Comments for MW-Blog</title>
	<link>http://www.teamfurry.com/wordpress</link>
	<description>About malware, packers and reverse engineering</description>
	<pubDate>Sat, 13 Mar 2010 10:41:07 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.2.3</generator>

	<item>
		<title>Comment on On TOR by PrivatsphÃ¤re mit TOR &#171; KOPIS.DE</title>
		<link>http://www.teamfurry.com/wordpress/2007/11/19/on-tor/#comment-337</link>
		<dc:creator>PrivatsphÃ¤re mit TOR &#171; KOPIS.DE</dc:creator>
		<pubDate>Wed, 10 Mar 2010 11:01:44 +0000</pubDate>
		<guid>http://www.teamfurry.com/wordpress/2007/11/19/on-tor/#comment-337</guid>
		<description>[...] weiÃ, es ist nicht mehr taufrisch &#8211; sogar heise berichtet schon drÃ¼ber &#8211; aber ich mÃ¶chte auch noch [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] weiÃ, es ist nicht mehr taufrisch &#8211; sogar heise berichtet schon drÃ¼ber &#8211; aber ich mÃ¶chte auch noch [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Under the Hood: Virut by information security</title>
		<link>http://www.teamfurry.com/wordpress/2007/02/15/under-the-hood-virut/#comment-336</link>
		<dc:creator>information security</dc:creator>
		<pubDate>Thu, 04 Mar 2010 07:26:12 +0000</pubDate>
		<guid>http://www.teamfurry.com/wordpress/2007/02/15/under-the-hood-virut/#comment-336</guid>
		<description>&lt;strong&gt;information security...&lt;/strong&gt;

Einige sind der Ansicht, dass es sich mit dem Thema zu beschaeftigen wenig lohnt, da der Informationsmarkt hierueber bereits recht ueberlaufen sei, Es laesst sich wahrlich nur recht selten auf etwas wriklich Gutes dabei zu treffen. Trotzdem kann sich d...</description>
		<content:encoded><![CDATA[<p><strong>information security&#8230;</strong></p>
<p>Einige sind der Ansicht, dass es sich mit dem Thema zu beschaeftigen wenig lohnt, da der Informationsmarkt hierueber bereits recht ueberlaufen sei, Es laesst sich wahrlich nur recht selten auf etwas wriklich Gutes dabei zu treffen. Trotzdem kann sich d&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on On TOR by Christians Blog &#187; Blog Archive &#187; Spy Tor Exit Node 2</title>
		<link>http://www.teamfurry.com/wordpress/2007/11/19/on-tor/#comment-335</link>
		<dc:creator>Christians Blog &#187; Blog Archive &#187; Spy Tor Exit Node 2</dc:creator>
		<pubDate>Sun, 17 Jan 2010 18:49:29 +0000</pubDate>
		<guid>http://www.teamfurry.com/wordpress/2007/11/19/on-tor/#comment-335</guid>
		<description>[...] MW-Blog, das sich mit Malware &#38; Co. beschäftigt, gibt&#8217;s einen interessanten Artikel über die [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] MW-Blog, das sich mit Malware &amp; Co. beschäftigt, gibt&#8217;s einen interessanten Artikel über die [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on TOR exit-node doing MITM attacks by Sniffing/MITM attacks on the Tor network &#124; Chucks Blog</title>
		<link>http://www.teamfurry.com/wordpress/2007/11/20/tor-exit-node-doing-mitm-attacks/#comment-334</link>
		<dc:creator>Sniffing/MITM attacks on the Tor network &#124; Chucks Blog</dc:creator>
		<pubDate>Mon, 14 Sep 2009 00:38:52 +0000</pubDate>
		<guid>http://www.teamfurry.com/wordpress/2007/11/20/tor-exit-node-doing-mitm-attacks/#comment-334</guid>
		<description>[...] and does not make you more secure by using it. If you use tor with encrypted protocols and avoid fake SSL certificates then you should be fine. However, if you use a plain text protocol such as HTTP, you are pretty much [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] and does not make you more secure by using it. If you use tor with encrypted protocols and avoid fake SSL certificates then you should be fine. However, if you use a plain text protocol such as HTTP, you are pretty much [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Under the Hood: Virut by laptop dead - Help2Go</title>
		<link>http://www.teamfurry.com/wordpress/2007/02/15/under-the-hood-virut/#comment-333</link>
		<dc:creator>laptop dead - Help2Go</dc:creator>
		<pubDate>Mon, 24 Aug 2009 18:19:19 +0000</pubDate>
		<guid>http://www.teamfurry.com/wordpress/2007/02/15/under-the-hood-virut/#comment-333</guid>
		<description>[...] spreading so trying to contain it is impossible. See this article on why it is so destructive. Under the Hood: Virut  If you do try to repair this without reformatting then your best chance is using the Avira AntiVir [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] spreading so trying to contain it is impossible. See this article on why it is so destructive. Under the Hood: Virut  If you do try to repair this without reformatting then your best chance is using the Avira AntiVir [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on zxarps by Old Chinese Hack Tool Used for New Tricks &#171; O24 &#8211; One Step Ahead</title>
		<link>http://www.teamfurry.com/wordpress/2007/08/29/zxarps/#comment-331</link>
		<dc:creator>Old Chinese Hack Tool Used for New Tricks &#171; O24 &#8211; One Step Ahead</dc:creator>
		<pubDate>Wed, 20 May 2009 05:59:53 +0000</pubDate>
		<guid>http://www.teamfurry.com/wordpress/2007/08/29/zxarps/#comment-331</guid>
		<description>[...] most malware we see these days, ZXArps (which dates back to 2006, and was discovered by the English-speaking security community the following year) isn’t designed to perform a single task. It’s more like a Swiss Army knife, [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] most malware we see these days, ZXArps (which dates back to 2006, and was discovered by the English-speaking security community the following year) isn’t designed to perform a single task. It’s more like a Swiss Army knife, [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on zxarps by Old Chinese Hack Tool Used for New Tricks &#171; Webroot Threat Blog</title>
		<link>http://www.teamfurry.com/wordpress/2007/08/29/zxarps/#comment-330</link>
		<dc:creator>Old Chinese Hack Tool Used for New Tricks &#171; Webroot Threat Blog</dc:creator>
		<pubDate>Thu, 14 May 2009 20:01:15 +0000</pubDate>
		<guid>http://www.teamfurry.com/wordpress/2007/08/29/zxarps/#comment-330</guid>
		<description>[...] most malware we see these days, ZXArps (which dates back to 2006, and was discovered by the English-speaking security community the following year) isn&#8217;t designed to perform a single task. It&#8217;s more like a Swiss [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] most malware we see these days, ZXArps (which dates back to 2006, and was discovered by the English-speaking security community the following year) isn&#8217;t designed to perform a single task. It&#8217;s more like a Swiss [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Botnet running on MIPS CPU devices. by Psyb0t Evolves, Targets Unprotected Linux Mipsel Routers &#124; google android os blog</title>
		<link>http://www.teamfurry.com/wordpress/2009/03/23/botnet-running-on-mips-cpu-devices/#comment-329</link>
		<dc:creator>Psyb0t Evolves, Targets Unprotected Linux Mipsel Routers &#124; google android os blog</dc:creator>
		<pubDate>Wed, 25 Mar 2009 19:26:06 +0000</pubDate>
		<guid>http://www.teamfurry.com/wordpress/2009/03/23/botnet-running-on-mips-cpu-devices/#comment-329</guid>
		<description>[...] now appears to have returned, and evolved into a new beast, PSYB0T 2.9L, and it affects more than Netcomm NB5 devices. Approximately 30 Linksys devices, 10 Netgear models, and 15 other models and brands of DSL modems [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] now appears to have returned, and evolved into a new beast, PSYB0T 2.9L, and it affects more than Netcomm NB5 devices. Approximately 30 Linksys devices, 10 Netgear models, and 15 other models and brands of DSL modems [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Microsoft published a $250000 bounty on Downadup/Conficker by Microsoft назначил награду за создателя вируса &#124; Моя газета</title>
		<link>http://www.teamfurry.com/wordpress/2009/02/12/microsoft-published-a-250000-bounty-on-downadupconficker/#comment-326</link>
		<dc:creator>Microsoft назначил награду за создателя вируса &#124; Моя газета</dc:creator>
		<pubDate>Wed, 04 Mar 2009 14:57:49 +0000</pubDate>
		<guid>http://www.teamfurry.com/wordpress/2009/02/12/microsoft-published-a-250000-bounty-on-downadupconficker/#comment-326</guid>
		<description>[...] MW-Blog » Blog Archive » Microsoft published a $250000 bounty on &#8230; [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] MW-Blog » Blog Archive » Microsoft published a $250000 bounty on &#8230; [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Illusion - Now you see me, now you don&#8217;t by DDoS attack against abuse.ch &#124; abuse.ch</title>
		<link>http://www.teamfurry.com/wordpress/2007/10/16/illusion-now-you-see-me-now-you-dont/#comment-324</link>
		<dc:creator>DDoS attack against abuse.ch &#124; abuse.ch</dc:creator>
		<pubDate>Sat, 14 Feb 2009 11:51:54 +0000</pubDate>
		<guid>http://www.teamfurry.com/wordpress/2007/10/16/illusion-now-you-see-me-now-you-dont/#comment-324</guid>
		<description>[...] Source: MWBlog: &#8220;Illusion - Now you see me, now you don’t&#8221; [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] Source: MWBlog: &#8220;Illusion - Now you see me, now you don’t&#8221; [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Under the Hood: Virut by Virut - Personal Reflections &#171; Of Bytes and Badges</title>
		<link>http://www.teamfurry.com/wordpress/2007/02/15/under-the-hood-virut/#comment-323</link>
		<dc:creator>Virut - Personal Reflections &#171; Of Bytes and Badges</dc:creator>
		<pubDate>Thu, 12 Feb 2009 00:39:02 +0000</pubDate>
		<guid>http://www.teamfurry.com/wordpress/2007/02/15/under-the-hood-virut/#comment-323</guid>
		<description>[...] unleashed) back in 2007, an excellent write-up of the virus&#8217;s initial strain can be found here. Just ignore the domain name and you&#8217;ll appreciate some serious disassembly and analysis. [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] unleashed) back in 2007, an excellent write-up of the virus&#8217;s initial strain can be found here. Just ignore the domain name and you&#8217;ll appreciate some serious disassembly and analysis. [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on TOR exit-node doing MITM attacks by Disculpen las Molestias &#187; 2. Cifrado</title>
		<link>http://www.teamfurry.com/wordpress/2007/11/20/tor-exit-node-doing-mitm-attacks/#comment-322</link>
		<dc:creator>Disculpen las Molestias &#187; 2. Cifrado</dc:creator>
		<pubDate>Wed, 14 Jan 2009 22:00:13 +0000</pubDate>
		<guid>http://www.teamfurry.com/wordpress/2007/11/20/tor-exit-node-doing-mitm-attacks/#comment-322</guid>
		<description>[...] Lo peligroso que puede resultar usarlas sin informarse antes, y es que si bien se garantiza el anonimato dentro de la red, es posible capturar la información desde los nodos de salida a Internet. [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] Lo peligroso que puede resultar usarlas sin informarse antes, y es que si bien se garantiza el anonimato dentro de la red, es posible capturar la información desde los nodos de salida a Internet. [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Zeus/Wsnpoem/Zbot targets by Zero Day mobile edition</title>
		<link>http://www.teamfurry.com/wordpress/2008/11/04/zeuswsnpoemzbot-targets/#comment-321</link>
		<dc:creator>Zero Day mobile edition</dc:creator>
		<pubDate>Fri, 05 Dec 2008 15:37:09 +0000</pubDate>
		<guid>http://www.teamfurry.com/wordpress/2008/11/04/zeuswsnpoemzbot-targets/#comment-321</guid>
		<description>[...] - that modern banker malware is no longer exclusively targeting a particular E-banking site, but is targeting all of them simultaneously.  "The Trusteer Attack Trace search engine allows IT professionals to submit their organization's [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] - that modern banker malware is no longer exclusively targeting a particular E-banking site, but is targeting all of them simultaneously.  &#8220;The Trusteer Attack Trace search engine allows IT professionals to submit their organization&#8217;s [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on TOR exit-node doing MITM attacks by TOR Proxy network under heavy fire for MITM attacks</title>
		<link>http://www.teamfurry.com/wordpress/2007/11/20/tor-exit-node-doing-mitm-attacks/#comment-319</link>
		<dc:creator>TOR Proxy network under heavy fire for MITM attacks</dc:creator>
		<pubDate>Sat, 22 Nov 2008 06:38:43 +0000</pubDate>
		<guid>http://www.teamfurry.com/wordpress/2007/11/20/tor-exit-node-doing-mitm-attacks/#comment-319</guid>
		<description>[...] password and other sensitive information is possibly being snared by a hacker. In the following posting the gatherer is from [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] password and other sensitive information is possibly being snared by a hacker. In the following posting the gatherer is from [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on New worm on the loose by Secure San Diego &#187; Patch Or Die</title>
		<link>http://www.teamfurry.com/wordpress/2008/10/24/new-worm-on-the-loose/#comment-317</link>
		<dc:creator>Secure San Diego &#187; Patch Or Die</dc:creator>
		<pubDate>Sun, 02 Nov 2008 20:06:21 +0000</pubDate>
		<guid>http://www.teamfurry.com/wordpress/2008/10/24/new-worm-on-the-loose/#comment-317</guid>
		<description>[...] Another Good Entry - Team Furry [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] Another Good Entry - Team Furry [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on TOR exit-node doing MITM attacks by OpenSSL für gesamten Domain-Namespace sinnvoll - sharkBLOG</title>
		<link>http://www.teamfurry.com/wordpress/2007/11/20/tor-exit-node-doing-mitm-attacks/#comment-314</link>
		<dc:creator>OpenSSL für gesamten Domain-Namespace sinnvoll - sharkBLOG</dc:creator>
		<pubDate>Fri, 01 Aug 2008 21:35:59 +0000</pubDate>
		<guid>http://www.teamfurry.com/wordpress/2007/11/20/tor-exit-node-doing-mitm-attacks/#comment-314</guid>
		<description>[...] sich führen, da sonst man-in-the-middle möglich wäre (was z.B. bei Tor schon gang und gäbe ist: tor ssl man-in-the-middle). Hinzu kommt noch, dass ältere PCs ein bisschen länger brauchen (Schlüssel aushandeln, Daten [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] sich führen, da sonst man-in-the-middle möglich wäre (was z.B. bei Tor schon gang und gäbe ist: tor ssl man-in-the-middle). Hinzu kommt noch, dass ältere PCs ein bisschen länger brauchen (Schlüssel aushandeln, Daten [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on TOR exit-node doing MITM attacks by Wi-Fi security for road warriors: On-line banking &#124; Network Administrator &#124; TechRepublic.com</title>
		<link>http://www.teamfurry.com/wordpress/2007/11/20/tor-exit-node-doing-mitm-attacks/#comment-305</link>
		<dc:creator>Wi-Fi security for road warriors: On-line banking &#124; Network Administrator &#124; TechRepublic.com</dc:creator>
		<pubDate>Fri, 02 May 2008 04:24:37 +0000</pubDate>
		<guid>http://www.teamfurry.com/wordpress/2007/11/20/tor-exit-node-doing-mitm-attacks/#comment-305</guid>
		<description>[...] option: I would use an IronKey device to setup a TOR-like SSL session with known (known is important) IronKey TOR servers. Then I would login to the bank&#8217;s web server using the log on web page. [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] option: I would use an IronKey device to setup a TOR-like SSL session with known (known is important) IronKey TOR servers. Then I would login to the bank&#8217;s web server using the log on web page. [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on TOR exit-node doing MITM attacks by Volker noch immer in Macao</title>
		<link>http://www.teamfurry.com/wordpress/2007/11/20/tor-exit-node-doing-mitm-attacks/#comment-289</link>
		<dc:creator>Volker noch immer in Macao</dc:creator>
		<pubDate>Mon, 28 Jan 2008 07:22:20 +0000</pubDate>
		<guid>http://www.teamfurry.com/wordpress/2007/11/20/tor-exit-node-doing-mitm-attacks/#comment-289</guid>
		<description>&lt;strong&gt;Playing with TOR...&lt;/strong&gt;

I've been playing with  TOR  again lately, and a but more carefully because the last time I tried   michaelw   got banned from IRC because of the exit server :-D 


 It seems the crooks are really running it themselves these days. This is a "conversa...</description>
		<content:encoded><![CDATA[<p><strong>Playing with TOR&#8230;</strong></p>
<p>I&#8217;ve been playing with  TOR  again lately, and a but more carefully because the last time I tried   michaelw   got banned from IRC because of the exit server :-D </p>
<p> It seems the crooks are really running it themselves these days. This is a &#8220;conversa&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on TOR exit-node doing MITM attacks by Anonymity with TOR and its limits &#124; Perimeter Grid</title>
		<link>http://www.teamfurry.com/wordpress/2007/11/20/tor-exit-node-doing-mitm-attacks/#comment-278</link>
		<dc:creator>Anonymity with TOR and its limits &#124; Perimeter Grid</dc:creator>
		<pubDate>Mon, 10 Dec 2007 22:32:04 +0000</pubDate>
		<guid>http://www.teamfurry.com/wordpress/2007/11/20/tor-exit-node-doing-mitm-attacks/#comment-278</guid>
		<description>[...] a virus or Trojan.)  This actually happens; Bruce Schneier linked to some logs of a TOR exit node trying to carry out a MitM on an SSL session.  So while TOR protects your anonymity, it may actually risk your privacy &#8212; it&#8217;s very [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] a virus or Trojan.)  This actually happens; Bruce Schneier linked to some logs of a TOR exit node trying to carry out a MitM on an SSL session.  So while TOR protects your anonymity, it may actually risk your privacy &#8212; it&#8217;s very [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on TOR exit-node doing MITM attacks by foobla - das Weblog von Norbert Wigbels &#187; Blog Archive &#187; Wenn Kaspertruppen für Anonymität kämpfen&#8230;</title>
		<link>http://www.teamfurry.com/wordpress/2007/11/20/tor-exit-node-doing-mitm-attacks/#comment-273</link>
		<dc:creator>foobla - das Weblog von Norbert Wigbels &#187; Blog Archive &#187; Wenn Kaspertruppen für Anonymität kämpfen&#8230;</dc:creator>
		<pubDate>Fri, 07 Dec 2007 08:23:05 +0000</pubDate>
		<guid>http://www.teamfurry.com/wordpress/2007/11/20/tor-exit-node-doing-mitm-attacks/#comment-273</guid>
		<description>[...] 2 und [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] 2 und [&#8230;]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
