MaS is about computer security, malware and spam issues in general.

2008/04/22

Virus calendar


Gosh, what a blast from the past. Way, way back in the annals of time it was actually possible to analyze malware (OK, viruses mainly) well enough to know all trigger dates of their payloads. So, I thought I'd create a virus calendar. I think the first was created for the year 1990 or 1991 for the Virus Test Center so that we'd have something fun to show at expos like CeBIT. Then I got a commission to create one (and later another one) for perComp Verlag which they dug up recently and posted on their site for the years 1992 and 1993. While the 1992 version was mainly my work, I think I only contributed data and ideas to the 1993 version. Apparently some people in Germany still show excerpts of these calendars in presentations, though I shudder to think why. I think S&S International Ltd, UK also created a few calendars based on their own data and graphics, but after 1995 it became impossible to analyze all known viruses and even if it was possible, it would have been one crowded calendar!
This is one rare moment, where I was able to do something graphical in the context of computer security.
I think when I get back home, I'll dig out the original and scan that in, too!

2008/03/10

OT: Splint


Just when I had accumulated a few things to blog about again (thought time is still a precious resource) I manage to hurt my middle finger bad enough to warrant a splint. My thumb was already hurt from a small skiing accident. That is going to put a damper on my blogging and other writing.
It's going to have to stay on for six weeks. Ugh. I guess I should look around for one handed keyboards!

2008/01/19

Survey of disassemblers


As the preparation for my course on Data Communications Forensics and Security this term, I've decided to to do a quick survey of disassemblers. The problem is that I've been writing my own disassemblers for special purposes, but I need to have something more general purpose for the students. Also, the code I wrote stayed with IBM when I left. Here is a quick survey of what I've found so far, in no particular order.
  1. Let's start out with the reigning King of disassembly, IDA Pro. This is more a disassembler framework than just a disassembler only. As of Jan 2008 they've moved it from the old DataRescue website (and presumably distributor) to the new Hex-Ray site. It's up to version 5.2 and there are quite a few plug-ins for it and this is clearly the strength of IDA Pro. Unfortunately, they want serious money for it and the University isn't interested in paying. I'm also a bit concerned about the move to Hex-Ray. What does it mean?? Will it survive. I'd also like something that came with source code.
  2. Sourcer doesn't seem to exist any more. V-Communication's website doesn't seem to list it. Sourcer used to be my favorite disassembler before I got into writing my own.
  3. Apparently ASMGen is still around, but I think it is stuck in the 16bit MS-DOS world. It was basic back then and must be antique now. I'll give it a spin and see.
  4. Jean-Louis SEIGNE's disasm32 is apparently a VxD disassembler according to his own website and it is available via WinSite. (Another website seems to indicate it is a visual disassembler, I'll find out what I get the chance to run it.) It seems to be at least 12 years old, so I don't think it will be that interesting.
  5. I can't find WDASM, so it is probably dead.
  6. Obj2asm is an MS-DOS object file disassembler and is available on Simtel.
  7. The New Jersey Machine-Code Toolkit also seems to have been discontinued back in 1998. It's written in SML and utilizes a machine model for disassembly (amongst other things) which should give it a lot of flexibility. However, it doesn't help if the project has been abandoned.
  8. GNU offers a lineup of surprisingly useful tools in its binutils package. Quoting: "nm - Lists symbols from object files. objdump - Displays information from object files. readelf - Displays information from any ELF format object file. strings - Lists printable strings from files. " They are meant for UNIX and so are not that useful for Windows. However, in theory the should be able to handle PE files, but they are not robust or endian agnostic.
  9. OllyDebug is not a disassembler, but a debugger. However, quite a few people use it for program analysis either to aid the disassembly or to produce the disassembly. It's free and one of the best.
  10. Although not actually a disassembler, REC attempts to decompile from binary to source. It uses the netwide disassembler for preprocessing, according to the documentation.
  11. The Netwide Disassembler is a part of the Netwide Assembler project. It doesn't actually understand the various binary file formats itself, so you have to give it the naked binary code. I've used this and objdump in my projects. It is far more useful than it sounds like. Consider that a certain amount of malware can only be snagged from memory.
  12. Boomerang is another decompiler (versus a disassembler). It was active until 2006, so I'll have to see where it stands.
  13. The diStorm project looks very very interesting to me in that they want to create a really good library for disassembly, not just a disassembler. This will not be for the casual disassembler. The core library is written in C (source is available, I think) and it interfaces with Python, which wouldn't have been my choice. They also have separated the opcode libraries from the code (again, according to the documentation) which makes it easier to repurpose the code, though I always wonder how much real mileage you get from it.
The open directory project lists a few more here.
Another mention is Wotsit. This site has been very useful over the years in figuring out various file formats (I'm a file format hacker at heart, but long inactive.) You need this site to figure out the various binary file formats.
So, the next step in this exercise is to evaluate the best candidates and see how well they will do in practice. That will be in some later post.

2007/12/24


The the BBC article, Assurances over US biometric data, "Mr [Thomas] Bush told the BBC that innocent people would have nothing to fear from the database". Yeah, and I have a bridge to sell you too! How can they say that with a straight face after all the recent corporate and governmental data loss.
I don't want to say that it is easy to implement security that prevents the misuse of such data, but it can be done to a degree, but I doubt that it is happening.
So, we are going to risk our data over a pretty dubious undertaking. Sigh.

2007/12/19

Master Data Management


I used to secretly make fun of the problems large companies have in keeping their data under control. They would have these databases full of customer data - all of unknown and at best dubious quality. Surely, these large companies would have their master data management under control.
I guess this is where we in research just assume things that are just not true in reality. I got involved with the Data Quality issues as a part of my study of Data Centric Security which had led us in the direction of Master Data Management. If you can't trust the quality of your data, then Data Centric Security would be of limited use, so Master Data Management became important to us, and not only for that reason.
The whole thing hit home with me when I was compiling my xmas card list. My own very limited address book is a total mess. Why? For the same reasons that large databases become a mess over time: I've been merging data in from various sources, synchronizing with my Nokia E61i that gets updated in the field. Each source has its own semantics (and syntax, too!) which means that the brute force, just-shovel-it-all-in-there, method just makes a mess of it. So, now I have my own Master Data Management problem to deal with. I guess I should apply the DCS principles to this problem...

2007/11/28

Spam like a pirate


Ok, usually I don't read my spam, but this caught my eye:

Subject: in waiting

Ooh u, bonny varmint. ya do have eyes for a gratis French stuff, I know it. But damn, who do not. Visit me and ball off on my pictures, my dear.

and then the web site, replacing the dots with spaces to foil spam filters and some very unusual junk words. I'm not sure how it got through the filters (and I'm not really that concerned. But, at least it was kind of poetic.

[Picture credits: http://flickr.com/photos/earlg/ used under the creative commons license]