<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>inREVERSE</title>
	<atom:link href="http://www.inreverse.net/?feed=rss2" rel="self" type="application/rss+xml" />
	<link>http://www.inreverse.net</link>
	<description></description>
	<lastBuildDate>Mon, 06 Sep 2010 23:01:59 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Minifilters callbacks</title>
		<link>http://www.inreverse.net/?p=1334</link>
		<comments>http://www.inreverse.net/?p=1334#comments</comments>
		<pubDate>Mon, 06 Sep 2010 23:01:59 +0000</pubDate>
		<dc:creator>swirl</dc:creator>
				<category><![CDATA[internals]]></category>
		<category><![CDATA[kernel]]></category>
		<category><![CDATA[minifilter]]></category>
		<category><![CDATA[reversing]]></category>

		<guid isPermaLink="false">http://www.inreverse.net/?p=1334</guid>
		<description><![CDATA[Most security products today rely on minifilter drivers to monitor filesystem operations, and thus provide on-access capabilities, but are they checking if they&#8217;re really working ? Once you register a minifilter you can choose for each mounted volume if you want to filter operations on it, and in this case a new instance will be [...]]]></description>
		<wfw:commentRss>http://www.inreverse.net/?feed=rss2&amp;p=1334</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Dissecting Android Malware</title>
		<link>http://www.inreverse.net/?p=1272</link>
		<comments>http://www.inreverse.net/?p=1272#comments</comments>
		<pubDate>Tue, 10 Aug 2010 20:46:46 +0000</pubDate>
		<dc:creator>Donato "ratsoul" Ferrante</dc:creator>
				<category><![CDATA[Android]]></category>
		<category><![CDATA[java]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[reversing]]></category>

		<guid isPermaLink="false">http://www.inreverse.net/?p=1272</guid>
		<description><![CDATA[Hello, today I am going to explain how to approach the analysis of the new malware (md5: fdb84ff8125b3790011b83cc85adce16) that is targeting the Android platform. What is Android ? (wikipedia.org) &#8220;Android is an operating system for mobile devices such as cellular phones, tablet computers and netbooks. Android was developed by Google and is based upon the [...]]]></description>
		<wfw:commentRss>http://www.inreverse.net/?feed=rss2&amp;p=1272</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>About TmpHider/Stuxnet #1</title>
		<link>http://www.inreverse.net/?p=1246</link>
		<comments>http://www.inreverse.net/?p=1246#comments</comments>
		<pubDate>Thu, 15 Jul 2010 21:59:44 +0000</pubDate>
		<dc:creator>swirl</dc:creator>
				<category><![CDATA[internals]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[reversing]]></category>

		<guid isPermaLink="false">http://www.inreverse.net/?p=1246</guid>
		<description><![CDATA[Some info on this new malware spreading in these days under the name of TmpHider/Stuxnet Let&#8217;s start with the propagation method which is the only novel aspect about this malware. As already discussed and reported on multiple forums online, this particular piece of malware exploits some unidentified bug in the lnk file format to autostart [...]]]></description>
		<wfw:commentRss>http://www.inreverse.net/?feed=rss2&amp;p=1246</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
		<item>
		<title>Malware Analysis via Reflection</title>
		<link>http://www.inreverse.net/?p=1153</link>
		<comments>http://www.inreverse.net/?p=1153#comments</comments>
		<pubDate>Wed, 07 Jul 2010 21:54:24 +0000</pubDate>
		<dc:creator>Donato "ratsoul" Ferrante</dc:creator>
				<category><![CDATA[.NET]]></category>
		<category><![CDATA[java]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[reversing]]></category>

		<guid isPermaLink="false">http://www.inreverse.net/?p=1153</guid>
		<description><![CDATA[I am going to explain a quick and quite effective way to spot malicious content inside malware written with languages that support reflection. I am not going to reinvent the wheel, but I will show you how to combine the wheel and a little bit of brain to obtain a good result while dealing with [...]]]></description>
		<wfw:commentRss>http://www.inreverse.net/?feed=rss2&amp;p=1153</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Backdoor.Rohimafo</title>
		<link>http://www.inreverse.net/?p=1127</link>
		<comments>http://www.inreverse.net/?p=1127#comments</comments>
		<pubDate>Tue, 04 May 2010 10:07:58 +0000</pubDate>
		<dc:creator>swirl</dc:creator>
				<category><![CDATA[botnet]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[reversing]]></category>

		<guid isPermaLink="false">http://www.inreverse.net/?p=1127</guid>
		<description><![CDATA[Today (despite our DDoSer &#8220;friend&#8221;) we&#8217;re going to analyze a new sample (md5: 2e7ea8b3d9cda626cdd8d6557952245d) that currently is 4/41 on virustotal. Just two words on the packer: it checks if a file named systemroot\system32\drivers\vmscsi.sys exists ( the SCSI driver of VMWare) and if so exits, ExpandEnvironmentStringsA is used to retrieve the path, followed by a call [...]]]></description>
		<wfw:commentRss>http://www.inreverse.net/?feed=rss2&amp;p=1127</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>FakeAV Serial Fishing</title>
		<link>http://www.inreverse.net/?p=1089</link>
		<comments>http://www.inreverse.net/?p=1089#comments</comments>
		<pubDate>Fri, 23 Apr 2010 19:31:43 +0000</pubDate>
		<dc:creator>Donato "ratsoul" Ferrante</dc:creator>
				<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[reversing]]></category>

		<guid isPermaLink="false">http://www.inreverse.net/?p=1089</guid>
		<description><![CDATA[Hello, I am going to analyze a FakeAV (thanks to MDL) md5: 5493bb325f4b3a1cc6efab226d1c4600. This analysis will be focused on how to spot the serial checking algorithm and retrieve a valid serial. So we have to locate the routine that checks the serial provided and figure out how to craft a valid serial. Since the sample [...]]]></description>
		<wfw:commentRss>http://www.inreverse.net/?feed=rss2&amp;p=1089</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Botnet attack report</title>
		<link>http://www.inreverse.net/?p=1052</link>
		<comments>http://www.inreverse.net/?p=1052#comments</comments>
		<pubDate>Sat, 17 Apr 2010 13:54:21 +0000</pubDate>
		<dc:creator>InReverseCrew</dc:creator>
				<category><![CDATA[blog]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[ddos]]></category>

		<guid isPermaLink="false">http://www.inreverse.net/?p=1052</guid>
		<description><![CDATA[Hello dear readers, the last night we have been under an heavy DDoS attack (so lame!), caused by a botnet that has targeted our blog. Some Details. The following is a graphical analysis of the botnet that has conducted this attack: If you want to block these IPs, a partial list can be found here. [...]]]></description>
		<wfw:commentRss>http://www.inreverse.net/?feed=rss2&amp;p=1052</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>JAVA Malware evading decompilation</title>
		<link>http://www.inreverse.net/?p=1028</link>
		<comments>http://www.inreverse.net/?p=1028#comments</comments>
		<pubDate>Tue, 13 Apr 2010 19:51:19 +0000</pubDate>
		<dc:creator>Donato "ratsoul" Ferrante</dc:creator>
				<category><![CDATA[java]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[reversing]]></category>

		<guid isPermaLink="false">http://www.inreverse.net/?p=1028</guid>
		<description><![CDATA[Hello, some days ago Param (thanks!) one of our blog readers sent me a couple of undetected JAVA malwares, which I&#8217;m going to analyze, the md5 are: (Sample 1) 2138bfc0c92b726a13ff5095bd2f2b72 (Sample 2) a0585edf638f5d1c556239d3bfaf08db At this time, both of this malware have a low detection, the first one 1/42 and the second one 0/42 from VirusTotal. [...]]]></description>
		<wfw:commentRss>http://www.inreverse.net/?feed=rss2&amp;p=1028</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PDF CVE-2010-0188</title>
		<link>http://www.inreverse.net/?p=1008</link>
		<comments>http://www.inreverse.net/?p=1008#comments</comments>
		<pubDate>Sun, 11 Apr 2010 16:56:35 +0000</pubDate>
		<dc:creator>swirl</dc:creator>
				<category><![CDATA[PDF]]></category>
		<category><![CDATA[javascript]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[python]]></category>
		<category><![CDATA[reversing]]></category>
		<category><![CDATA[tiff]]></category>

		<guid isPermaLink="false">http://www.inreverse.net/?p=1008</guid>
		<description><![CDATA[While analyzing a recent pdf sample exploiting the TIFF vuln it used a known technique to obfuscate it&#8217;s content: it appends a pdf to the first one after a bunch of of &#8220;garbage&#8221; (that contains the dropped executables) %PDF-1.6 ... %%EOF [GARBAGE] %PDF-1.6 ... %%EOF I tried to run my extractor on the sample to [...]]]></description>
		<wfw:commentRss>http://www.inreverse.net/?feed=rss2&amp;p=1008</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>JAVA Malware Family</title>
		<link>http://www.inreverse.net/?p=987</link>
		<comments>http://www.inreverse.net/?p=987#comments</comments>
		<pubDate>Thu, 18 Mar 2010 00:15:03 +0000</pubDate>
		<dc:creator>Donato "ratsoul" Ferrante</dc:creator>
				<category><![CDATA[java]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[reversing]]></category>

		<guid isPermaLink="false">http://www.inreverse.net/?p=987</guid>
		<description><![CDATA[Hello guys, do you remember one of my last post about a JAVA malware exploiting a vulnerability related to the deserialization? If not, you can read it here. In the last days I have found a lot of variants of this malware. I picked for this post the following: sample 1: 3af7627af6348a76d1bf3b7bf31514e0 sample 2: a022524cb52223a939ba50043d90ff94 [...]]]></description>
		<wfw:commentRss>http://www.inreverse.net/?feed=rss2&amp;p=987</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>
