<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
	xmlns:media="http://search.yahoo.com/mrss/"
>

<channel>
	<title>Fortinet Security Blog &#187; virus bulletin</title>
	<atom:link href="http://blog.fortinet.com/tag/virus-bulletin/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.fortinet.com</link>
	<description>Real Time Network Protection</description>
	<lastBuildDate>Fri, 27 Jan 2012 11:59:33 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1.3</generator>
	<!-- podcast_generator="podPress/8.8" -->
		<copyright>&#xA9;Fortinet Product Marketing </copyright>
		<managingEditor>rpopko@fortinet.com (Fortinet Product Marketing)</managingEditor>
		<webMaster>rpopko@fortinet.com(Fortinet Product Marketing)</webMaster>
		<category>Fortinet Product Information</category>
		<ttl>1440</ttl>
		<itunes:keywords>forti-gate, anti-spam, anti-virus, fortigate</itunes:keywords>
		<itunes:subtitle>The latest news and information about Fortinet products and services for Real Time Network Protection.</itunes:subtitle>
		<itunes:summary>Fortinet is a leading provider of Unified Threat Management (UTM) network security solutions for enterprise and service provider environments. The Fortinet FortiCast delivers news, information, and tutorials about products, services, and industry trends. Fortinet's FortiGate product line and FortiGuard security subscription services provide an array of integrated network security functions including antivirus, firewall, virtual private networking, intrusion prevention (IPS), web filtering, antispam and traffic optimization. </itunes:summary>
		<itunes:author>Fortinet Product Marketing</itunes:author>
		<itunes:category text="Technology"/>
<itunes:category text="Technology">
  <itunes:category text="Tech News"/>
</itunes:category>
		<itunes:owner>
			<itunes:name>Fortinet Product Marketing</itunes:name>
			<itunes:email>rpopko@fortinet.com</itunes:email>
		</itunes:owner>
		<itunes:block>No</itunes:block>
		<itunes:explicit>no</itunes:explicit>
		<itunes:image href="http://blog.fortinet.com/wp-content/uploads/2009/01/forticast-300x300.jpg" />
		<image>
			<url>http://blog.fortinet.com/wp-content/uploads/2009/01/forticast-144x144.jpg</url>
			<title>Fortinet Security Blog</title>
			<link>http://blog.fortinet.com</link>
			<width>144</width>
			<height>144</height>
		</image>
		<item>
		<title>Dissecting Flash with EASE</title>
		<link>http://blog.fortinet.com/dissecting-flash-with-ease/</link>
		<comments>http://blog.fortinet.com/dissecting-flash-with-ease/#comments</comments>
		<pubDate>Thu, 06 Oct 2011 17:28:51 +0000</pubDate>
		<dc:creator>GLovet</dc:creator>
				<category><![CDATA[Research]]></category>
		<category><![CDATA[actionscript emulator]]></category>
		<category><![CDATA[ASLR]]></category>
		<category><![CDATA[DEP]]></category>
		<category><![CDATA[Flash emulator]]></category>
		<category><![CDATA[flash exploit]]></category>
		<category><![CDATA[unpacking]]></category>
		<category><![CDATA[virus bulletin]]></category>

		<guid isPermaLink="false">http://blog.fortinet.com/?p=3443</guid>
		<description><![CDATA[EASE stands for Experimental ActionScript Emulator, and besides being a pun of debatable quality, it is the in-house tool we at FortiGuard use to analyse malicious Flash samples, unpack obfuscated code (if applicable), and automatically detect heap spraying and JIT spraying (two techniques essential to bypass DEP/ASLR when exploiting a vulnerability). Adobe Flash being nearly [...]]]></description>
			<content:encoded><![CDATA[<p><a rel="attachment wp-att-3446" href="http://blog.fortinet.com/dissecting-flash-with-ease/flash-bgnew-2/"><img class="alignleft size-full wp-image-3446" title="Flash-BGnew" src="http://blog.fortinet.com/wp-content/uploads/2011/10/Flash-BGnew1.jpg" alt="" width="137" height="85" /></a></p>
<p><img src="file:///tmp/moz-screenshot.png" alt="" />EASE stands for Experimental ActionScript Emulator, and besides being a pun of debatable quality, it is the in-house tool we at FortiGuard use to analyse malicious Flash samples, unpack obfuscated code (if applicable), and automatically detect heap spraying and JIT spraying (two techniques essential to bypass DEP/ASLR when exploiting a vulnerability).</p>
<p>Adobe Flash being nearly ubiquitous today, this is quite a useful tool for analysts and security researchers alike. Now for the bad news, which actually lays in its very name: It&#8217;s experimental. But we have good news to balance that: FortiGuard researcher Bing Liu will <a href="http://www.virusbtn.com/conference/vb2011/abstracts/Liu.xml" target="_blank">detail EASE and demo it tomorrow at VirusBulletin 2011, in Barcelona</a>.</p>
<p>So, if you are interested in Flash malware or Flash exploits and you attend the conference, make sure not to miss Bing&#8217;s presentation.</p>
<p>And if you missed <a href="http://blog.fortinet.com/?s=crypto+girl" target="_blank">Crypto Girl</a>&#8216;s presentation yesterday, you can still catch her around the conference &#8211; she&#8217;s quite easy to spot with her superhero costume.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.fortinet.com/dissecting-flash-with-ease/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Asprox, the return</title>
		<link>http://blog.fortinet.com/asprox-the-return/</link>
		<comments>http://blog.fortinet.com/asprox-the-return/#comments</comments>
		<pubDate>Fri, 06 Nov 2009 18:00:15 +0000</pubDate>
		<dc:creator>DMaciejak</dc:creator>
				<category><![CDATA[Research]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[asprox]]></category>
		<category><![CDATA[vb conference]]></category>
		<category><![CDATA[virus bulletin]]></category>

		<guid isPermaLink="false">http://blog.fortinet.com/?p=708</guid>
		<description><![CDATA[Do you remember Asprox, the botnet that used SQL injection attacks combined with result from search engine like Google to automatically infect Microsoft IIS powered websites? We did a talk (slides) at last Virus Bulletin about that, and for about a month now, we&#8217;ve been seeing some new variants in the wild. Like last December, [...]]]></description>
			<content:encoded><![CDATA[<p>Do you remember Asprox, the botnet that used SQL injection attacks combined with result from search engine like Google to automatically infect Microsoft IIS powered websites? We did a <a id="hr_i" title="talk" href="http://www.fortiguard.com/papers/VB2009_Botnet-Powered_SQL_Injection_Attacks_-_A_Deeper_Look_Within.pdf">talk</a> (<a id="k2g4" title="slides" href="http://www.virusbtn.com/pdf/conference_slides/2009/Maciejak-Lovet-VB2009.pdf">slides</a>) at last Virus Bulletin about that, and for about a month now, we&#8217;ve been seeing some new variants in the wild.</p>
<p>Like last December, a blind SQL injection targeting ASP pages using Transact SQL is attempted using the following chain as a request argument:</p>
<p>DECLARE%20@S%20VARCHAR(4000);SET%20@S=CAST(0x4445434C41524520405420564&#8230;%20AS%20VARCHAR(4000));EXEC(@S)</p>
<p>Once decoded, it turns out this code tries to inject malicious javascript in the database contents, so nothing new here; the sample we have seen injected:</p>
<p>&lt;script src=hxxp://www.<em>bannerdriven</em>.<em>ru</em>/ads.js&lt;/script&gt;</p>
<p>As this string is concatenated with the HTML &lt;title&gt; tag, it&#8217;s easy to use Google to find more victims. Hundreds of websites have already been compromised. From what we saw, the injected javascript&#8217;s goal is to silently redirect users to malicious servers are located in Russia. Here is a non-exhaustive list:</p>
<p>www.ads-t.ru/ads.js<br />
www.bannert.ru/ads.js<br />
www.bannerdriven.ru/ads.js<br />
www.adtcp.ru/ads.js<br />
www.adbnr.ru/ads.js<br />
www.htmlads.ru/ads.js</p>
<p>These sites are set-up to trap victims using drive-by-download attacks. The web exploit toolkit powering those attacks was updated to also target latest vulnerabilities in Adobe Flash (swf files) and Adobe Reader (pdf files).</p>
<p>The injection vector is still the same as last year (vulnerable server-side scripts), however from the results we can get, there are still many web applications vulnerable to SQL injection attacks (and I believe this is a never-ending battle). So why should they look for another attack vector? Besides, the web exploit toolkit update ensure a steady rate of newly infected machines, and a constant growth of their Botnet.</p>
<p>At the VB conference, during the Q&amp;A session of our speech, a cunning attendee suggested that the positive side of last year&#8217;s ubiquitous Botnet-powered SQL injection campains was that at least, it served as a giant pen-test for the Web. Unfortunately, it seems that the pen-test aftermath, as alarming as it was, did not suffice to raise the awareness of webmasters to a point where cybercriminals would stop to have an endless supply of machines ready to be infected.</p>
<p>Did you update your third-party software recently?</p>
<p><strong>Fortinet customers are protected using Fortiguard IPS that detects malicious SQL queries in HTTP requests.</strong></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.fortinet.com/asprox-the-return/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Papers of VB2009</title>
		<link>http://blog.fortinet.com/papers-of-vb2009/</link>
		<comments>http://blog.fortinet.com/papers-of-vb2009/#comments</comments>
		<pubDate>Thu, 29 Oct 2009 18:03:14 +0000</pubDate>
		<dc:creator>DMaciejak</dc:creator>
				<category><![CDATA[Research]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[conference]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[paper]]></category>
		<category><![CDATA[sql injection]]></category>
		<category><![CDATA[threat level]]></category>
		<category><![CDATA[virus bulletin]]></category>

		<guid isPermaLink="false">http://blog.fortinet.com/?p=684</guid>
		<description><![CDATA[The papers Bryan, Guillaume and I presented at Virus Bulletin 2009 have been available on the FortiguardCenter since yesterday: &#8216;I am not a numero!&#8217;: assessing global security threat levels &#8211; Bryan Lu Fighting cybercrime: technical, juridical, and ethical challenges &#8211; Guillaume Lovet Botnet-powered SQL injection attacks: a deeper look within &#8211; David Maciejak &#38; Guillaume [...]]]></description>
			<content:encoded><![CDATA[<p>The papers Bryan, Guillaume and I presented at Virus Bulletin 2009 have been available on the FortiguardCenter since yesterday:</p>
<p><a id="fwgd" title="'I am not a numero!': assessing global security threat levels" href="http://www.fortiguard.com/papers/VB2009_I_am_Not_a_Numero_-_Assessing_Global_Security_Threat_Levels.pdf">&#8216;I am not a numero!&#8217;: assessing global security threat levels</a> &#8211; Bryan Lu</p>
<p><a id="hy:2" title="Fighting cybercrime: technical, juridical, and ethical challenges" href="http://www.fortiguard.com/papers/VB2009_Fighting_Cybercrime_-_Technical,Juridical_and_Ethical_Challenges.pdf">Fighting cybercrime: technical, juridical, and ethical challenges</a> &#8211; Guillaume Lovet</p>
<p><a id="xo4k" title="Botnet-powered SQL injection attacks: a deeper look within" href="http://www.fortiguard.com/papers/VB2009_Botnet-Powered_SQL_Injection_Attacks_-_A_Deeper_Look_Within.pdf">Botnet-powered SQL injection attacks: a deeper look within</a> &#8211; David Maciejak &amp; Guillaume Lovet</p>
<p>It&#8217;s the 4th year in a row that Fortinet has had at least one paper in the line-up, but the first time we hit a count of three presentations.</p>
<p>The conference was held last month in Geneva, Switzerland, and was quite exciting (see program <a id="lajo" title="here" href="http://www.virusbtn.com/conference/vb2009/programme">here</a>). Despite the economic situation, the number of attendants hit a record high this year &#8211; which was perceptible during the keynote presentation, but less so afterwards. It seems as if over time people are considering the conference more as a social and professional networking event than a presentation-driven one.</p>
<p>We did follow some presentations in the corporate and technical tracks, the latter slightly more crowded. There were some nice discussions around current topics such as <a id="o9vm" title="cloud computing" href="http://www.virusbtn.com/conference/vb2009/abstracts/RaduRagragio.xml">cloud computing</a> (Marian Radu and Hilda Larina Ragragio from <em>Microsoft</em>) or <a id="e16s" title="malware sandboxing" href="http://www.virusbtn.com/conference/vb2009/abstracts/Mandl.xml">malware sandboxing</a> (Thomas Mandl <em> Secure Business Austria/IKARUS Security Software, </em>Florian Nentwich <em> IKARUS Security Software</em>, Ulrich Bayer and Engin Kirda from <em>Vienna University of Technology/Institute Eurecom</em>), as well as more traditional <a id="sezm" title="static analysis" href="http://www.virusbtn.com/conference/vb2009/abstracts/DimakilingSengWu.xml">static analysis</a> (Elda Dimakiling,  Francis Allan Tan Seng and Scott Wu from  Microsoft) and <a id="ysws" title="botnet history" href="http://www.virusbtn.com/conference/vb2009/abstracts/LastMinute6.xml">botnet history</a> (<em>Erik Wu and Gunter Ollmann, Damballa</em>). I got particularly interested by the in-depth looks at some threats like <a id="g00r" title="Koobface" href="http://www.virusbtn.com/conference/vb2009/abstracts/LastMinute2.xml">Koobface</a> (Ryan Flores, Joey Costoya and Jonell Baltazar from Trend Micro) or vulnerabilities like MS08-067. Guillaume also shared a good presentation on poorly-known aspects of <a id="fqz3" title="fighting cyber-crime" href="http://www.virusbtn.com/conference/vb2009/abstracts/Lovet.xml">fighting cyber-crime</a>. Threats leveraging popular Internet web sites also had the honor of multiple presentations this year (especially <a id="kak1" title="Twitter" href="http://www.virusbtn.com/conference/vb2009/abstracts/LastMinute3.xml">Twitter</a> and <a id="ggpa" title="Facebook" href="http://www.virusbtn.com/conference/vb2009/abstracts/LastMinute2.xml">Facebook</a>).</p>
<p>In the upcoming events, I would love to see more discussion around mobile security. Besides the <a id="dlct" title="&quot;iPhone v3 malware vector&quot;" href="http://www.virusbtn.com/conference/vb2009/abstracts/LastMinute1.xml">&#8220;iPhone v3 malware vector&#8221;</a> presentation (Marius van Oers from McAfee), the only other one was &#8220;Mobile malware/security: iPhone in the enterprise,&#8221; but unfortunately, it was canceled. Nonetheless, this year&#8217;s  vintage of the iconic conference of the AV industry was good, and as always a perfect occasion to put faces on various names (and beers into various faces). I hope the 2010 one will be just as good, so&#8230; see you in Vancouver ?</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.fortinet.com/papers-of-vb2009/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Fortinet security experts to present at VB2009</title>
		<link>http://blog.fortinet.com/fortinet-security-experts-to-present-at-vb2009/</link>
		<comments>http://blog.fortinet.com/fortinet-security-experts-to-present-at-vb2009/#comments</comments>
		<pubDate>Tue, 15 Sep 2009 18:04:38 +0000</pubDate>
		<dc:creator>RPopko</dc:creator>
				<category><![CDATA[Research]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[anti-malware]]></category>
		<category><![CDATA[vb2009]]></category>
		<category><![CDATA[virus bulletin]]></category>

		<guid isPermaLink="false">http://blog.fortinet.com/?p=602</guid>
		<description><![CDATA[At next week&#8217;s Virus Bulletin VB2009 conference in Geneva, four members of the FortiGuard Global Security Research Team will be among the experts sharing their expertise on the topic of anti-malware. This is the fourth consecutive year that members of Fortinet&#8217;s seasoned research team have been on the roster of the event, which is in [...]]]></description>
			<content:encoded><![CDATA[<p>At next week&#8217;s Virus Bulletin <a href="http://www.virusbtn.com/conference/vb2009/index">VB2009</a> conference in Geneva, four members of the <a href="http://www.fortiguardcenter.com">FortiGuard Global Security Research Team</a> will be among the experts sharing their expertise on the topic of anti-malware. This is the fourth consecutive year that members of Fortinet&#8217;s seasoned research team have been on the roster of the event, which is in its 19th year.</p>
<p>Only 38 of more than 160 proposals were selected by the VB2009 committee for this year&#8217;s conference program. That said, here are the presentations to check out:</p>
<ul>
<li>&#8220;<a href="http://www.virusbtn.com/conference/vb2009/abstracts/Lovet.xml">Fighting cybercrime: technical, juridical and ethical challenges</a>,&#8221; Wednesday, September 23, 4:20 p.m. Speaker: Guillaume Lovet, Threat Response senior manager.</li>
<li>&#8220;&#8216;<a href="http://www.virusbtn.com/conference/vb2009/abstracts/Lu.xml">I am not a numero!&#8217;: assessing global security threat levels</a>,&#8221; Thursday, September 24, 10:40 a.m. Speaker: Bryan Lu, FortiGuard project manager.</li>
<li>&#8220;<a href="http://www.virusbtn.com/conference/vb2009/abstracts/Yang.xml">The hackpacker guide: an in-depth look into custom run-time packers</a>,&#8221; Thursday, September 24, 5:00 p.m. Speaker: Xu Yang, FortiGuard project manager.</li>
<li>&#8220;<a href="http://www.virusbtn.com/conference/vb2009/abstracts/MaciejakLovet-R.xml">Botnet-powered SQL injection attacks: a deeper look within</a>&#8221; Thursday, September 24, 4:20 p.m. Speakers: David Maciejak, IPS analyst, and Guillaume Lovet.</li>
</ul>
<p>Will you attend VB2009?</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.fortinet.com/fortinet-security-experts-to-present-at-vb2009/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

