<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title> &#187; Info</title>
	<atom:link href="http://www.megapanzer.com/category/info/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.megapanzer.com</link>
	<description></description>
	<lastBuildDate>Fri, 23 Dec 2011 13:02:33 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3</generator>
		<item>
		<title>AyCarrumba &#8230; testing</title>
		<link>http://www.megapanzer.com/2011/12/23/aycarrumba-testing/</link>
		<comments>http://www.megapanzer.com/2011/12/23/aycarrumba-testing/#comments</comments>
		<pubDate>Fri, 23 Dec 2011 13:02:33 +0000</pubDate>
		<dc:creator>carrumba</dc:creator>
				<category><![CDATA[Info]]></category>
		<category><![CDATA[Tools & sources]]></category>

		<guid isPermaLink="false">http://www.megapanzer.com/?p=5945</guid>
		<description><![CDATA[Well, the last missing features like depoisoning, correctly working half-duplex MITM with ARP poisoning and parsing DNS requests are finally implemented. Testing outside my own test environment will start at about 26. december. Bugfixing will take some time and I think after new year version 1.0 is available for download. 15/18 Dec. as dead line [...]]]></description>
			<content:encoded><![CDATA[<glossarycode><glossarycode><p><img src="http://www.megapanzer.com/wp-content/uploads/information-150x150.jpg" alt="" title="information" width="75" height="75" class="alignright size-thumbnail wp-image-2871" />Well, the last missing features like depoisoning, correctly working half-duplex <a class="glossaryLink" href="http://www.megapanzer.com/?page_id=1430" title="Glossary: MITM" target="_blank">MITM</a> with ARP poisoning and parsing DNS requests are finally implemented. Testing outside my own test environment will start at about 26. december. <a class="glossaryLink" href="http://www.megapanzer.com/" title="Glossary: Bug" target="_blank">Bugfixing</a> will take some time and I think after new year version 1.0 is available for download.</p>
<p>15/18 Dec. as dead line didn&#8217;t work. Sorry for that but as it is a private project without commercial interests, withouth stakeholders and so no pressure from outside : it&#8217;s there when it&#8217;s there.</p>
<p>Also I think some lines about the motivation behinde this project, the objectives and counter measures are necessary so also people without deeper technical background can see, understand and mainly react appropriately to this situation. </p></glossarycode></glossarycode>]]></content:encoded>
			<wfw:commentRss>http://www.megapanzer.com/2011/12/23/aycarrumba-testing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>AyCarrumba</title>
		<link>http://www.megapanzer.com/2011/12/01/aycarrumba/</link>
		<comments>http://www.megapanzer.com/2011/12/01/aycarrumba/#comments</comments>
		<pubDate>Thu, 01 Dec 2011 11:06:25 +0000</pubDate>
		<dc:creator>carrumba</dc:creator>
				<category><![CDATA[Info]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://www.megapanzer.com/?p=5926</guid>
		<description><![CDATA[The last weeks were quite intensive. In theorie it looked plausible and logical but while putting the plan into practise some obstacles had to be overcome, namely getting back into libpcap, ARP man in the middle and TCP stream reassembly. I&#8217;m on track and the deadline (between 15. and 18. December) is still realistic &#8230; [...]]]></description>
			<content:encoded><![CDATA[<glossarycode><p><img src="http://www.megapanzer.com/wp-content/uploads/App-150x150.jpg" alt="" title="App" width="75" height="75" class="alignright size-thumbnail wp-image-3567" />The last weeks were quite intensive. In theorie it looked plausible and logical but while putting the plan into practise some obstacles had to be overcome, namely getting back into libpcap, ARP <a class="glossaryLink" href="http://www.megapanzer.com/?page_id=1428" title="Glossary: Man in the middle" target="_blank">man in the middle</a> and TCP stream reassembly. I&#8217;m  on track and the deadline (between 15. and 18. December) is still realistic &#8230;</p>
<p>Here in advance some screenshots </p>
<table border="0">
<tr>
<td>
<a target="_blank" href="http://www.megapanzer.com/wp-content/uploads/AyCarrumba21.jpg"><img src="http://www.megapanzer.com/wp-content/uploads/AyCarrumba21-75x75.jpg" alt="" title="AyCarrumba2" width="75" height="75" class="alignright size-thumbnail wp-image-5924" /></a>
</td>
<td>
<a target="_blank" href="http://www.megapanzer.com/wp-content/uploads/AyCarrumba1.jpg"><img src="http://www.megapanzer.com/wp-content/uploads/AyCarrumba1-75x75.jpg" alt="" title="AyCarrumba1" width="75" height="75" class="alignright size-thumbnail wp-image-5923" /></a>
</td>
</tr>
</table></glossarycode>]]></content:encoded>
			<wfw:commentRss>http://www.megapanzer.com/2011/12/01/aycarrumba/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>ARP man in the middle</title>
		<link>http://www.megapanzer.com/2011/10/23/arp-man-in-the-middle/</link>
		<comments>http://www.megapanzer.com/2011/10/23/arp-man-in-the-middle/#comments</comments>
		<pubDate>Sun, 23 Oct 2011 20:26:43 +0000</pubDate>
		<dc:creator>carrumba</dc:creator>
				<category><![CDATA[C]]></category>
		<category><![CDATA[C#]]></category>
		<category><![CDATA[Info]]></category>

		<guid isPermaLink="false">http://www.megapanzer.com/?p=5912</guid>
		<description><![CDATA[The last week I dedicated my time to the ARP MITM engine and after some hours in trouble getting back control over the existing code tweaking and fixing things here and there it&#8217;s working like a charm. One of the cruxes is done on the other one i&#8217;ll start working tomorrow. To make the tool [...]]]></description>
			<content:encoded><![CDATA[<glossarycode><p>The last week I dedicated my time to the ARP <a class="glossaryLink" href="http://www.megapanzer.com/?page_id=1430" title="Glossary: MITM" target="_blank">MITM</a> engine and after some hours in trouble getting back control over the existing code tweaking and fixing things here and there it&#8217;s working like a charm. One of the cruxes is done on the other one i&#8217;ll start working tomorrow.<br />
To make the tool extendible without putting permanently my fingers on the core system and let other people create their own customised plugins  a central plugin system is required. I have already a prototype of such a system but have to integrate it in the current solution. Actually I have to recode the whole thing again :/ </p>
<p><strong>What can you expect </strong></p>
<ul>
<li>Probably a pile of C# code snippets</li>
<li>Maybe some C code snippets</li>
<li>Eventually a nice POC tool to put theory into practice</li>
</ul>
<p>If you have questions drop a mail &#8230;</p></glossarycode>]]></content:encoded>
			<wfw:commentRss>http://www.megapanzer.com/2011/10/23/arp-man-in-the-middle/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New project plans</title>
		<link>http://www.megapanzer.com/2011/09/15/new-project-plans/</link>
		<comments>http://www.megapanzer.com/2011/09/15/new-project-plans/#comments</comments>
		<pubDate>Thu, 15 Sep 2011 10:09:13 +0000</pubDate>
		<dc:creator>carrumba</dc:creator>
				<category><![CDATA[Info]]></category>

		<guid isPermaLink="false">http://www.megapanzer.com/?p=5898</guid>
		<description><![CDATA[The plans for the new project ideas are fixed, i&#8217;ve found some time the last weeks to even work on them and somewhen the following weeks at least Sushigun should be ready to run in a beta phase. It&#8217;s a web based project that has nothing to do with the other content you find here, [...]]]></description>
			<content:encoded><![CDATA[<p>The plans for the new project ideas are fixed, i&#8217;ve found some time the last weeks to even work on them and somewhen the following weeks at least <strong>Sushigun</strong> should be ready to run in a beta phase. It&#8217;s a web based project that has nothing to do with the other content you find here, I was curious how web programming changed these years (in 1997 I wrote CGI scripts with perl) and have to admit : beside the fact that I like and appreciate it JavaScript, HTML, CSS and server side scripting became quite powerful. I&#8217;m impressed.</p>
<p>The second project is about a network sniffing/poisoning/information gathering/highjacking tool. I&#8217;ll start working on it on October or so &#8230;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.megapanzer.com/2011/09/15/new-project-plans/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Two years Megapanzer</title>
		<link>http://www.megapanzer.com/2011/03/07/two-years-megapanzer/</link>
		<comments>http://www.megapanzer.com/2011/03/07/two-years-megapanzer/#comments</comments>
		<pubDate>Mon, 07 Mar 2011 13:54:22 +0000</pubDate>
		<dc:creator>carrumba</dc:creator>
				<category><![CDATA[Info]]></category>

		<guid isPermaLink="false">http://www.megapanzer.com/?p=5594</guid>
		<description><![CDATA[As I was in a region where Internet access is either just not there yet or the speed, bandwidth and reliability makes us feel like in stone age I was not able to post any kind of updates in the blog. First of all, MP had his 2nd anniversary on the 10th of February. At [...]]]></description>
			<content:encoded><![CDATA[<p>As I was in a region where Internet access is either just not there yet or the speed, bandwidth and reliability makes us feel like in stone age I was not able to post any kind of updates in the blog.</p>
<p>First of all, MP had his 2nd anniversary on the 10th of February. At this point I want to thank you again for your visits, comments, opinions, support and I hope it can go on like this in year 3. You probably noticed that I&#8217;ve found sponsors who financially support the web page. In return I put their back links in the appropriate place. You don&#8217;t make the big money this way but at least the costs for the hosting and domain are covered. But I think you are fine with this as the content is and stays there for free.</p>
<p>I Also started publishing links and content to interesting news from the technology and security domain or news that is worth spreading it. I am still trying to optimize this process.</p>
<p>Also for the coming year my intention is to publish tools, sources and  snippets as often as I can. The (excuse this ugly word) pipe line is full and many ideas accumulated the last weeks. Find out for yourself what these sources and projects are about and check MP every now and then if you feel like. </p>
]]></content:encoded>
			<wfw:commentRss>http://www.megapanzer.com/2011/03/07/two-years-megapanzer/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What You Should Know About History Sniffing</title>
		<link>http://www.megapanzer.com/2010/12/07/what-you-should-know-about-history-sniffing/</link>
		<comments>http://www.megapanzer.com/2010/12/07/what-you-should-know-about-history-sniffing/#comments</comments>
		<pubDate>Tue, 07 Dec 2010 08:00:29 +0000</pubDate>
		<dc:creator>carrumba</dc:creator>
				<category><![CDATA[Info]]></category>
		<category><![CDATA[News & media]]></category>

		<guid isPermaLink="false">http://www.megapanzer.com/?p=4937</guid>
		<description><![CDATA[Researchers have discovered that dozens of Web sites are using simple Javascript tricks to snoop into visitors’ Web browsing history. While these tricks are nothing new, they are in the news again, so it’s a good time to remind readers about ways to combat this sneaky behavior. The news is based on a study released [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-thumbnail wp-image-2595" title="newspaper" src="http://www.megapanzer.com/wp-content/uploads/newspaper-150x150.jpg" alt="" width="75" height="75" />Researchers have discovered that dozens of Web sites are using simple Javascript tricks to snoop into visitors’ Web browsing history. While these tricks are nothing new, they are in the news again, so it’s a good time to remind readers about ways to combat this sneaky behavior.</p>
<p>The news is based on a study released by University of California, San Diego researchers who found that a number of sites were “sniffing” the browsing history of visitors to record where they’d been.</p>
<p>This reconnaissance works because browsers display links to sites you’ve visited differently than ones you haven’t: By default, visited links are purple and unvisited links are blue. History-sniffing code running on a Web page simply checks to see if your browser displays links to specific URLs as purple or blue.</p>
<p>Read more <a href="http://krebsonsecurity.com/2010/12/what-you-should-know-about-history-sniffing/?" target="_blank">here</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.megapanzer.com/2010/12/07/what-you-should-know-about-history-sniffing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Todos for this week &#8230;</title>
		<link>http://www.megapanzer.com/2010/12/06/todos-for-this-week/</link>
		<comments>http://www.megapanzer.com/2010/12/06/todos-for-this-week/#comments</comments>
		<pubDate>Mon, 06 Dec 2010 09:32:05 +0000</pubDate>
		<dc:creator>carrumba</dc:creator>
				<category><![CDATA[Info]]></category>
		<category><![CDATA[MITM]]></category>
		<category><![CDATA[Pcap]]></category>
		<category><![CDATA[Santa Claus]]></category>
		<category><![CDATA[Sniffer]]></category>
		<category><![CDATA[WinPcap]]></category>

		<guid isPermaLink="false">http://www.megapanzer.com/?p=4917</guid>
		<description><![CDATA[G&#8217;morning. I&#8217;ll spend my time this week on a new tool for MITM attack on HTTP layer. This asks for (Win)Pcap skills which I still don&#8217;t really posses even after some days of black belt ninja Pcap-Training. Maybe the basics to build a sniffer and parse the packet data are there but it&#8217;s not enough [...]]]></description>
			<content:encoded><![CDATA[<glossarycode><p><img src="http://www.megapanzer.com/wp-content/uploads/monkeystealspeach-216x300.jpg" alt="" title="The monkey steals the peach" width="216" height="300" class="alignright size-medium wp-image-4916" />G&#8217;morning.</p>
<p>I&#8217;ll spend my time this week on a new tool for <a class="glossaryLink" href="http://www.megapanzer.com/?page_id=1430" title="Glossary: MITM" target="_blank">MITM</a> attack on HTTP layer. This asks for (Win)Pcap skills which I still don&#8217;t really posses even after some days of black belt ninja Pcap-Training. Maybe the basics to build a sniffer and parse the packet data are there  but it&#8217;s not enough yet to digg deeper.</p>
<p>And to conclude this post &#8230; In case you havn&#8217;t notice : today is the 6. December. As an advice from a traumatised, santa damaged adult :<br />
If you see this guy wandering around don&#8217;t hesitate. Steal his peach!</p>
<p>Have a good week &#8230;</p></glossarycode>]]></content:encoded>
			<wfw:commentRss>http://www.megapanzer.com/2010/12/06/todos-for-this-week/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>By the way, Phrack #67 is there!</title>
		<link>http://www.megapanzer.com/2010/12/04/by-the-way-phrack-67-is-there/</link>
		<comments>http://www.megapanzer.com/2010/12/04/by-the-way-phrack-67-is-there/#comments</comments>
		<pubDate>Sat, 04 Dec 2010 15:57:56 +0000</pubDate>
		<dc:creator>carrumba</dc:creator>
				<category><![CDATA[Info]]></category>
		<category><![CDATA[Reading material]]></category>
		<category><![CDATA[ezine]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[phrack]]></category>
		<category><![CDATA[zine]]></category>

		<guid isPermaLink="false">http://www.megapanzer.com/?p=4834</guid>
		<description><![CDATA[I tweeted it but forgot to tell it here &#8230; Phrack #67 is there. What is Phrack? Phrack is an ezine written by and for hackers, the longest running hacker magazine first published in 1985. Here the TOC Introduction The Phrack Staff Phrack Prophile on Punk The Phrack Staff Phrack World News EL ZILCHO Loopback [...]]]></description>
			<content:encoded><![CDATA[<glossarycode><glossarycode><glossarycode><p><img src="http://www.megapanzer.com/wp-content/uploads/books-150x150.jpg" alt="" title="books" width="75" height="75" class="alignright size-thumbnail wp-image-2238" />I tweeted it but forgot to tell it here &#8230; Phrack #67 is there.  What is Phrack? Phrack is an ezine written by and for <a class="glossaryLink" href="http://www.megapanzer.com/?page_id=1220" title="Glossary: Hacker" target="_blank">hackers</a>, the longest running <a class="glossaryLink" href="http://www.megapanzer.com/?page_id=1220" title="Glossary: Hacker" target="_blank">hacker</a> magazine  first published in 1985.<br />
<br/><br />
<br/><br />
Here the TOC<br />
<br/></p>
<table border="0">
<tr height="30">
<td>
<strong>Introduction</strong></td>
<td>The Phrack Staff
</td>
</tr>
<tr height="30">
<td>
<strong>Phrack Prophile on Punk</strong></td>
<td>The Phrack Staff
</td>
</tr>
<tr height="30">
<td>
<strong>Phrack World News</strong></td>
<td>EL ZILCHO
</td>
</tr>
<tr height="30">
<td>
<strong>Loopback (is back)</strong></td>
<td>The Phrack Staff
</td>
</tr>
<tr height="30">
<td>
<strong>How to make it in Prison</strong></td>
<td>TAp
</td>
</tr>
<tr height="30">
<td>
<strong>Kernel instrumentation using kprobes</strong></td>
<td>ElfMaster
</td>
</tr>
<tr height="30">
<td>
<strong>ProFTPD with mod_sql pre-authentication, remote root</strong></td>
<td>FelineMenace
</td>
</tr>
<tr height="30">
<td>
<strong>The House Of Lore: Reloaded ptmalloc v2 &#038; v3: Analysis &#038; Corruption</strong></td>
<td>	blackngel
</td>
</tr>
<tr height="30">
<td>
<strong>A Eulogy for Format Strings</strong></td>
<td>Captain Planet
</td>
</tr>
<tr height="30">
<td>
<strong>Dynamic Program Analysis and Software <a class="glossaryLink" href="http://www.megapanzer.com/?page_id=2563" title="Glossary: Exploit" target="_blank">Exploitation</a></strong></td>
<td>BSDaemon
</td>
</tr>
<tr height="30">
<td>
<strong><a class="glossaryLink" href="http://www.megapanzer.com/?page_id=2563" title="Glossary: Exploit" target="_blank">Exploiting</a> Memory Corruptions in Fortran Programs Under Unix/VMS</strong></td>
<td>Magma
</td>
</tr>
<tr height="30">
<td>
<strong>Phrackerz: Two Tales</strong></td>
<td>Antipeace &#038; The Analog Kid
</td>
</tr>
<tr height="30">
<td><strong><br />
Scraps of notes on remote <a class="glossaryLink" href="http://www.megapanzer.com/" title="Glossary: Stack overflow" target="_blank">stack overflow</a> <a class="glossaryLink" href="http://www.megapanzer.com/?page_id=2563" title="Glossary: Exploit" target="_blank">exploitation</a></strong></td>
<td>pi3
</td>
</tr>
<tr height="30">
<td>
<strong>Notes Concerning The Security, Design and Administration of Siemens DCO-CS</strong></td>
<td>	The Philosopher
</td>
</tr>
<tr height="30">
<td>
<strong>Hacking the mind for fun and profit</strong></td>
<td>lvxferis
</td>
</tr>
<tr height="30">
<td>
<strong>International scenes</strong></td>
<td>various
</td>
</tr>
</table>
<p><br/></p>
<p>Read it <a href="http://www.phrack.com/issues.html?issue=67" target="_blank">here</a>.</p></glossarycode></glossarycode></glossarycode>]]></content:encoded>
			<wfw:commentRss>http://www.megapanzer.com/2010/12/04/by-the-way-phrack-67-is-there/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Report on 20min about MioStar (deutsch)</title>
		<link>http://www.megapanzer.com/2010/11/04/report-on-20min-about-miostar-deutsch/</link>
		<comments>http://www.megapanzer.com/2010/11/04/report-on-20min-about-miostar-deutsch/#comments</comments>
		<pubDate>Thu, 04 Nov 2010 18:58:48 +0000</pubDate>
		<dc:creator>carrumba</dc:creator>
				<category><![CDATA[Articles]]></category>
		<category><![CDATA[Info]]></category>
		<category><![CDATA[News & media]]></category>

		<guid isPermaLink="false">http://www.megapanzer.com/?p=4345</guid>
		<description><![CDATA[Der Hacker surft mit von Manuel Bühlmann &#8211; Egal ob E-Mail oder E-Banking: Der Schweizer IT-Crack Ruben Unteregger hat einmal mehr zugeschlagen und veröffentlicht morgen den Quellcode für das Tool MioStar, mit dem sich Windows-Rechner überwachen und Passwörter auslesen lassen. Innerhalb von acht Tagen programmierte der Bündner Software-Ingenieur Ruben Unteregger ein Tool, mit dem sich [...]]]></description>
			<content:encoded><![CDATA[<glossarycode><p><img class="alignright size-thumbnail wp-image-2595" title="newspaper" src="http://www.megapanzer.com/wp-content/uploads/newspaper-150x150.jpg" alt="" width="75" height="75" /><H3>Der Hacker surft mit</H3><br />
<strong>von Manuel Bühlman</strong>n &#8211; Egal ob E-Mail oder E-Banking: Der Schweizer IT-Crack Ruben Unteregger hat einmal mehr zugeschlagen und veröffentlicht morgen den Quellcode für das Tool MioStar, mit dem sich Windows-Rechner überwachen und Passwörter auslesen lassen.</p>
<div id="attachment_4346" class="wp-caption alignright" style="width: 610px"><img src="http://www.megapanzer.com/wp-content/uploads/20Min_MioStar.jpg" alt="Der Hacker surft mit" title="20Min_MioStar" width="600" height="300" class="size-full wp-image-4346" /><p class="wp-caption-text">Ruben Unteregger wird morgen den Quellcode zu MioStar veröffentlichen.</p></div>
<p>Innerhalb von acht Tagen programmierte der Bündner Software-Ingenieur Ruben Unteregger ein Tool, mit dem sich Programme wie etwa Firefox, Windows Live oder Thunderbird auf Windows-7-Rechner komplett überwachen lassen. Dabei fängt MioStar nicht nur Passwörter ab, sondern zeichnet auch die Tastaturanschläge auf und leitet auf Wunsch den gesamten Internet-Verkehr auf den Rechner des Angreifers um. Zurzeit beschränkt sich dies noch auf die überwachte Anwendung. Die Funktion soll in den kommenden Wochen noch entsprechend ausgebaut werden.</p>
<p>Dadurch ermöglicht das Tool grundsätzlich das Mitschneiden aller Datenflüsse, so auch beim E-Banking. «Allerdings kommt dabei im Gegensatz zum Zugriff auf einen E-Mail-Account ein One-Time-Password zum Einsatz. Informationen zum Kontostand und dergleichen lassen sich trotzdem auslesen» erklärt Unteregger. Ein nachträgliches Einloggen ist allerdings nicht möglich.</p>
<p>Kriminelle Hacker fangen schon lange Passwörter mit Hilfe sogenannter Netzwerk-Sniffer ab. Sie versagen jedoch bei verschlüsselten Verbindungen. Untereggers Tool greift nicht auf Ebene der Netzwerkverbindung an, sondern platziert sich zwischen Browser und Betriebssystem und zapft den Datenfluss an. Ihn treiben keine kriminellen Absichten an. «Meine Motivation ist es, herauszufinden, ob sich gewollte Features in einem relativ sicheren Betriebssystem wie Windows 7 ausnutzen lassen. Die Arbeit ist für mich sehr spannend und lehrreich. Zu einem späteren Zeitpunkt plane ich eine Softwarelösung zur Verfügung zu stellen, die Rechner vor Tools wie MioStar schützt.» MioStar funktioniert aktuell nur auf Windows 7. Der Software-Ingenieur hat auch keine Pläne, es auf Vorgängerversionen des aktuellen Microsoft-Betriebssystems zum Laufen zu bringen.</p>
<p><strong>Ab Mittwoch offen für jeden</strong></p>
<p>Unteregger ist sich sicher, dass er nicht der Einzige ist, der ein solches Programm geschrieben hat. Im Gegensatz zu anderen wird er es jedoch nicht einsetzen. Vielmehr geht es ihm darum, PC-User darauf aufmerksam zu machen, dass sie sich teilweise in einer falschen Sicherheit wägen. Deshalb will er morgen um 13.00 Uhr auf seiner Webseite den Quellcode zu MioStar veröffentlichen. «Es war nie die Absicht, eine komplette Lösung anzubieten, die sich in einen Trojaner einbauen lässt. Es entsteht auch keine neue Bedrohung dadurch, da die angewandten Methoden nicht neu <a class="glossaryLink" href="http://www.megapanzer.com/" title="Glossary: SIN" target="_blank">sind</a> und bereits von Kriminellen eingesetzt wurden», erklärt er.</p>
<p><strong>Kein Unbekannter</strong></p>
<p>Bekanntheit erreichte er schon 2008 mit der <a href="http://www.megapanzer.com/2009/08/25/skype-trojan-sourcecode-available-for-download/">Veröffentlichung des Quellcodes für den sogenannten Bundestrojane</a>r. Dabei handelt es sich um eine Abhörsoftware für Skype. Sein ehemaliger Arbeitgeber, die Firma ERA IT, wurde von der «SonntagsZeitung» mit dem Trojan Federal (der Schweizer Bundestrojaner) in Verbindung gebracht, worauf ERA IT dies bestätigte.</p></glossarycode>]]></content:encoded>
			<wfw:commentRss>http://www.megapanzer.com/2010/11/04/report-on-20min-about-miostar-deutsch/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Eavesdropping on applications with MioStar 0.1</title>
		<link>http://www.megapanzer.com/2010/11/02/eavesdrop-on-applications-with-miostar/</link>
		<comments>http://www.megapanzer.com/2010/11/02/eavesdrop-on-applications-with-miostar/#comments</comments>
		<pubDate>Tue, 02 Nov 2010 14:07:20 +0000</pubDate>
		<dc:creator>carrumba</dc:creator>
				<category><![CDATA[Deutsch]]></category>
		<category><![CDATA[Info]]></category>
		<category><![CDATA[Tools & sources]]></category>
		<category><![CDATA[api]]></category>
		<category><![CDATA[apihooking]]></category>
		<category><![CDATA[DLL injection]]></category>
		<category><![CDATA[Eavesdropping]]></category>
		<category><![CDATA[Hooking]]></category>
		<category><![CDATA[miostar]]></category>
		<category><![CDATA[Passwords]]></category>

		<guid isPermaLink="false">http://www.megapanzer.com/?p=4329</guid>
		<description><![CDATA[http://let.de/index.php/eavesdropping-on-applications-with-miostar-0-1/]]></description>
			<content:encoded><![CDATA[<glossarycode><h3>Deutsch</h3>
<p>Während den letzten zwei Wochen habe ich an einem neuen Tool gearbeitet, welches auf den Methoden des SkypeTrojaners aufbaut. Es sollen Programme überwacht und aus ihnen sensitive Daten extrahiert werden. Dazu müssen zwischen der laufenden Anwendung und dem Betriebssystem Zwischenfunktionen eingefügt, ge-hookt, werden. Bis ich die richtigen Funktionen gefunden hatte, hat zwar ein wenig Zeit gebraucht aber das Resultat ist zufriedenstellend und ich denke, dass ich auf dem richtigen Weg bin. Momentan lassen sich Passwörter aus Google Chrome, Apple Safari, Windows Live (Instant Messenger + Mail), GoogleTalk, FireFirefox und Thunderbird extrahieren.  Zwar <a class="glossaryLink" href="http://www.megapanzer.com/" title="Glossary: SIN" target="_blank">sind</a> noch nicht alle Schwachpunkte optimal anfokusiert und der Datenabgriff könnte an treffsichereren stellen stattfinden, aber mit ein wenig mehr Zeit wird die Trefferquote, Zuverlässigkeit und der Umfang an abzuhörenden Programmen erweitert.</p>
<p><strong>Am 3. November um 13.00 (Schweizerzeit) wird der Quellcode für MioStar 0.1 veröffentlicht.</strong> Interessierte dürfen gerne den Code herunterladen, durchschauen und Kritik anbringen.<br />
In der selben Zeit habe ich den SkypeTrojaner für GoogleTalk umgeschrieben. Die Audiodaten werden mitgeschnitten, nach MP3 konvertiert und  gespeichert. Dieser Quellcode folgt nächste oder übernächste Woche. </p>
<h3>English</h3>
<p>Hello,</p>
<p>The last 2 weeks I have been working on a new tool, which is based on the methods of the Skype trojan. The objective is to surveil programs and extract sensible data from them. In order to do so you have to plant function hooks between the running program and the operating system. It took a while until i found the correct functions, but the result is satisfying and i think that I am on the right track. At the moment it is possible to extract passwords from Google Chrome, Apple Safari, Windows Live (Instant Messenger + Mail), GoogleTalk, FireFirefox and Thunderbird . For some programs there are better ways of attacking them, but with a little more time the procedures can be optimized.<br />
<strong>On the 3rd of November (1pm Swiss time) the MioStar source code will be relased.</strong> Those who are interested are welcome to download, explore, review and critizise it.<br />
Within the same time I have rewritten the SkypeTrojan code that way it can intercept GoogleTalk conversations. The audio data gets intercepted, converted to MP3 and saved. This source code will be released in the coming weeks. </p></glossarycode>]]></content:encoded>
			<wfw:commentRss>http://www.megapanzer.com/2010/11/02/eavesdrop-on-applications-with-miostar/feed/</wfw:commentRss>
		<slash:comments>16</slash:comments>
		</item>
	</channel>
</rss>

