<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Hinky's Proxy Obsession</title>
	<atom:link href="http://proxyobsession.net/?feed=rss2" rel="self" type="application/rss+xml" />
	<link>http://proxyobsession.net</link>
	<description>The Most Danger List on the Web</description>
	<lastBuildDate>Sun, 05 Sep 2010 14:13:04 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Scumbags Of Security Blogging</title>
		<link>http://proxyobsession.net/?p=1124</link>
		<comments>http://proxyobsession.net/?p=1124#comments</comments>
		<pubDate>Sun, 05 Sep 2010 14:13:04 +0000</pubDate>
		<dc:creator>hinkydink</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Scumbags]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://proxyobsession.net/?p=1124</guid>
		<description><![CDATA[Like a lot of folks in the security field, I follow a number of the Big Names in the industry, one of which is Dave Aitel, CIO of Immunity, Inc. Let me stress he is not a scumbag.  At least I don&#8217;t think he is.  He might be, but I don&#8217;t know him personally.  I [...]]]></description>
			<content:encoded><![CDATA[<p>Like a lot of folks in the security field, I follow a number of the Big Names in the industry, one of which is <a href="http://en.wikipedia.org/wiki/Dave_Aitel" target="_blank">Dave Aitel, CIO of Immunity, Inc</a>.</p>
<p>Let me stress he is <em>not </em>a scumbag.  At least <em>I </em>don&#8217;t think he is.  He might be, but I don&#8217;t know him personally.  I <em>assume </em>he&#8217;s a legitimate security professional—I&#8217;ve subscribed to his mailing list for years—but some of his <a href="http://groups.google.com/group/alt.sex.stories/browse_thread/thread/9273ec916c9032dd/6329ff9861c2c0b8?hl=en&amp;ie=UTF-8&amp;oe=utf-8&amp;q=The+Birth+of+a+Gay+Slut#6329ff9861c2c0b8" target="_blank">Usenet posts from the 90s</a> make me wonder.  Those are going to haunt you for years, Dave.</p>
<p>A couple of <a href="http://twitter.com/daveaitel" target="_blank">his tweets</a> that popped up today left me scratching my head.</p>
<p>One of them (and this is where the <em>real </em>scumbag enters the page) was for an SQL injection tool called BlindCAT that pointed to a site called PenTestIT.com, which I refuse to link to.  The download link for BlindCAT went through a service called LinkBucks.com, which was bad enough, but after that it pointed to an Indian (.in) domain.</p>
<p>I passed on that.  Get serious.  A Windows executable from India via a linkbait site?  uh-uh.  Not gonna happen.</p>
<p>I went back and started poking around PenTestIT and noticed that just about <em>all </em>their articles bounce through LinkBucks and <em>none </em>of  their content is original.  The <em>real </em>BlindCAT author&#8217;s page <em>appears </em>to be <a href="http://itsecuritylab.eu/index.php/tag/blind-cat/" target="_blank">here</a>, but I can&#8217;t vouch for it.  The PentestIT site has the top search result (<a href="http://www.google.com/search?q=blindcat+sql&amp;ie=utf-8&amp;oe=utf-8&amp;aq=t&amp;rls=org.mozilla:en-US:official&amp;client=firefox-a" target="_blank">search: blindcat sql</a>, no quotes), which is probably just SEO.</p>
<p>LinkBucks (<em>&#8220;LinkBucks allows you to make cash from the links your users post, from the links you place on your website, or from the posts you make in a forum&#8221;</em>) pops up a window with crappy links to articles about Paris Hilton, Justin Beiber, and Lindsay Lohan, people who I could care less about.</p>
<p>Tila Tequila, <em>maybe</em>, but Paris Hilton?  Lilo?  Jeeez.</p>
<p>All in all it was a very well done link trap site (WordPress).  If it weren&#8217;t for the ads, you&#8217;d think it was a legit security blog.</p>
<p><em>That</em>, my friends, is pure scumbaggery.</p>
<p>The next tweet that came out of Aitel&#8217;s account was in <em>Chinese </em>and pointed to <a href="http://www.baidu.com/" target="_blank">baidu.com</a>, which is China&#8217;s Google.  And just now another Chinese tweet came out of his account.  Translation: &#8220;So incredible is that I can read Chinese?&#8221;</p>
<p>So Dave, what&#8217;s the deal?  Did someone hack your Twitter account or have you started shilling with tweets?</p>
]]></content:encoded>
			<wfw:commentRss>http://proxyobsession.net/?feed=rss2&amp;p=1124</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Chinese Radio Station Problem</title>
		<link>http://proxyobsession.net/?p=1104</link>
		<comments>http://proxyobsession.net/?p=1104#comments</comments>
		<pubDate>Sat, 04 Sep 2010 14:39:06 +0000</pubDate>
		<dc:creator>hinkydink</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Chinese Radio]]></category>
		<category><![CDATA[Haxx]]></category>
		<category><![CDATA[Obfuscation]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://proxyobsession.net/?p=1104</guid>
		<description><![CDATA[The other day I was on a support call with a techie from a vendor that will remain nameless (go ahead&#8230; guess!).  We were watching some HTTP packets fly by with tcpdump when he suddenly said, &#8220;WTF is that?&#8221; &#8220;That&#8221; was along the lines of this: http://72.246.30.118/idle/Ga0mdz02wSLOaQ5Q/250 http://72.246.30.118/idle/Gx0mdz02xSLWq-NW/44 http://72.246.30.118/idle/Gx0mdz02xSLWq-NW/121 http://72.246.30.118/idle/Gx0mdz02xSLWq-NW/200 http://72.246.30.118/idle/Gx0mdz02xSLWq-NW/251 http://72.246.30.118/idle/Gx0mdz02xSLWq-NW/310 http://72.246.30.118/idle/Gx0mdz02xSLWq-NW/359 http://72.246.30.118/idle/Gx0mdz02xSLWq-NW/422 http://72.246.30.118/idle/Gx0mdz02xSLWq-NW/481 [...]]]></description>
			<content:encoded><![CDATA[<p>The other day I was on a support call with a techie from a vendor that will remain nameless (go ahead&#8230; <em>guess!</em>).  We were watching some HTTP packets fly by with tcpdump when he suddenly said, &#8220;WTF is <em><strong>that?</strong></em>&#8221;</p>
<p>&#8220;That&#8221; was along the lines of this:</p>
<p><span style="color: #ffff00; margin-left:30px;">http://72.246.30.118/idle/Ga0mdz02wSLOaQ5Q/250</span><br />
<span style="color: #ffff00; margin-left:30px;">http://72.246.30.118/idle/Gx0mdz02xSLWq-NW/44</span><br />
<span style="color: #ffff00; margin-left:30px;">http://72.246.30.118/idle/Gx0mdz02xSLWq-NW/121</span><br />
<span style="color: #ffff00; margin-left:30px;">http://72.246.30.118/idle/Gx0mdz02xSLWq-NW/200</span><br />
<span style="color: #ffff00; margin-left:30px;">http://72.246.30.118/idle/Gx0mdz02xSLWq-NW/251</span><br />
<span style="color: #ffff00; margin-left:30px;">http://72.246.30.118/idle/Gx0mdz02xSLWq-NW/310</span><br />
<span style="color: #ffff00; margin-left:30px;">http://72.246.30.118/idle/Gx0mdz02xSLWq-NW/359</span><br />
<span style="color: #ffff00; margin-left:30px;">http://72.246.30.118/idle/Gx0mdz02xSLWq-NW/422</span><br />
<span style="color: #ffff00; margin-left:30px;">http://72.246.30.118/idle/Gx0mdz02xSLWq-NW/481</span></p>
<p>More or less.  Lots of these suckers.  I see <em>millions </em>of them in my proxy logs every day.</p>
<p>This fellow had never seen these URLs before.  Odd because his company deals with URLs every day.  I just told him to add &#8220;not host 72.246.30.118&#8243; to his tcpdump command line and that got rid of it.</p>
<p>Well, the support call eventually ended.  Nothing was resolved, as usual.  But this article is not about him anyway.</p>
<p>That crap is Flash.  The URL never has a hostname.  It&#8217;s always an IP address and that address usually belongs to a CDN (Content Distribution Network).  The address above belongs to <a href="http://www.akamai.com/" target="_blank">Akamai</a>.  The second part of the URL is one of open/send/idle.  The third is some sort of content or user or session identifier.  The last part is obviously a sequence number.</p>
<p>If you frequent some sort of Internet Radio station while you&#8217;re at work and you play it all day and you leave work with your browser open to that site, you will generate tens of thousands of these URLs.  I&#8217;ve seen a single user drop a half a million of these a day.</p>
<p>Now, all you blackhat spooks out there <em>listen up</em>, because this is important.  If you don&#8217;t get it already, I&#8217;m going to spell it out.</p>
<p><em>This is a perfect covert channel.</em></p>
<p>Just faking these URLs offers excellent cover.  The &#8220;idle&#8221; URLs are all http POSTs.    You can send data out without raising red flags as long as you keep the packet size down.  A single /idle/ URL packs about 215 bytes, but the user will hit a single /idle/ URL 600-700 times, for a total of ~150K.  In the logs, looking for that kind of crap in a multi-user environment boils down to the &#8220;needle in a needlestack&#8221; problem.</p>
<p>You get the picture.</p>
<p>It gets better if you can do it over a CDN.  This is what I like to call &#8220;The Chinese Radio Station Problem&#8221;.  It&#8217;s a deep pockets hack, because you have to control the server.  The CDN serves to mask the real destination.  In my small little mind I see it as something an adversarial government has the resources to do.  Hence, Chinese.</p>
<p>Think about it.  It&#8217;s <em><strong>Flash</strong></em>, so there are plenty of known, unknown, and, shall we say,  &#8221;private label&#8221; vectors that can be leveraged to add a little <em>some-some </em>to an end-user&#8217;s PC.</p>
<p>What that some-some <em>is</em>, is up to you.  You are only limited by your imagination.</p>
<p>If you control the server, the user can still listen to Internet Radio while he sends you his company&#8217;s intellectual property.  Logged or not, it still looks like streaming media.</p>
<p>I would conjecture that most companies that block streaming media leave it open for C<em>x</em>Os, which is even better because they get the juiciest details on intellectual property.  You just need to know what kind of media they like.</p>
<p>And for employers who <em>don&#8217;t </em>block streaming media, there&#8217;s people like <a href="http://www.google.com/search?hl=en&#038;client=firefox-a&#038;rls=org.mozilla%3Aen-US%3Aofficial&#038;sout=1&#038;biw=1127&#038;bih=790&#038;q=Shirley+in+Accounts+Payable&#038;btnG=Search&#038;aq=f&#038;aqi=&#038;aql=&#038;oq=&#038;gs_rfai=" target="_blank" rel="nofollow">Shirley in Accounts Payable</a>, who has all the bank passwords and likes to listen to Christian music all day long.  Double cover.  Anything with &#8220;Christian&#8221; in it is above suspicion, right?</p>
<p>And what about <a href="http://www.google.com/search?hl=en&#038;client=firefox-a&#038;rls=org.mozilla:en-US:official&#038;sout=1&#038;q=tony%20lee%20in%20engineering%20-anthony&#038;um=1&#038;biw=1127&#038;bih=790&#038;ie=UTF-8&#038;sa=N&#038;tab=iw"  target="_blank" rel="nofollow">that Asian dude in Engineering, Tony Lee</a>?  What is he <a href="http://www.google.com/search?hl=en&#038;client=firefox-a&#038;rls=org.mozilla%3Aen-US%3Aofficial&#038;sout=1&#038;biw=1127&#038;bih=790&#038;q=chinese+radio+station&#038;aq=f&#038;aqi=g10&#038;aql=&#038;oq=&#038;gs_rfai="  target="_blank" rel="nofollow">listening to</a>?</p>
<p>Endless opportunity.</p>
]]></content:encoded>
			<wfw:commentRss>http://proxyobsession.net/?feed=rss2&amp;p=1104</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>2.9 Million Proxies</title>
		<link>http://proxyobsession.net/?p=1100</link>
		<comments>http://proxyobsession.net/?p=1100#comments</comments>
		<pubDate>Tue, 31 Aug 2010 09:39:14 +0000</pubDate>
		<dc:creator>hinkydink</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Proxy Count]]></category>
		<category><![CDATA[Proxy List]]></category>
		<category><![CDATA[tidnybbles]]></category>

		<guid isPermaLink="false">http://proxyobsession.net/?p=1100</guid>
		<description><![CDATA[Unless something extraordinary happens today, my previous prediction of &#8220;three million proxies by the end of August&#8221; is shot down. I have taken the time to spiff things up a bit.  I have added flags that were missing for one reason or another, including Greece (how did that get missed?), Hong Kong, some tiny island [...]]]></description>
			<content:encoded><![CDATA[<p>Unless something extraordinary happens today, my previous prediction of &#8220;three million proxies by the end of August&#8221; is shot down.</p>
<p>I have taken the time to spiff things up a bit.  I have added flags that were missing for one reason or another, including Greece (how did that get missed?), Hong Kong, some tiny island near Finland I forgot the name of, and &#8220;APAC&#8221;, short for &#8220;Asia/PACific&#8221; and <a href="http://www.maxmind.com/app/faq#EUAPcodes" target="_blank">a peculiarity of the Maxmind geoip database</a>.  I had been using the <a href="http://en.wikipedia.org/wiki/File:CadleFlagEarth.svg" target="_blank">flag of the Earth</a> for missing flags, but I was tired of looking at it.</p>
<p>Here and there a few duplicate proxies have popped up in <a href="http://www.mrhinkydink.com/proxies.htm" target="_self">the List</a>.  I scour the master database every day for dupes but some have escaped into the gold database.  Fixing that will only take a few minutes when I decide to get around to it.</p>
]]></content:encoded>
			<wfw:commentRss>http://proxyobsession.net/?feed=rss2&amp;p=1100</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PoTTy v0.60 Subject To DLL Hijacking</title>
		<link>http://proxyobsession.net/?p=1097</link>
		<comments>http://proxyobsession.net/?p=1097#comments</comments>
		<pubDate>Fri, 27 Aug 2010 14:54:43 +0000</pubDate>
		<dc:creator>hinkydink</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Haxx]]></category>
		<category><![CDATA[PoTTY]]></category>
		<category><![CDATA[Websense]]></category>

		<guid isPermaLink="false">http://proxyobsession.net/?p=1097</guid>
		<description><![CDATA[When I released PoTTy into the wild, I noted that I didn&#8217;t plan on supporting or improving it. However, this DLL hijack hack for PuTTy also works against PoTTy.  I suppose that&#8217;s expected, since they use the same code. So&#8230; I&#8217;d like to fix it.  The problem is, I&#8217;m not sure how to go about [...]]]></description>
			<content:encoded><![CDATA[<p>When I released PoTTy into the wild, I noted that I didn&#8217;t plan on supporting or improving it.</p>
<p>However, <a href="http://www.exploit-db.com/exploits/14796/" target="_blank">this DLL hijack hack for PuTTy</a> also works against PoTTy.  I suppose that&#8217;s expected, since they use the same code.</p>
<p>So&#8230; I&#8217;d <em>like </em>to fix it.  The problem is, I&#8217;m not sure how to go about doing that, but I am currently looking at <a href="http://msdn.microsoft.com/en-us/library/ff919712%28VS.85%29.aspx" target="_blank">this MSDN article</a> and scratching my head.</p>
<p>There are other motivations for hacking PoTTy as well.</p>
<p>My <a href="http://mrhinkydink.blogspot.com/2010/08/websenseisa-via-bypass-redux.html" target="_blank">Via Bypass Redux hack</a> will come in handy for a few months.  Long ago I considered building that functionality (adding arbitrary headers when connecting via proxy) into PoTTy, so I may be adding that in the future as well.</p>
<p>Still, I&#8217;m basically a lazy programmer.  But I am looking into the DLL fix now.</p>
]]></content:encoded>
			<wfw:commentRss>http://proxyobsession.net/?feed=rss2&amp;p=1097</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>TCP 9415 Proxies Brought To You By Network Solutions</title>
		<link>http://proxyobsession.net/?p=1095</link>
		<comments>http://proxyobsession.net/?p=1095#comments</comments>
		<pubDate>Wed, 18 Aug 2010 09:48:11 +0000</pubDate>
		<dc:creator>hinkydink</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Haxx]]></category>
		<category><![CDATA[KoobFace]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://proxyobsession.net/?p=1095</guid>
		<description><![CDATA[Reports of &#8220;millions of infected Web sites&#8221; in the past few days have been flooding the Intertubes.  These are due to a malware widget displayed on default parked pages at Network Solutions. According to this article the widget is dropping a Koobface variant primarily on Chinese browsers. One potentially limiting factor in this attack was [...]]]></description>
			<content:encoded><![CDATA[<p>Reports of &#8220;millions of infected Web sites&#8221; in the past few days have been flooding the Intertubes.  These are due to a malware widget displayed on default parked pages at Network Solutions.</p>
<p>According to <a href="http://krebsonsecurity.com/2010/08/networksolutions-sites-hacked-by-wicked-widget/" target="_blank">this article</a> the widget is dropping a Koobface variant primarily on Chinese browsers.</p>
<blockquote><p>One potentially limiting factor in this attack was that it seemed to target Chinese Web surfers. The malicious widget caused a fake message box to pop up, similar to a message prompt generated by the instant messaging client <a href="http://en.wikipedia.org/wiki/Tencent_QQ" target="_blank">Tencent QQ</a>. While this chat client is by far the most popular in China, it is probably unknown to most Westerners.</p></blockquote>
<p>It doesn&#8217;t take a genius to connect the dots on that one.</p>
]]></content:encoded>
			<wfw:commentRss>http://proxyobsession.net/?feed=rss2&amp;p=1095</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Via: 1.0 Thunder</title>
		<link>http://proxyobsession.net/?p=1092</link>
		<comments>http://proxyobsession.net/?p=1092#comments</comments>
		<pubDate>Wed, 18 Aug 2010 02:23:32 +0000</pubDate>
		<dc:creator>hinkydink</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[FAIL]]></category>
		<category><![CDATA[Mikrotik]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://proxyobsession.net/?p=1092</guid>
		<description><![CDATA[If you&#8217;ve been poking around the Brazilian proxies that have showed up in the past couple of days, you&#8217;re probably familiar with the Via header above. All of these proxies point to the same upstream server, which identifies itself as, you guessed it, &#8220;Thunder&#8221;.  And all appear to be running the same version of Mikrotik [...]]]></description>
			<content:encoded><![CDATA[<p>If you&#8217;ve been poking around the Brazilian proxies that have showed up in the past couple of days, you&#8217;re probably familiar with the Via header above.</p>
<p>All of these proxies point to the same upstream server, which identifies itself as, you guessed it, &#8220;Thunder&#8221;.  And all appear to be running the same version of <a href="http://wiki.mikrotik.com/wiki/Manual:RouterOS_features" target="_blank">Mikrotik routerOS</a>, judging by the presence of other open ports on the IP addresses.</p>
<p>Yes, it&#8217;s yet another flawed device roll-out.</p>
<p>This <a href="http://www.unigranrio.br/" target="_blank">fine learning establishment</a> is planting all these boxes as a part of their <a href="https://ead.unigranrio.edu.br/ead/" target="_blank">distance learning program</a>.  So, in a sense it&#8217;s a &#8220;Back to School Special&#8221;, Brazilian style!</p>
<p><a href="http://br.linkedin.com/pub/bruce-louren%C3%A7o/22/610/483" target="_blank">Here</a>&#8216;s one of their network techs!</p>
<p>I don&#8217;t expect these to be around for long (next Monday at the latest), but they <em>do </em>work.  The fact they&#8217;re all transparent proxies and all bounce to the same downstream IP severely limits their usefulness, but there they are.</p>
]]></content:encoded>
			<wfw:commentRss>http://proxyobsession.net/?feed=rss2&amp;p=1092</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>More Annoying JavaSHIT Obfuscation!</title>
		<link>http://proxyobsession.net/?p=1086</link>
		<comments>http://proxyobsession.net/?p=1086#comments</comments>
		<pubDate>Mon, 09 Aug 2010 17:30:25 +0000</pubDate>
		<dc:creator>hinkydink</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Haxx]]></category>
		<category><![CDATA[Obfuscation]]></category>
		<category><![CDATA[Proxy Lists]]></category>

		<guid isPermaLink="false">http://proxyobsession.net/?p=1086</guid>
		<description><![CDATA[Time and time again the bozos who run proxy lists try to come up with silly JavaSHIT schemes to prevent their pages from getting scraped by list raiders like me. Consider the following stupidity (click for a larger view): This is silly on a number of levels. First, anyone remotely concerned about online security (there&#8217;s [...]]]></description>
			<content:encoded><![CDATA[<p>Time and time again the bozos who run proxy lists try to come up with silly JavaSHIT schemes to prevent their pages from getting scraped by list raiders like me.</p>
<p>Consider the following stupidity (click for a larger view):</p>
<p style="text-align: center;"><a href="http://proxyobsession.net/wp-content/uploads/2010/08/anal1.jpg"><img class="aligncenter size-medium wp-image-1088" title="anal" src="http://proxyobsession.net/wp-content/uploads/2010/08/anal1-300x288.jpg" alt="" width="300" height="288" /></a></p>
<p>This is silly on a number of levels.</p>
<p>First, anyone remotely concerned about online security (there&#8217;s a couple of us) has JavaSHIT disabled 24&#215;7 and the last place they&#8217;d want to enable it would be on a freakin&#8217; proxy list site.</p>
<p>Second, that &#8220;eval(unescape(&#8230;&#8221; bullshit screams &#8220;HAXX!!!&#8221;</p>
<p>Third, this code simply unescapes to the html that would have been displayed had they not obfuscated it in the first place.  <em>What is the point?</em></p>
<p>And since it&#8217;s JavaSHIT, it&#8217;s easy to pull off the page and de-obfuscate.</p>
<p>I bring this up because I have been throwing out the unproductive sites I&#8217;ve been pulling data from.  Some have disappeared, including my very last, solid gold Russian proxy site.</p>
<p>Those are some big shoes to fill, so to replace it I Googled &#8220;proxy list&#8221; to see who&#8217;s getting all the hits these days.  For the most part it was the usual suspects, but there were a few new names so I looked into them.</p>
<p>And sure enough, most of them were using JavaSHIT obfuscation.  Even some of the old standby sites have been re-written to leverage JavaSHIT.</p>
<p>And I was surprised to find that I could actually get some good proxies from these sites.  THAT in itself is <em>very </em>unusual.  Typically you go through the hassle of unobfuscating this crap and it&#8217;s seldom worth the effort.</p>
<p>As usual, <em>you&#8217;re </em>the WINNER!</p>
]]></content:encoded>
			<wfw:commentRss>http://proxyobsession.net/?feed=rss2&amp;p=1086</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>TCP 9415 Proxies</title>
		<link>http://proxyobsession.net/?p=1080</link>
		<comments>http://proxyobsession.net/?p=1080#comments</comments>
		<pubDate>Fri, 06 Aug 2010 11:37:24 +0000</pubDate>
		<dc:creator>hinkydink</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Dead Proxies]]></category>
		<category><![CDATA[KoobFace]]></category>
		<category><![CDATA[Proxy Count]]></category>

		<guid isPermaLink="false">http://proxyobsession.net/?p=1080</guid>
		<description><![CDATA[Recently, a sharp-eyed reader noted that proxies on TCP port 9415 suck ass, and suggested they might be Koobface proxies.  So this morning I did a little reality check and found: They do suck ass They share some aspects of last year&#8217;s Koobface spread I did a special resurrection on every dead port 9415 proxy [...]]]></description>
			<content:encoded><![CDATA[<p>Recently, a sharp-eyed reader <a href="http://proxyobsession.net/?p=1074#comment-588" target="_self">noted</a> that proxies on TCP port 9415 suck ass, and suggested they might be Koobface proxies.  So this morning I did a little reality check and found:</p>
<ul>
<li>They <em>do </em>suck ass</li>
<li>They share some aspects of last year&#8217;s Koobface spread</li>
</ul>
<p>I did a special resurrection on every dead port 9415 proxy in the Gold Database (proxies verified at one time or another) and did some manual spot-checking.  In all, out of 5766 dead proxies I found fifteen live ones.  Most were located in China, Hong Kong, or Taiwan.  One was in Alberta, Canada.</p>
<p>The first one I found, in China, gave me two pages before it started resetting connections.</p>
<p>The Canadian proxy &#8211; apparently a Shaw Cable residential account &#8211; was fine.  It was perky and never refused a request.</p>
<p>However, I just now re-checked it and it&#8217;s timing out.</p>
<p>Several of the others simply returned the text string &#8220;error&#8221; to the browser.</p>
<p>Some took forever and never returned anything.</p>
<p>This <a href="http://www.ipa.go.jp/security/english/virus/press/201005/E_PR201005.html" target="_blank">report from Japan</a> offers some interesting insights:</p>
<blockquote><p><em><span style="color: #ffff99;">As for 9415/tcp, access from multiple sources in  overseas (mainly  China) observed at multiple monitoring points &#8230; has  been on the  rise since March.</span></em></p></blockquote>
<p>When I look at the Big Database (all proxies scraped but not verified) I see approximately the same results just eyeballing the data, but I see the activity starting way back in August 2009.</p>
<p>It really takes off by the middle of May 2010.  A quick query shows that 60% of all 9415 proxies were discovered after May 15th.</p>
<p>In all there are over 170,000 port 9415 proxies in the database, which would make a decent botnet.</p>
<p>Coincidentally, <a href="http://proxyobsession.net/?p=740" target="_self">Koobface &#8220;bloomed&#8221; in May of 2009</a>.</p>
<p>I&#8217;ve always said this was a seasonal business.</p>
]]></content:encoded>
			<wfw:commentRss>http://proxyobsession.net/?feed=rss2&amp;p=1080</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>419 SPAM From a Texas Hospital</title>
		<link>http://proxyobsession.net/?p=1074</link>
		<comments>http://proxyobsession.net/?p=1074#comments</comments>
		<pubDate>Sun, 11 Jul 2010 18:24:50 +0000</pubDate>
		<dc:creator>hinkydink</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[169% PWN3D]]></category>
		<category><![CDATA[FACEBOOK]]></category>
		<category><![CDATA[SPAM]]></category>

		<guid isPermaLink="false">http://proxyobsession.net/?p=1074</guid>
		<description><![CDATA[I have a lot of security delicacies &#8220;on my plate&#8221; but SPAM isn&#8217;t one of them.  Back at the salt mines, that&#8217;s someone else&#8217;s problem.  Suffice to say I&#8217;ve ignored the subject for years, considering it&#8217;s fairly well handled by all the Web mail accounts I have floating around (Yahoo, Hotmail, Gmail, et cetera). I never even [...]]]></description>
			<content:encoded><![CDATA[<p>I have a lot of security delicacies &#8220;on my plate&#8221; but SPAM isn&#8217;t one of them.  Back at the salt mines, that&#8217;s someone else&#8217;s problem.  Suffice to say I&#8217;ve ignored the subject for years, considering it&#8217;s fairly well handled by all the Web mail accounts I have floating around (Yahoo, Hotmail, Gmail, <em>et cetera</em>).</p>
<p>I never even look at the stuff.</p>
<p>However, there is this woman &#8211; let&#8217;s call her &#8220;Helen Dink&#8221; &#8211; who is no relation to me but by some strange quirk of fate we share the same ISP.  She <em>believes </em>her e-mail address is hdink@myisp.com, but it&#8217;s not.  That&#8217;s <em>my </em>email address.  I&#8217;ve had that address for almost ten years now, but whenever she goes to fill out Web forms online <em>she plugs in my email address!</em></p>
<p>So I get <em>a lot </em>of her email.</p>
<p>This has been going on for at least five years.  I know more about this woman than I want to (yes, she&#8217;s a Facebook user).  Her friends constantly send me email about a variety of crap, from Girl Scout meeting notices to recipes and the like.  It&#8217;s <em>incredibly annoying </em>and for the past few years I&#8217;ve been writing them back and letting them know, in no uncertain terms that I am <em>not </em>&#8220;Helen Dink&#8221; and to please remove my email address from their &#8220;Contacts&#8221; folder.</p>
<p>So today I got an email from &#8220;Andrea Wilson&#8221;, a normal-sounding American name.  Thinking it&#8217;s one of Helen&#8217;s buddies I open it up in order to send my standard reply to these things.</p>
<p>But it&#8217;s not.  It&#8217;s a 419 scam email&#8230;</p>
<blockquote><p>I am Golan Bradley a staff of Natwest Bank ,I am pleased to pass across to you a very urgent and profitable business proposal which I believe will profit the both of us after completion.I will await to receive a positive response from you to enable me give more details Please send your confidential telephone and fax number in your reply to: golan.bradley@removed.com Golan Bradley(Mr.)</p></blockquote>
<p>The security wonk inside me kicks in and I decide to look at the SMTP headers, thinking I&#8217;d be able to track it back to Nigeria or Cameroon (hi, fellas!).</p>
<p>But the headers were extremely legit.  The email went through 2 Exchange servers, a Symantec Brightmail Gateway (an anti-SPAM device), and a ZIX encryption device before ending up at my ISP.</p>
<p>&#8220;Andrea Wilson&#8221; turns out to be a Real Person™  who works at <a href="http://www.memorialhermann.org/Default.aspx" target="_blank">a hospital in Texas</a>.  And, not surprisingly, she&#8217;s an active Facebook user.  Obviously her workstation or laptop or whatever had been summarily pwn3d and was being used to deliver 419 SPAM for person or persons unknown.</p>
<p>Well, that&#8217;s <em>her </em>problem.</p>
<p>I briefly toyed with the idea of writing her back and suggesting she have the IT department check out her box, but that&#8217;s a notoriously bad idea and generally frowned upon (this comes from the heyday of email viruses, when sending a &#8220;HEY ASSHOLE YOUR COMPUTER HAS A VIRUS&#8221; email only served to exacerbate the problem).</p>
<p>Maybe I&#8217;ve been away from SPAM for too long, but it seems unusual to see legitimate SMTP headers from an obviously corporate environment, considering that lately the vast majority of SPAM comes from Yahoo, Gmail, Hotmail, <em>et cetera</em>.</p>
<p>Everything old is new again.</p>
]]></content:encoded>
			<wfw:commentRss>http://proxyobsession.net/?feed=rss2&amp;p=1074</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Fucking Snort&#8230; 64bit Edition</title>
		<link>http://proxyobsession.net/?p=1071</link>
		<comments>http://proxyobsession.net/?p=1071#comments</comments>
		<pubDate>Thu, 01 Jul 2010 16:11:58 +0000</pubDate>
		<dc:creator>hinkydink</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Haxx]]></category>
		<category><![CDATA[snort]]></category>

		<guid isPermaLink="false">http://proxyobsession.net/?p=1071</guid>
		<description><![CDATA[I built 64bit snort (x86-64) on my old friend, Debian 4 (&#8220;etch&#8221;) and had lots of fun doing it. It wasn&#8217;t quite as hard as I thought it would be, but there were a number of stumbling blocks, so I thought I&#8217;d post them here if anyone runs across the same issues. First, our old [...]]]></description>
			<content:encoded><![CDATA[<p>I built 64bit snort (x86-64) on my old friend, Debian 4 (&#8220;etch&#8221;) and had lots of fun doing it.</p>
<p>It wasn&#8217;t quite as hard as I thought it would be, but there were a number of stumbling blocks, so I thought I&#8217;d post them here if anyone runs across the same issues.</p>
<p>First, our old pal Libnet1.02a is so fucking ancient it predates the AMD64 processor.  The Makefile simply barfs with an &#8220;unknown platform&#8221; error.  This was easy enough to fix.  First, locate line #172, which should be a comment starting with  &#8221;Recognize the basic CPU types&#8221; (duh).  Right under that line should be a line starting with &#8220;vax-*&#8221;.  Edit that line to include &#8220;| x86_64-* |&#8221;.  No quotes, as usual.  Run configure, make, make install and that issue is over and done with.</p>
<p>Libdnet was the next big issue, and it was a problem on my 32bit Deb4 system as well.  Normally I hack shit together in /usr/local/src and libs fall into /usr/local/lib.  Unfortunately, libdnet doesn&#8217;t like living there and you can run ldconfig all day long and snort will still bitch about not being able to find it.</p>
<p>So start with &#8220;./configure &#8211;prefix=/usr&#8221; and <em>that </em>problem goes away.</p>
<p>I had to build a few things from scratch because Georgia Tech (<em>gtlib.gatech.edu</em>), my favorite apt repository (they seem to be the fastest around),  apparently stopped mirroring 64bit Deb4 and I was too lazy to look for a working repository.  You shouldn&#8217;t have this problem.  I had to build libpcap, flex, and bison from source but there were <em>zero </em>issues with any of those.</p>
<p>It took a while to come up with a decent config for snort but what I finally used was this:</p>
<div style="margin-left: 75px;">./configure &#8211;prefix=/usr \<br />
&#8211;sysconfdir=/ \<br />
&#8211;localstatedir=/ \<br />
&#8211;enable-react &#8211;enable-flexresp2 \<br />
&#8211;enable-build-dynamic-examples &#8211;with-zlib \<br />
&#8211;with-libnet-includes=/usr/include \<br />
&#8211;with-libnet-libraries=/usr/lib \<br />
&#8211;enable-decoder-preprocessor-rules \<br />
&#8211;enable-targetbased &#8211;enable-64bit-gcc</div>
<p>Some of that may be unnecessary.  The dynamic examples are buggy and you&#8217;ll end up deleting them anyway (you&#8217;ll figure it out &#8211; trust me).</p>
<p>Once building snort64 was out of the way, I downloaded the rule set and tried out the different pre-compiled &#8220;so&#8221; (Shared Object) rules.</p>
<p><em>None of them worked.</em></p>
<p>That is of course <em>my problem </em>for using an ancient (2006) version of 64bit Debian.  There are a limited number of pre-compiled preprocessors for x86_64 and none are compatible with Deb4 (they all want &#8216;GLIBC_2.4&#8242;, which Debian 4.0 doesn&#8217;t have).</p>
<p>This is not going to be a problem for you folks on the cutting edge of Linux.  If I was running Lenny (I hate Lenny with a passion) I&#8217;m sure I could have used one of the 64bit pre-compiled preprocessors for Ubuntu.</p>
<p>But I&#8217;m not, so I had to roll my own.  And that&#8217;s when it got ugly.</p>
<p>Due to &#8220;contractual obligations&#8221; (NDAs no doubt), snort/SourceFire is only allowed to distribute certain rules in binary format.  They include the source for the non-NDA rules, but how to actually compile them is a trip into Undocumented Territory (&#8220;here be monsters&#8221;).</p>
<p>Sure, there&#8217;s a README file but all it does is explain their legal obligations and reassure you that one of the the pre-compiled preprocessors <em>should </em>work.  That&#8217;s it.  <em>That&#8217;s all it says.</em></p>
<p>Thanks, Marty.</p>
<p>But there <em>is </em>a Makefile, so you&#8217;re halfway there.  I had to do the following to build the so preprocessors.</p>
<p>First, copy all the files in the src folder (that came with your VRT rules) into the folder where your snort source lives.  I called the folder &#8220;so_rules&#8221;.  Then fix the locations in the Makefile, like so (assuming you installed the snort source in /usr/src):</p>
<div style="margin-left: 30px;">BASEDIR=/usr/local/src/snort-2.8.6<br />
ENGINEDIR=$(BASEDIR)/src/dynamic-plugins/sf_engine<br />
PLUGINDIR=$(BASEDIR)/src/dynamic-plugins<br />
ENGINE=$(BASEDIR)/src/dynamic-plugins/sf_engine/.libs/libsf_engine.so<br />
SNORT=$(BASEDIR)/src/snort</div>
<p>Note the variable $SNORT assumes snort is already built and living in your source folder.</p>
<p>Then, comment out the line that begins with &#8220;PATH&#8221; because I absolutely guarantee you don&#8217;t have an Intel compiler.</p>
<p>Now, find the line that start with &#8220;libs :=&#8221; and remove the following:</p>
<div style="margin-left: 75px;"><strong>pop3<br />
web-activex<br />
web-iis<br />
icmp<br />
sql</strong></div>
<p>These must be the NDA-disqualified shared objects because there is <em>no source </em>to build them from.</p>
<p>Next, just for fun, find and comment out this line:</p>
<div style="margin-left: 50px;">MYCFLAGS+= -DMISSING_DELETED=1</div>
<p>Why?  Check out the &#8220;deleted.rules&#8221; file that came with your VRT rules.  There is a lot of old crap you may never see again, but you never know.</p>
<p>Save the Makefile and type &#8220;make&#8221; inside the so_rules folder (<em>not </em>the toplevel make).  If all goes well, move the *.so files you just built to a folder under /etc/snort (I used &#8220;so_64&#8243;) and edit your snort.conf file to point to them (the very last line in the &#8220;Step 4&#8243; part of snort.conf).</p>
<p>Finally, test your new config out and see what happens. You should see &#8220;166 preprocessor rules&#8221; intead of &#8220;0 preprocessor rules&#8221; now and 13 new &#8220;Rules Object&#8221; entires (I&#8217;m using the May 2010 VRT set, so YMMV).</p>
<p>Again, you shouldn&#8217;t have to go through this crap if you have a relatively modern 64bit distro of Linux (newer than 2006 I&#8217;d say) since the distributed shared objects <em>should </em>run just fine.</p>
<p>What do Windows users do about the lack of shared object rules?  Suffer, I guess, since there are no pre-compiled binaries, 32 or 64bit.</p>
<p>Hopefully, SourceFire will fix that soon.</p>
<p>Are you listening, Marty?</p>
]]></content:encoded>
			<wfw:commentRss>http://proxyobsession.net/?feed=rss2&amp;p=1071</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
