<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>iThreats</title>
	<atom:link href="http://ithreats.net/feed/" rel="self" type="application/rss+xml" />
	<link>http://ithreats.net</link>
	<description>What Do You Think Is The Biggest Threat To Mac Users&#039; Security?</description>
	<lastBuildDate>Thu, 12 Jan 2012 00:09:22 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='ithreats.net' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://0.gravatar.com/blavatar/6cfb95912e01ba3e5913979a06571621?s=96&#038;d=http%3A%2F%2Fs2.wp.com%2Fi%2Fbuttonw-com.png</url>
		<title>iThreats</title>
		<link>http://ithreats.net</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://ithreats.net/osd.xml" title="iThreats" />
	<atom:link rel='hub' href='http://ithreats.net/?pushpress=hub'/>
		<item>
		<title>Virus Bulletin 2011</title>
		<link>http://ithreats.net/2011/10/06/virus-bulletin-2011/</link>
		<comments>http://ithreats.net/2011/10/06/virus-bulletin-2011/#comments</comments>
		<pubDate>Thu, 06 Oct 2011 03:12:48 +0000</pubDate>
		<dc:creator>Methusela Cebrian Ferrer</dc:creator>
				<category><![CDATA[Daily Thoughts]]></category>
		<category><![CDATA[Cyberattack]]></category>
		<category><![CDATA[mac threats]]></category>
		<category><![CDATA[Remembering Steve Jobs]]></category>
		<category><![CDATA[Virus Bulletin 2011]]></category>

		<guid isPermaLink="false">http://ithreats.net/?p=1306</guid>
		<description><![CDATA[It&#8217;s 5:15 AM here in Barcelona and second day of the conference. For the past three years, I&#8217;ve been given an opportunity to present and discuss topic relating to malware or threats in Macs. And at the same time, attending VB conference allows you to meet, learn and discuss with fellow researcher sharing the same [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ithreats.net&amp;blog=3681895&amp;post=1306&amp;subd=ithreats&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>It&#8217;s 5:15 AM here in Barcelona and second day of the conference. For the past three years, I&#8217;ve been given an opportunity to present and discuss topic relating to malware or threats in Macs. And at the same time, attending VB conference allows you to meet, learn and discuss with fellow researcher sharing the same interest.</p>
<p>I have 30min. (11:20 &#8211; 11:50 am) this morning to discuss an interesting topic about <a href="http://www.virusbtn.com/conference/vb2011/abstracts/Ferrer.xml">Cyber attacks: how are Mac OS X and iOS users playing the role?</a> The presentation is divided into two subtopics; I&#8217;ll first discuss Apple security defences and the financially motivated threats, then a topic that is complex because it&#8217;s beyond malware. However, in this forum, I&#8217;d like to draw attention and bring awareness of this subject.</p>
<p>Cyberattack is a form of threat motivated by ideals and belief, often responding to social and economic issues where people voluntarily participates and takes action as a response to an open call. Devices, system and application act as a tool and weapon &#8211; which aids in accomplishing a task or mission. Contrary to most people believe that threats are platform specific, and targets the biggest market share, this notion is not true. Attacks and threats today targets user&#8217;s data, the information space and user&#8217;s identity, and this occurs regardless of the platform.</p>
<p>On a sad note, I would like extend my deepest condolences and sympathy to a man of great spirit and high vision; his death is a great loss and his absence will surely be felt.</p>
<p style="text-align:center;"><a href="http://ithreats.files.wordpress.com/2011/10/steve-jobs.png"><img class="aligncenter size-large wp-image-1307" title="Steve jobs" src="http://ithreats.files.wordpress.com/2011/10/steve-jobs.png?w=717&#038;h=475" alt="" width="717" height="475" /></a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ithreats.wordpress.com/1306/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ithreats.wordpress.com/1306/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ithreats.wordpress.com/1306/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ithreats.wordpress.com/1306/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/ithreats.wordpress.com/1306/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/ithreats.wordpress.com/1306/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/ithreats.wordpress.com/1306/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/ithreats.wordpress.com/1306/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ithreats.wordpress.com/1306/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ithreats.wordpress.com/1306/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ithreats.wordpress.com/1306/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ithreats.wordpress.com/1306/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ithreats.wordpress.com/1306/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ithreats.wordpress.com/1306/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ithreats.net&amp;blog=3681895&amp;post=1306&amp;subd=ithreats&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://ithreats.net/2011/10/06/virus-bulletin-2011/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/4d7b7d253fb250ab3887bbcbccd15411?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">meths</media:title>
		</media:content>

		<media:content url="http://ithreats.files.wordpress.com/2011/10/steve-jobs.png?w=1024" medium="image">
			<media:title type="html">Steve jobs</media:title>
		</media:content>
	</item>
		<item>
		<title>&#8216;Olyx&#8217; connection to Fake Apple Stores?</title>
		<link>http://ithreats.net/2011/07/28/olyx-connection-to-fake-apple-stores/</link>
		<comments>http://ithreats.net/2011/07/28/olyx-connection-to-fake-apple-stores/#comments</comments>
		<pubDate>Thu, 28 Jul 2011 13:48:11 +0000</pubDate>
		<dc:creator>Methusela Cebrian Ferrer</dc:creator>
				<category><![CDATA[Daily Thoughts]]></category>
		<category><![CDATA[OS X]]></category>
		<category><![CDATA[5 Fake Apple Stores]]></category>
		<category><![CDATA[Backdoor Olyx]]></category>
		<category><![CDATA[Kunming]]></category>
		<category><![CDATA[Kunming Wuhua District YanXing Technology Sales Department]]></category>
		<category><![CDATA[Olyx]]></category>
		<category><![CDATA[Wolyx]]></category>
		<category><![CDATA[Yunnan]]></category>

		<guid isPermaLink="false">http://ithreats.net/?p=1297</guid>
		<description><![CDATA[An interesting observation from a colleague, check out the digital certificate information of &#8216;Wolyx&#8217; the Windows backdoor packaged with &#8216;Olyx&#8217;  below: Issued By:      WoSign Code Signing Authority Issued To:      CN, Yunnan, Kunming, Kunming Wuhua District YanXing Technology Sales Department, WoSign Class 3 Code Signing, Kunming Wuhua District YanXing Technology Sales Department Effective On:   11/03/2009 00:00  [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ithreats.net&amp;blog=3681895&amp;post=1297&amp;subd=ithreats&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>An interesting observation from a colleague, check out the digital certificate information of &#8216;Wolyx&#8217; the Windows backdoor packaged with &#8216;Olyx&#8217;  below:</p>
<p><em>Issued By:      WoSign Code Signing Authority<br />
</em><em>Issued To:      <strong>CN, Yunnan, Kunming</strong>, Kunming Wuhua District YanXing Technology Sales Department, WoSign Class 3 Code Signing, Kunming Wuhua District YanXing Technology Sales Department<br />
<span class="Apple-style-span" style="font-style:normal;"><em>Effective On:   11/03/2009 00:00 </em></span><br />
</em><em>Expired On:     11/02/2012 23:59</em></p>
<p>The place where the revoked digital certificate was issued to was <strong>Kunming, Yunnan China</strong>.</p>
<p>In the news, you&#8217;ll notice that this is the same city of the <strong>fake Apple stores.  </strong></p>
<h1>China officials find 5 fake Apple stores in 1 city</h1>
<blockquote><p>BEIJING</p>
<p>A Chinese city government website says local trade officials have found five fake Apple stores in a southwestern city.</p>
<p>The <strong>Kunming</strong> government website says authorities in the city in <strong>Yunnan province</strong> took action against two of the stores, which were found to be operating without a business license.</p>
<p>[Read <a href="http://www.businessweek.com/ap/financialnews/D9OME9280.htm">http://www.businessweek.com/ap/financialnews/D9OME9280.htm</a>]</p></blockquote>
<h2>Officials close 2 of 5 fake Apple stores</h2>
<blockquote>
<div>
<div><em><strong>KUNMING</strong> &#8211; Officials looking into the illegal sale of Apple gadgets say they are waiting for the electronics company to respond before they decide whether to close three more possibly unlicensed stores. [Read <a href="http://www.chinadaily.com.cn/usa/us/2011-07/26/content_12980613.htm">http://www.chinadaily.com.cn/usa/us/2011-07/26/content_12980613.htm</a>]</em></div>
</div>
</blockquote>
<div>Coincidence?</div>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ithreats.wordpress.com/1297/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ithreats.wordpress.com/1297/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ithreats.wordpress.com/1297/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ithreats.wordpress.com/1297/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/ithreats.wordpress.com/1297/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/ithreats.wordpress.com/1297/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/ithreats.wordpress.com/1297/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/ithreats.wordpress.com/1297/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ithreats.wordpress.com/1297/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ithreats.wordpress.com/1297/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ithreats.wordpress.com/1297/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ithreats.wordpress.com/1297/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ithreats.wordpress.com/1297/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ithreats.wordpress.com/1297/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ithreats.net&amp;blog=3681895&amp;post=1297&amp;subd=ithreats&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://ithreats.net/2011/07/28/olyx-connection-to-fake-apple-stores/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/4d7b7d253fb250ab3887bbcbccd15411?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">meths</media:title>
		</media:content>
	</item>
		<item>
		<title>Backdoor &#8216;Olyx&#8217;</title>
		<link>http://ithreats.net/2011/07/26/backdoor-olyx/</link>
		<comments>http://ithreats.net/2011/07/26/backdoor-olyx/#comments</comments>
		<pubDate>Tue, 26 Jul 2011 16:24:11 +0000</pubDate>
		<dc:creator>Methusela Cebrian Ferrer</dc:creator>
				<category><![CDATA[Daily Thoughts]]></category>
		<category><![CDATA[Emerging Threats]]></category>
		<category><![CDATA[Malwares]]></category>
		<category><![CDATA[OS X]]></category>
		<category><![CDATA[/Users/yxl/Documents/]]></category>
		<category><![CDATA[5 July 2009]]></category>
		<category><![CDATA[Mac OS X targeted attack]]></category>
		<category><![CDATA[targeting Uyghur supporters]]></category>
		<category><![CDATA[World Uyghur Congress]]></category>

		<guid isPermaLink="false">http://ithreats.net/?p=1276</guid>
		<description><![CDATA[In my last blog post, I&#8217;ve discussed the early features of RAT &#8216;Blackhole&#8217;. Although, it was then in its early stage, I find this type of offensive development interesting due to the fact that they emerge and distribute as a hacking tool, with functional backdoor client-server mechanism. Last month, we have spotted a new piece of [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ithreats.net&amp;blog=3681895&amp;post=1276&amp;subd=ithreats&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>In my last blog post, I&#8217;ve discussed the early features of RAT &#8216;Blackhole&#8217;. Although, it was then in its early stage, I find this type of offensive development interesting due to the fact that they emerge and distribute as a hacking tool, with functional backdoor client-server mechanism.</p>
<p>Last month, we have spotted a new piece of malware, a backdoor server called &#8216;Olyx&#8217;. The file is a Mach-O binary and the traces of the working directory suggest that the Mac user name is &#8216;yxl&#8217;. So, this is where the name &#8216;Olyx&#8217; came.</p>
<p>Backdoor &#8216;Olyx&#8217; was spotted in a package called &#8216;<em>P</em><em>ortalCurrent events-2009 July 5.rar</em>”, where the content suggest that it was extracted from Wikipedia community portal current events <a href="http://en.wikipedia.org/wiki/Portal:Current_events/2009_July_5">2009 July 5 page</a>.  If you will visit the Wikipedia current events <a href="http://en.wikipedia.org/wiki/Portal:Current_events/2009_July_5">2009 July 5 page</a>, and compare the screenshot below, you&#8217;ll find it very similar.</p>
<p><a href="http://ithreats.files.wordpress.com/2011/07/portalcurrent-events-2009-july-5.png"><img class="aligncenter size-full wp-image-1278" title="PortalCurrent events-2009 July 5" src="http://ithreats.files.wordpress.com/2011/07/portalcurrent-events-2009-july-5.png?w=600&#038;h=427" alt="" width="600" height="427" /></a></p>
<p>However, the extracted page includes a folder which contains photos of the 2011 June 15th protest in Athens, Greece and alongside the two malicious binary executable:</p>
<p><a href="http://ithreats.files.wordpress.com/2011/07/portalcurrent-events-2009-july-5-content.png"><img class="aligncenter size-full wp-image-1279" title="PortalCurrent events-2009 July 5 - content" src="http://ithreats.files.wordpress.com/2011/07/portalcurrent-events-2009-july-5-content.png?w=600&#038;h=304" alt="" width="600" height="304" /></a></p>
<p>There&#8217;s another folder called<em> &#8216;Photo-Current events 2009 July 5&#8242;</em>, which contains 21 (disturbing) photos.</p>
<p>Q: So, the question now is, what happened on &#8217;2009 July 5&#8242; ?</p>
<p>The World Uyghur Congress <a href="http://www.uyghurcongress.org/en/" target="_blank">website</a> describes it,</p>
<p><em>On 5 July 2009, Uyghurs in Urumqi, the capital of East Turkestan, staged a peaceful protest which was suppressed by Chinese security forces and subsequently led to ethnic unrest in the city that left hundreds of people dead.</em></p>
<p>Q: Ok, that was 2 years ago right?</p>
<p>Yes, and in a press released titled &#8220;<a href="http://www.uyghurcongress.org/en/?p=9024" target="_blank">Worldwide Uyghur Protests on Second Anniversary of 5 July 2009&#8243;</a> describes the present,</p>
<p><em>On July 5, 2011 and in the days surrounding July 5th, the WUC called the Uyghurs in exile and their supporters around the globe to stage demonstrations and other actions to commemorate the second anniversary of one of the saddest and most tragic days in the history of the Uyghur people and of East Turkestan and to ensure that the world does not forget about the devastating plight of the Uyghur people.</em></p>
<p>So, there’s a call for an organized demonstration to remind the whole world of the 2009 event, and in support for Uyghur’s human rights and freedom.</p>
<p>Q: What&#8217;s the protest? This Facebook invitation <a href="http://www.facebook.com/event.php?eid=140320079376958" target="_blank">page</a> explains,</p>
<p><em>Approaching the second anniversary of these events, and despite international calls, no independent investigation into the incident has been allowed by the Chinese authorities and the number of people killed, detained, imprisoned, executed and disappeared remains unclear.</em></p>
<p><a href="http://ithreats.files.wordpress.com/2011/07/facebook-page.png"><img class="aligncenter size-full wp-image-1280" title="Facebook Page" src="http://ithreats.files.wordpress.com/2011/07/facebook-page.png?w=600&#038;h=311" alt="" width="600" height="311" /></a></p>
<p>The activities surrounding this protest clearly took place in the cyberspace, resulting to attacks as described in press released titled  <em><a href="http://www.uyghurcongress.org/en/?p=8978" target="_blank">World Uyghur Congress (WUC) Victim of DDoS Cyber Attacks</a>,</em></p>
<p><em>Approaching the second anniversary of the 5 July 2009 events, the World Uyghur Congress (WUC) has again been the victim of cyber attacks.</em></p>
<p>So, how do you think Backdoor &#8216;Olyx&#8217; fits in this picture?</p>
<p>The discovery of this threat should remind Mac users to carefully consider security and the real-life consequences of getting pwned. Remember, this type of threats are on the mission, and this is not cybercriminal that monetize infection nor steals money.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ithreats.wordpress.com/1276/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ithreats.wordpress.com/1276/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ithreats.wordpress.com/1276/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ithreats.wordpress.com/1276/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/ithreats.wordpress.com/1276/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/ithreats.wordpress.com/1276/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/ithreats.wordpress.com/1276/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/ithreats.wordpress.com/1276/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ithreats.wordpress.com/1276/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ithreats.wordpress.com/1276/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ithreats.wordpress.com/1276/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ithreats.wordpress.com/1276/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ithreats.wordpress.com/1276/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ithreats.wordpress.com/1276/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ithreats.net&amp;blog=3681895&amp;post=1276&amp;subd=ithreats&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://ithreats.net/2011/07/26/backdoor-olyx/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/4d7b7d253fb250ab3887bbcbccd15411?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">meths</media:title>
		</media:content>

		<media:content url="http://ithreats.files.wordpress.com/2011/07/portalcurrent-events-2009-july-5.png" medium="image">
			<media:title type="html">PortalCurrent events-2009 July 5</media:title>
		</media:content>

		<media:content url="http://ithreats.files.wordpress.com/2011/07/portalcurrent-events-2009-july-5-content.png" medium="image">
			<media:title type="html">PortalCurrent events-2009 July 5 - content</media:title>
		</media:content>

		<media:content url="http://ithreats.files.wordpress.com/2011/07/facebook-page.png" medium="image">
			<media:title type="html">Facebook Page</media:title>
		</media:content>
	</item>
		<item>
		<title>RAT &#8216;BlackHole&#8217;</title>
		<link>http://ithreats.net/2011/02/25/rat-blackhole/</link>
		<comments>http://ithreats.net/2011/02/25/rat-blackhole/#comments</comments>
		<pubDate>Fri, 25 Feb 2011 15:43:54 +0000</pubDate>
		<dc:creator>Methusela Cebrian Ferrer</dc:creator>
				<category><![CDATA[Emerging Threats]]></category>
		<category><![CDATA[OS X]]></category>
		<category><![CDATA[Backdoor Mac OS X]]></category>
		<category><![CDATA[BlackHole Beta]]></category>
		<category><![CDATA[RAT Mac]]></category>

		<guid isPermaLink="false">http://ithreats.net/?p=1253</guid>
		<description><![CDATA[&#8216;BlackHole&#8217; is the latest remote administration tool (RAT) and is available both in Windows and Mac. Hacktool such RAT employs client-server program that communicates to its victim&#8217;s machine through its trojan server. The server application is installed on the victim while the client application is on the managing side. The version suggest that &#8216;BlackHole&#8217; is [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ithreats.net&amp;blog=3681895&amp;post=1253&amp;subd=ithreats&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>&#8216;BlackHole&#8217; is the latest remote administration tool (RAT) and is available both in Windows and Mac.</p>
<p>Hacktool such RAT employs client-server program that communicates to its victim&#8217;s machine through its trojan server. The server application is installed on the victim while the client application is on the managing side.</p>
<p><a href="http://ithreats.files.wordpress.com/2011/02/blackhole-client.png"><img class="aligncenter size-full wp-image-1254" title="BlackHole Client" src="http://ithreats.files.wordpress.com/2011/02/blackhole-client.png?w=600" alt=""   /></a>The version suggest that &#8216;BlackHole&#8217; is currently in its early stage. However, the author seems to start showcasing the following functionalities:</p>
<ul>
<li>Remote execution of shell commands.</li>
<li>Opens webpage using user&#8217;s default browser.</li>
<li>Sends a message which is displayed on the victims screen.</li>
<li>Creates a text file.</li>
<li>It is capable to perform shutdown, restart and sleep operation.</li>
<li>It is capable to request for admin privileges.</li>
</ul>
<p>Also, it is also capable to block users screen with this message: please refer this <a href="http://ithreats.files.wordpress.com/2011/02/screen-lock.png">image</a>.</p>
<p>Be wary of possible backdoor infection. Report suspicious application, especially if it is communicating to unknown or unfamiliar remote server.</p>
<p><em>Note: While checking the client-server capability, I just thought that it would be useful to capture a video for reference. (recommended screen 720pHD)</em></p>
<span style="text-align:center; display: block;"><a href="http://ithreats.net/2011/02/25/rat-blackhole/"><img src="http://img.youtube.com/vi/ge67SuW1GvU/2.jpg" alt="" /></a></span>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ithreats.wordpress.com/1253/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ithreats.wordpress.com/1253/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ithreats.wordpress.com/1253/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ithreats.wordpress.com/1253/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/ithreats.wordpress.com/1253/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/ithreats.wordpress.com/1253/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/ithreats.wordpress.com/1253/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/ithreats.wordpress.com/1253/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ithreats.wordpress.com/1253/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ithreats.wordpress.com/1253/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ithreats.wordpress.com/1253/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ithreats.wordpress.com/1253/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ithreats.wordpress.com/1253/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ithreats.wordpress.com/1253/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ithreats.net&amp;blog=3681895&amp;post=1253&amp;subd=ithreats&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://ithreats.net/2011/02/25/rat-blackhole/feed/</wfw:commentRss>
		<slash:comments>33</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/4d7b7d253fb250ab3887bbcbccd15411?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">meths</media:title>
		</media:content>

		<media:content url="http://ithreats.files.wordpress.com/2011/02/blackhole-client.png" medium="image">
			<media:title type="html">BlackHole Client</media:title>
		</media:content>
	</item>
		<item>
		<title>Socially Engineered Threats</title>
		<link>http://ithreats.net/2011/01/29/socially-engineered-threats/</link>
		<comments>http://ithreats.net/2011/01/29/socially-engineered-threats/#comments</comments>
		<pubDate>Sat, 29 Jan 2011 14:06:48 +0000</pubDate>
		<dc:creator>Methusela Cebrian Ferrer</dc:creator>
				<category><![CDATA[Daily Thoughts]]></category>
		<category><![CDATA[Facebook get a surprise now]]></category>
		<category><![CDATA[IM spam]]></category>
		<category><![CDATA[Koobface]]></category>
		<category><![CDATA[redirection attack]]></category>
		<category><![CDATA[Sasfis Oficla]]></category>
		<category><![CDATA[Slenfbot Rimecud]]></category>
		<category><![CDATA[social engineering]]></category>
		<category><![CDATA[Socially Engineered Threats]]></category>

		<guid isPermaLink="false">http://ithreats.net/?p=1243</guid>
		<description><![CDATA[Socially engineered threats has been very active and in-the-wild for the past 48hours. Following the Eurosoft, Canadian Pharmacy and Porn sites spams, the internet viral activity is also observed spreading in Facebook. The spammed URL redirects users to a Facebook looking website, where a malware is served. Although, Mac users are not directly targeted at [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ithreats.net&amp;blog=3681895&amp;post=1243&amp;subd=ithreats&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Socially engineered threats has been very active and in-the-wild for the past 48hours. Following the Eurosoft, Canadian Pharmacy and Porn sites spams, the internet viral activity is also observed spreading in Facebook.</p>
<p><a href="http://ithreats.files.wordpress.com/2011/01/facebook-spam-i-got-you-surprise.png"><img class="aligncenter size-full wp-image-1245" title="Facebook Spam 'I got you surprise'" src="http://ithreats.files.wordpress.com/2011/01/facebook-spam-i-got-you-surprise.png?w=600" alt=""   /></a></p>
<p>The spammed URL redirects users to a Facebook looking website, where a malware is served. Although, Mac users are not directly targeted at the moment, it is important to be cautious especially &#8216;Boonana&#8217; is known being spread via Facebook.</p>
<p><a href="http://ithreats.files.wordpress.com/2011/01/facebook-get-a-surprise-now.png"><img class="aligncenter size-full wp-image-1246" title="Facebook 'Get a surprise now'" src="http://ithreats.files.wordpress.com/2011/01/facebook-get-a-surprise-now.png?w=600&#038;h=397" alt="" width="600" height="397" /></a>As observed, the viral activity seems to trigger the following:</p>
<ul>
<li>Koobface known for spreading in <strong>social networks</strong> such as Facebook.</li>
<li>Sasfis/Oficla known as a spambot, spreading through <strong>email </strong></li>
<li>Slenfbot and/or Rimecud for spreading in <strong>instant messengers </strong></li>
</ul>
<p>Along these malware families are the notable active threats such as TDSS, Zeus, Spyeye and FakeAVs.</p>
<p>Stay safe!</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ithreats.wordpress.com/1243/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ithreats.wordpress.com/1243/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ithreats.wordpress.com/1243/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ithreats.wordpress.com/1243/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/ithreats.wordpress.com/1243/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/ithreats.wordpress.com/1243/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/ithreats.wordpress.com/1243/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/ithreats.wordpress.com/1243/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ithreats.wordpress.com/1243/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ithreats.wordpress.com/1243/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ithreats.wordpress.com/1243/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ithreats.wordpress.com/1243/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ithreats.wordpress.com/1243/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ithreats.wordpress.com/1243/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ithreats.net&amp;blog=3681895&amp;post=1243&amp;subd=ithreats&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://ithreats.net/2011/01/29/socially-engineered-threats/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/4d7b7d253fb250ab3887bbcbccd15411?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">meths</media:title>
		</media:content>

		<media:content url="http://ithreats.files.wordpress.com/2011/01/facebook-spam-i-got-you-surprise.png" medium="image">
			<media:title type="html">Facebook Spam &#039;I got you surprise&#039;</media:title>
		</media:content>

		<media:content url="http://ithreats.files.wordpress.com/2011/01/facebook-get-a-surprise-now.png" medium="image">
			<media:title type="html">Facebook &#039;Get a surprise now&#039;</media:title>
		</media:content>
	</item>
		<item>
		<title>EuroSoft 2011</title>
		<link>http://ithreats.net/2011/01/27/eurosoft-2011/</link>
		<comments>http://ithreats.net/2011/01/27/eurosoft-2011/#comments</comments>
		<pubDate>Thu, 27 Jan 2011 13:52:28 +0000</pubDate>
		<dc:creator>Methusela Cebrian Ferrer</dc:creator>
				<category><![CDATA[OS X]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Apple Mac application offers]]></category>
		<category><![CDATA[cheap Mac OS X]]></category>
		<category><![CDATA[EuroSoft 2011]]></category>
		<category><![CDATA[Mac OS utilities discount]]></category>
		<category><![CDATA[mac software deals]]></category>

		<guid isPermaLink="false">http://ithreats.net/?p=1233</guid>
		<description><![CDATA[The EuroSoft spamming is up and kicking through email and in any writable pages in the web. Around this time last year, I&#8217;ve spotted this activity through Skype but the difference this year is that the spam trend uses shortened URL. Safari recognises some of the website and displays warning message &#8220;Suspected phishing site&#8221;, however [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ithreats.net&amp;blog=3681895&amp;post=1233&amp;subd=ithreats&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://ithreats.files.wordpress.com/2011/01/eurosoft-spam.png"><img class="aligncenter size-full wp-image-1234" title="Eurosoft Spam" src="http://ithreats.files.wordpress.com/2011/01/eurosoft-spam.png?w=600" alt=""   /></a></p>
<p>The <a title="EuroSoft Description" href="http://spamtrackers.eu/wiki/index.php/EuroSoft" target="_blank">EuroSoft</a> spamming is up and kicking through email and in any writable pages in the web.</p>
<p>Around this time last year, I&#8217;ve spotted this <a title="best-mac-software" href="http://ithreats.net/2010/01/13/best-mac-software-com/" target="_blank">activity through Skype</a> but the difference this year is that the spam trend uses shortened URL. Safari recognises some of the website and displays warning message &#8220;Suspected phishing site&#8221;, however not everything just like this site &#8220;http://best-mac-software.com/&#8221;.</p>
<p>So be careful and pay attention, you&#8217;ll never know you are already dealing with a typosquatted and fraudulent websites.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ithreats.wordpress.com/1233/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ithreats.wordpress.com/1233/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ithreats.wordpress.com/1233/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ithreats.wordpress.com/1233/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/ithreats.wordpress.com/1233/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/ithreats.wordpress.com/1233/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/ithreats.wordpress.com/1233/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/ithreats.wordpress.com/1233/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ithreats.wordpress.com/1233/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ithreats.wordpress.com/1233/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ithreats.wordpress.com/1233/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ithreats.wordpress.com/1233/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ithreats.wordpress.com/1233/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ithreats.wordpress.com/1233/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ithreats.net&amp;blog=3681895&amp;post=1233&amp;subd=ithreats&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://ithreats.net/2011/01/27/eurosoft-2011/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/4d7b7d253fb250ab3887bbcbccd15411?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">meths</media:title>
		</media:content>

		<media:content url="http://ithreats.files.wordpress.com/2011/01/eurosoft-spam.png" medium="image">
			<media:title type="html">Eurosoft Spam</media:title>
		</media:content>
	</item>
		<item>
		<title>Annoying ads coming from an iPad/iPhone app</title>
		<link>http://ithreats.net/2011/01/25/annoying-ads-coming-from-an-ipadiphone-app/</link>
		<comments>http://ithreats.net/2011/01/25/annoying-ads-coming-from-an-ipadiphone-app/#comments</comments>
		<pubDate>Tue, 25 Jan 2011 13:53:02 +0000</pubDate>
		<dc:creator>Methusela Cebrian Ferrer</dc:creator>
				<category><![CDATA[iPhone]]></category>
		<category><![CDATA[OS X]]></category>
		<category><![CDATA[Tips]]></category>
		<category><![CDATA[alerts]]></category>
		<category><![CDATA[annoying Ads]]></category>
		<category><![CDATA[badges]]></category>
		<category><![CDATA[how to delete app in iPad and iPhone]]></category>
		<category><![CDATA[notification]]></category>
		<category><![CDATA[pop-up message iPad iPhone]]></category>

		<guid isPermaLink="false">http://ithreats.net/?p=1228</guid>
		<description><![CDATA[I&#8217;ve recently encountered lots of annoying Ads in my iPhone and iPad. My initial impression is what an &#8216;Ad serving app&#8217;!  But, this is the result when you allow or agree to receive push notifications as shown below. Here are some useful tips on how to deal with it. This instruction should stop the problem, [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ithreats.net&amp;blog=3681895&amp;post=1228&amp;subd=ithreats&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve recently encountered lots of annoying Ads in my iPhone and iPad. My initial impression is what an &#8216;Ad serving app&#8217;!  But, this is the result when you allow or agree to receive push notifications as shown below.</p>
<p><a href="http://ithreats.files.wordpress.com/2011/01/img_0010.png"><img class="aligncenter size-full wp-image-1229" title="IMG_0010" src="http://ithreats.files.wordpress.com/2011/01/img_0010.png?w=600" alt=""   /></a></p>
<p>Here are some useful tips on how to deal with it. This instruction should stop the problem, otherwise the app causing your trouble is absolutely suspicious and you should report it for investigation.</p>
<p>How do I stop annoying Ads coming from an iPad/iPhone app?</p>
<p>1) Tap &#8216;Settings&#8217; and look for &#8216;Notification&#8217;<br />
2) It will display all application with Notification &#8216;turned on&#8217;, then tap the application that is bugging you with Ads.<br />
3) Turn &#8220;OFF&#8221; Alerts, Badges and Sounds.</p>
<p>If the problem persist, you may want to consider to delete it.</p>
<p>How to delete application in iPad/iPhone?</p>
<p>1) Tap the target app, hold and wait until it starts to wiggle.<br />
2) You&#8217;ll notice &#8220;X&#8221; button in the top right corner, which means you may tap it to delete.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ithreats.wordpress.com/1228/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ithreats.wordpress.com/1228/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ithreats.wordpress.com/1228/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ithreats.wordpress.com/1228/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/ithreats.wordpress.com/1228/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/ithreats.wordpress.com/1228/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/ithreats.wordpress.com/1228/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/ithreats.wordpress.com/1228/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ithreats.wordpress.com/1228/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ithreats.wordpress.com/1228/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ithreats.wordpress.com/1228/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ithreats.wordpress.com/1228/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ithreats.wordpress.com/1228/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ithreats.wordpress.com/1228/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ithreats.net&amp;blog=3681895&amp;post=1228&amp;subd=ithreats&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://ithreats.net/2011/01/25/annoying-ads-coming-from-an-ipadiphone-app/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/4d7b7d253fb250ab3887bbcbccd15411?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">meths</media:title>
		</media:content>

		<media:content url="http://ithreats.files.wordpress.com/2011/01/img_0010.png" medium="image">
			<media:title type="html">IMG_0010</media:title>
		</media:content>
	</item>
		<item>
		<title>How to Remove Starfield</title>
		<link>http://ithreats.net/2011/01/17/how-to-remove-starfield/</link>
		<comments>http://ithreats.net/2011/01/17/how-to-remove-starfield/#comments</comments>
		<pubDate>Mon, 17 Jan 2011 13:29:30 +0000</pubDate>
		<dc:creator>Methusela Cebrian Ferrer</dc:creator>
				<category><![CDATA[Emerging Threats]]></category>
		<category><![CDATA[Malwares]]></category>
		<category><![CDATA[OS X]]></category>
		<category><![CDATA[How to remove Firefox plugin Starfield]]></category>
		<category><![CDATA[How to remove Starfield Mac]]></category>
		<category><![CDATA[OffSyncService]]></category>
		<category><![CDATA[StarfieldUpdate]]></category>
		<category><![CDATA[uninstall Starfield Zoom]]></category>
		<category><![CDATA[uninstall Starfield Zoom 1.1]]></category>
		<category><![CDATA[WBE Paste 1.1]]></category>
		<category><![CDATA[wbepaste]]></category>
		<category><![CDATA[zoomext]]></category>

		<guid isPermaLink="false">http://ithreats.net/?p=1211</guid>
		<description><![CDATA[1) Kill the running process. Using spotlight, type-in Activity Monitor and filter by searching starfieldUpdate and click Quit Process. Then, search offSyncService and click Quit Process. If using Terminal, you may run the following command: &#160; killall -9 offSyncService killall -9 starfieldUpdate 2) Delete Starfield internet plugins and components. Using Terminal, you may run the following [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ithreats.net&amp;blog=3681895&amp;post=1211&amp;subd=ithreats&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>1) Kill the running process.</p>
<p>Using spotlight, type-in <span style="color:green;">Activity Monitor </span>and filter by searching <span style="color:green;">starfieldUpdate</span> and click <span style="color:red;">Quit Process</span>. Then, search <span style="color:green;">offSyncService</span> and click <span style="color:red;">Quit Process</span>.</p>
<p>If using Terminal, you may run the following command:<br />
<code> </code></p>
<p>&nbsp;</p>
<p><code></p>
<div>killall -9 offSyncService</div>
<div>killall -9 starfieldUpdate</div>
<p></code><br />
2) Delete Starfield internet plugins and components.</p>
<p>Using Terminal, you may run the following command:<br />
<code> </code></p>
<p>&nbsp;</p>
<p><code></p>
<div>rm -rf ~/Library/Internet\ Plug-Ins/WbeTools64_14.plugin</div>
<div>rm -rf ~/Library/Internet\ Plug-Ins/fileEditTool64_15.plugin</div>
<div>rm -rf ~/Library/Preferences/com.starfield.update.plist</div>
<div>rm -rf ~/Library/Application\ Support/Mozilla/Extensions/\{ec8030f7-c20a-464f-9b0e-13a3a9e97384\}/wbepaste\@starfield</div>
<div>rm -rf ~/Library/Application\ Support/Mozilla/Extensions/\{ec8030f7-c20a-464f-9b0e-13a3a9e97384\}/zoomext\@starfield</div>
<div>rm -rf ~/Library/Application\ Support/Starfield/</div>
<p></code></p>
<p>&nbsp;</p>
<p>3) It will require root password to remove the following files.</p>
<div>Using terminal, type in <span style="color:green;">sudo su</span> and authenticate, then continue:</div>
<div>
<p>&nbsp;</p>
<p><code></p>
<div>rm -rf /Library/LaunchDaemons/com.starfield.backupservice.plist</div>
<div>rm -rf /Library/offsync</div>
<div>rm -rf /Applications/WBE\ Desktop\ Notifier.App</div>
<div>rm -rf /Applications/DesktopTools.App</div>
<div>rm -rf /Applications/Starfield</div>
<div>rm -rf /install.sh</div>
<p></code>&nbsp;</p>
<p>This instruction removes all the traces of Starfield.  Stay safe!</p>
<p>**Note: If you find Starfield application useful, you may keep the &#8216;WBE Desktop Notified.App&#8217; and &#8216;DesktopTools.App&#8217;.</p>
</div>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ithreats.wordpress.com/1211/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ithreats.wordpress.com/1211/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ithreats.wordpress.com/1211/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ithreats.wordpress.com/1211/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/ithreats.wordpress.com/1211/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/ithreats.wordpress.com/1211/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/ithreats.wordpress.com/1211/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/ithreats.wordpress.com/1211/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ithreats.wordpress.com/1211/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ithreats.wordpress.com/1211/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ithreats.wordpress.com/1211/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ithreats.wordpress.com/1211/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ithreats.wordpress.com/1211/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ithreats.wordpress.com/1211/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ithreats.net&amp;blog=3681895&amp;post=1211&amp;subd=ithreats&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://ithreats.net/2011/01/17/how-to-remove-starfield/feed/</wfw:commentRss>
		<slash:comments>14</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/4d7b7d253fb250ab3887bbcbccd15411?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">meths</media:title>
		</media:content>
	</item>
		<item>
		<title>Analysis of OSX Starfield</title>
		<link>http://ithreats.net/2011/01/14/analysis-of-osx-starfield/</link>
		<comments>http://ithreats.net/2011/01/14/analysis-of-osx-starfield/#comments</comments>
		<pubDate>Fri, 14 Jan 2011 15:09:54 +0000</pubDate>
		<dc:creator>Methusela Cebrian Ferrer</dc:creator>
				<category><![CDATA[malware report]]></category>
		<category><![CDATA[OS X]]></category>
		<category><![CDATA[BackupStatusItem.app]]></category>
		<category><![CDATA[com.starfield]]></category>
		<category><![CDATA[DriveMapReconnect.App]]></category>
		<category><![CDATA[DriveMapServer]]></category>
		<category><![CDATA[Firefox Starfield]]></category>
		<category><![CDATA[na.secureserver.net/moduleinfoStarfield]]></category>
		<category><![CDATA[OffSettings.bundle]]></category>
		<category><![CDATA[OffSyncService]]></category>
		<category><![CDATA[rundms]]></category>
		<category><![CDATA[Starfield Zoom]]></category>
		<category><![CDATA[StarfieldInstall]]></category>
		<category><![CDATA[StarfieldUpdate]]></category>
		<category><![CDATA[WBE Paste]]></category>
		<category><![CDATA[WbeSettings.Bundle]]></category>
		<category><![CDATA[zoomext]]></category>
		<category><![CDATA[{ec8030f7-c20a-464f-9b0e-13a3a9e97384}]]></category>

		<guid isPermaLink="false">http://ithreats.net/?p=1179</guid>
		<description><![CDATA[When you download an application or installer from legitimate website, you establish a level of trust expecting not to be tricked or deceived. Distribution: The installer is distributed by Starfield a technology and research branch of Go Daddy Group. If you are Go Daddy user, when you logged-in, this tool is available in the tool section [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ithreats.net&amp;blog=3681895&amp;post=1179&amp;subd=ithreats&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://ithreats.files.wordpress.com/2011/01/starfield.png"><img class="aligncenter size-full wp-image-1180" title="Starfield" src="http://ithreats.files.wordpress.com/2011/01/starfield.png?w=600" alt=""   /></a>When you download an application or installer from legitimate website, you establish a level of trust expecting not to be tricked or deceived.</p>
<p><strong>Distribution: </strong></p>
<p>The installer is distributed by Starfield a technology and research branch of Go Daddy Group. If you are Go Daddy user, when you logged-in, this tool is available in the tool section as:</p>
<p>1)  Desktop Notified Installer</p>
<p><a href="http://ithreats.files.wordpress.com/2011/01/desktop-notifier-installer.png"><img class="aligncenter size-full wp-image-1181" title="Desktop Notifier Installer" src="http://ithreats.files.wordpress.com/2011/01/desktop-notifier-installer.png?w=600" alt=""   /></a></p>
<p>2) It is also offered as &#8220;Web-Based Email Tools plugin&#8221; promising that this tool will enable image paste.</p>
<p><img class="aligncenter size-full wp-image-1182" title="Enable Image Paste" src="http://ithreats.files.wordpress.com/2011/01/enable-image-paste.png?w=600&#038;h=480" alt="" width="600" height="480" /></p>
<p>It&#8217;s possible that this installer will be distributed elsewhere.</p>
<p><a href="http://ithreats.files.wordpress.com/2011/01/view-download.png"><img class="aligncenter size-full wp-image-1184" title="View Download" src="http://ithreats.files.wordpress.com/2011/01/view-download.png?w=600" alt=""   /></a><a href="http://ithreats.files.wordpress.com/2011/01/screen-shot-2011-01-12-at-11-51-35-pm.png"><img class="aligncenter size-full wp-image-1185" title="Screen shot 2011-01-12 at 11.51.35 PM" src="http://ithreats.files.wordpress.com/2011/01/screen-shot-2011-01-12-at-11-51-35-pm.png?w=600" alt=""   /></a>When you download the installer, you&#8217;ll notice two things:</p>
<p>1) It is telling you &#8220;Double-click to Install&#8221;</p>
<p>2) It is not the installer itself, instead it is a shortcut link.</p>
<p>Why?</p>
<p>It is a social engineering trick. It attempts to trigger user&#8217;s immediate impulse to respond based from a command or instruction.</p>
<div>Let&#8217;s check ACL using terminal:</div>
<div>
<p>&nbsp;</p>
<p><code></p>
<div>$ ls -al /Volumes/install</div>
<p></code><span style="font-family:monospace;">total 8</span></p>
<div>
<div>
<div>
<p><code> </code></p>
<p>&nbsp;</p>
<p><code></p>
<div>drwxr-xr-x  7 test  staff  306 23 Dec 03:50 .</div>
<div>drwxrwxrwt@ 6 root  admin  204 12 Jan 23:42 ..</div>
<div>drwxr-xr-x  2 test  staff   68 23 Dec 03:50 .Trashes</div>
<div>lrwxr-xr-x  1 test  staff   20 23 Dec 03:49 Double-click to Install -&gt; StarfieldInstall.app</div>
<div>drwxr-xr-x@ 3 test  staff  102 23 Dec 03:49 StarfieldInstall.app</div>
<p></code>&nbsp;</p>
<div>The application is basically hidden. Obviously, It discourages user to inspect the package. Back in the terminal, let&#8217;s run this command to unhide:</div>
<div>
<p><code> </code></p>
<p>&nbsp;</p>
<p><code></p>
<div>$ defaults write com.apple.finder AppleShowAllFiles TRUE</div>
<div>$ killall Finder</div>
<p></code><a href="http://ithreats.files.wordpress.com/2011/01/unhide-starfieldinstall.png"><img class="aligncenter size-full wp-image-1187" title="Unhide StarfieldInstall" src="http://ithreats.files.wordpress.com/2011/01/unhide-starfieldinstall.png?w=600" alt=""   /></a><strong>Installation: </strong>What happens when you &#8216;double click&#8217; it?  You&#8217;ll notice that it requires root privilege.</p>
<p><a href="http://ithreats.files.wordpress.com/2011/01/authorize-starfield.png"><img class="aligncenter size-full wp-image-1188" title="Authorize Starfield" src="http://ithreats.files.wordpress.com/2011/01/authorize-starfield.png?w=600" alt=""   /></a>In this stage, it is already too late because even if you decide to discard or cancel the authorization, the tricky &#8216;StarfieldInstall.app&#8217; has already installed itself as follows:</p>
<p>1)  It creates a &#8216;Starfield&#8217; folder in the Application directory.  In this folder, you&#8217;ll find a copy of itself and an update component.</p>
<p><code><code>/Application/Starfield/</code>StarfieldInstall.app</code></p>
<p><code> </code><code><code>/Application/Starfield/</code>starfieldupdate.app</code></p>
<p>2) It is set to run at login by adding &#8216;starfieldupdate&#8217; in the Login Items.</p>
<p><a href="http://ithreats.files.wordpress.com/2011/01/login-items.png"><img class="aligncenter size-full wp-image-1190" title="Login Items" src="http://ithreats.files.wordpress.com/2011/01/login-items.png?w=600&#038;h=490" alt="" width="600" height="490" /></a>3) It is always running in the background.</p>
<p>&nbsp;</p>
<p><code></p>
<div>$ lsof -c Starfield</div>
<div>COMMAND   PID USER   FD     TYPE     DEVICE  SIZE/OFF    NODE NAME</div>
<div>Starfield 221 test  cwd      DIR       14,2      1394       2 /</div>
<div>Starfield 221 test  txt      REG       14,2     93668 1294527 /Applications/Starfield/starfieldupdate.app/Contents/MacOS/StarfieldUpdate</div>
<div>Starfield 221 test  txt      REG       14,2   1064960 2655251 /private/var/folders/ur/urE9xwfCE+a922ltbYjezk+++TU/-Caches-/com.apple.LaunchServices-025504.csstore</div>
<div>Starfield 221 test  txt      REG       14,2   1054960   25052 /usr/lib/dyld</div>
<div>Starfield 221 test  txt      REG       14,2 206983168 2609511 /private/var/db/dyld/dyld_shared_cache_i386</div>
<div>Starfield 221 test    0r     CHR        3,2       0t0     297 /dev/null</div>
<div>Starfield 221 test    1     PIPE 0x079a7640     16384         -&gt;0x079a76a4</div>
<div>Starfield 221 test    2     PIPE 0x079a7640     16384         -&gt;0x079a76a4</div>
<div>Starfield 221 test    3r     REG       14,2       163   42178 /private/etc/security/audit_control</div>
<div>Starfield 221 test    4u  KQUEUE                              count=1, state=0x2</div>
<div>Starfield 221 test    5r     REG       14,2     93668 1294527 /Applications/Starfield/starfieldupdate.app/Contents/MacOS/StarfieldUpdate</div>
<div>Starfield 221 test   66r     REG       14,2       611   42177 /private/etc/security/audit_class</div>
<p></code>So, when you thought it&#8217;s gone, it&#8217;s not because &#8216;StarfieldInstall&#8217; sleeps and activates again to request your password. It will continue to annoy you with repeated request until it gets authorized.</p>
<div><span style="font-family:Georgia, 'Times New Roman', 'Bitstream Charter', Times, serif;">On a sidenote, &#8216;StarfieldUpdate.app&#8217; gets the following information:</span></div>
<ul>
<li>OS version and CPU Type</li>
<li>Local user</li>
<li>Previous installation</li>
<li>Starfield installation component versions</li>
</ul>
<p>And performs the following:</p>
<ul>
<li>Checks user privilege on the system by checking if user is admin or if the user can be elevated to admin.</li>
<li>StarfieldInstall launches &#8216;starfieldupdate.app&#8217; which is kept in the background.</li>
<li>&#8216;starfieldupdate.app&#8217; is responsible for initial installation (first run) and updates.</li>
<li>The initial installation path of Starfield would be:</li>
</ul>
<div>
<div>/Applications/Starfield</div>
<div>/Library/Application Support/Starfield</div>
<div>/Library/Internet Plug-ins/</div>
<div>/Library/Application Support/Mozilla/Extensions/{ec8030f7-c20a-464f-9b0e-13a3a9e97384}</div>
</div>
<ul>
<li>Dumps data log of its activity especially the installation. Notice the name &#8216;starfield&#8217; in the ~/Library/Logs/ folder.</li>
</ul>
<p>&nbsp;</p>
<p><code></p>
<div>Launch.cpp(18): Launching /Applications/Starfield/StarfieldUpdate.app runme</div>
<div>StarfieldInstall.cpp(862): Starting v1.0.4.9 with command: -psn_0_1011959</div>
<div>StarfieldInstall.cpp(879): OS Version 10.6 x86</div>
<div>StarfieldInstall.cpp(880): Local user test (test)</div>
<div>StarfieldInstall.cpp(881): User can become administrator.</div>
<div>
<div>StarfieldUpdate.cpp(90): Starting v1.0.3.3 with command: -psn_0_1007862</div>
<div>StarfieldUpdate.cpp(119): launchargs runme</div>
<div>StarfieldUpdate.cpp(144): Local user test</div>
<div>StarfieldUpdate.cpp(145): User can become administrator.</div>
<div>StarfieldUpdate.cpp(162): Launching /Applications/Starfield/StarfieldInstall.app</div>
<div>Launch.cpp(18): Launching /Applications/Starfield/StarfieldInstall.app</div>
</div>
<p></code><strong>Payload: </strong></p>
<p>The payload is mainly handled by &#8216;StarfieldInstall.app&#8217;. When the user inputs the password, the installation continues by sending a HTTP request to the server as follows:</p>
<div>
<p><span style="color:#c80000;"> </span></p>
<div>GET /moduleinfo HTTP/1.1</div>
<div>User-Agent: StarfieldInstall/1.0</div>
<div>Host: na.secureserver.net</div>
<div>Accept: *.*</div>
</div>
<p>&#8216;Moduleinfo&#8217; is a JSON text which &#8216;StarfieldInstall.app&#8217; parses and evaluating the content of a JSON string. For example, it reads and evaluate which package appropriate to the user: Windows or Mac.</p>
<p><code><br />
{ "win" :</code></p>
<p><code> </code>&#8230;</p>
<p><code>, "mac" :</code></p>
<p>It also evaluates the installation requirement, example:<br />
<code> </code></p>
<p>&nbsp;</p>
<p><code></p>
<div>, "mac" :</div>
<div>[ { "file" : "StarfieldInstall.App"</div>
<div>, "version" : 4</div>
<div>, "source" : "starfieldinstall.zip"</div>
<div>, "app" : "*"</div>
<div>, "type" : "util"</div>
<div>, "adminRequired" : false</div>
<div>, "osMin" : [10,4]</div>
<div>}</div>
<p></code>&#8216;StarfieldInstall&#8217; compares this requirement defined by JSON file &#8216;moduleinfo&#8217; before it downloads, extracts and run the latest package resulting to installation of the following:</p>
<p>starfieldinstall.zip</p>
<p>starfieldupdate.zip</p>
<p>fileedittool64.plugin.zip</p>
<p>fileedittool.zip</p>
<p>WBETools14.plugin</p>
<p>wbetools64.zip</p>
<p>copypaste.xpi</p>
<p>zoomext.xpi</p>
<p>offdavhelper_mac4.zip</p>
<p>offdavhelper_mac.zip</p>
<p>offsettings.bundle.zip</p>
<p>wbesettings.bundle.zip</p>
<p>drivemapreconnect.zip</p>
<p>backupstatus.zip</p>
<p>offsync_mac.zip</p>
<p>desktoptools.zip</p>
<p>wbedesktopnotifier.zip</p>
<p>So far we have 17 files here and 4 of these files do not require root password. It is important to take note that  &#8217;StarfieldUpdate.app&#8217; is always running in the background and launch &#8216;StarfieldInstall.app&#8217; to perform the following:</p>
<p>- Evaluating JSON text &#8216;moduleinfo&#8217; for update</p>
<p>- Download and installation of latest versions</p>
<p>- Discovery of products installed</p>
<p>- Running privileged shell command</p>
<p>It installs two Firefox extensions and plugins, which is persistent. It means that you can&#8217;t just click &#8216;uninstall&#8217; to remove it . In Firefox, click Tools and Addons to view the installed Extensions and Plugins as shown below:</p>
<p><a href="http://ithreats.files.wordpress.com/2011/01/starfield-plugins.png"><img class="aligncenter size-full wp-image-1199" title="Starfield Plugins" src="http://ithreats.files.wordpress.com/2011/01/starfield-plugins.png?w=600&#038;h=189" alt="" width="600" height="189" /></a></p>
<p><a href="http://ithreats.files.wordpress.com/2011/01/starfield-plugins.png"></a><a href="http://ithreats.files.wordpress.com/2011/01/startfield-extensions.png"><img class="aligncenter size-full wp-image-1200" title="Startfield Extensions" src="http://ithreats.files.wordpress.com/2011/01/startfield-extensions.png?w=600&#038;h=201" alt="" width="600" height="201" /></a></p>
<p>Another notable process created is &#8216;OffSyncService&#8217; which is always running in the background .</p>
<p>In conclusion, this is a nasty and abusive application that performs remote activities and installation of unwanted plugins and application without user consent. It is a bloatware and a backdoor.</p>
</div>
</div>
</div>
</div>
</div>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ithreats.wordpress.com/1179/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ithreats.wordpress.com/1179/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ithreats.wordpress.com/1179/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ithreats.wordpress.com/1179/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/ithreats.wordpress.com/1179/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/ithreats.wordpress.com/1179/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/ithreats.wordpress.com/1179/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/ithreats.wordpress.com/1179/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ithreats.wordpress.com/1179/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ithreats.wordpress.com/1179/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ithreats.wordpress.com/1179/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ithreats.wordpress.com/1179/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ithreats.wordpress.com/1179/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ithreats.wordpress.com/1179/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ithreats.net&amp;blog=3681895&amp;post=1179&amp;subd=ithreats&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://ithreats.net/2011/01/14/analysis-of-osx-starfield/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/4d7b7d253fb250ab3887bbcbccd15411?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">meths</media:title>
		</media:content>

		<media:content url="http://ithreats.files.wordpress.com/2011/01/starfield.png" medium="image">
			<media:title type="html">Starfield</media:title>
		</media:content>

		<media:content url="http://ithreats.files.wordpress.com/2011/01/desktop-notifier-installer.png" medium="image">
			<media:title type="html">Desktop Notifier Installer</media:title>
		</media:content>

		<media:content url="http://ithreats.files.wordpress.com/2011/01/enable-image-paste.png" medium="image">
			<media:title type="html">Enable Image Paste</media:title>
		</media:content>

		<media:content url="http://ithreats.files.wordpress.com/2011/01/view-download.png" medium="image">
			<media:title type="html">View Download</media:title>
		</media:content>

		<media:content url="http://ithreats.files.wordpress.com/2011/01/screen-shot-2011-01-12-at-11-51-35-pm.png" medium="image">
			<media:title type="html">Screen shot 2011-01-12 at 11.51.35 PM</media:title>
		</media:content>

		<media:content url="http://ithreats.files.wordpress.com/2011/01/unhide-starfieldinstall.png" medium="image">
			<media:title type="html">Unhide StarfieldInstall</media:title>
		</media:content>

		<media:content url="http://ithreats.files.wordpress.com/2011/01/authorize-starfield.png" medium="image">
			<media:title type="html">Authorize Starfield</media:title>
		</media:content>

		<media:content url="http://ithreats.files.wordpress.com/2011/01/login-items.png" medium="image">
			<media:title type="html">Login Items</media:title>
		</media:content>

		<media:content url="http://ithreats.files.wordpress.com/2011/01/starfield-plugins.png" medium="image">
			<media:title type="html">Starfield Plugins</media:title>
		</media:content>

		<media:content url="http://ithreats.files.wordpress.com/2011/01/startfield-extensions.png" medium="image">
			<media:title type="html">Startfield Extensions</media:title>
		</media:content>
	</item>
		<item>
		<title>Drag and Drop</title>
		<link>http://ithreats.net/2011/01/07/drag-and-drop/</link>
		<comments>http://ithreats.net/2011/01/07/drag-and-drop/#comments</comments>
		<pubDate>Fri, 07 Jan 2011 13:11:33 +0000</pubDate>
		<dc:creator>Methusela Cebrian Ferrer</dc:creator>
				<category><![CDATA[Emerging Threats]]></category>
		<category><![CDATA[iPhone]]></category>
		<category><![CDATA[OS X]]></category>
		<category><![CDATA[deceptive packaging]]></category>
		<category><![CDATA[Drag and Drop Mac App Cracking]]></category>

		<guid isPermaLink="false">http://ithreats.net/?p=1172</guid>
		<description><![CDATA[This is unfortunate for business, and a worrying attack vector. The Mac App store was easily bypassed and cracked by this simple drag and drop process. Evidently, you&#8217;ll find it &#8216;Installed&#8217; when you open the app. Please be reminded that &#8216;deceptive packaging&#8217; takes advantage of legitimate software and application packaging to obscure the possible execution of [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ithreats.net&amp;blog=3681895&amp;post=1172&amp;subd=ithreats&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://ithreats.files.wordpress.com/2011/01/replacable.png"><img class="aligncenter size-full wp-image-1173" title="Replacable" src="http://ithreats.files.wordpress.com/2011/01/replacable.png?w=600&#038;h=347" alt="" width="600" height="347" /></a></p>
<p>This is unfortunate for business, and a worrying attack vector. The Mac App store was easily bypassed and cracked by this simple drag and drop process. Evidently, you&#8217;ll find it &#8216;Installed&#8217; when you open the app.</p>
<p><a href="http://ithreats.files.wordpress.com/2011/01/installed.png"><img class="aligncenter size-full wp-image-1174" title="Installed" src="http://ithreats.files.wordpress.com/2011/01/installed.png?w=600" alt=""   /></a></p>
<p>Please be reminded that &#8216;deceptive packaging&#8217; takes advantage of legitimate software and application packaging to obscure the possible execution of malicious code;  and, this provides attacker a good opportunity.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ithreats.wordpress.com/1172/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ithreats.wordpress.com/1172/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ithreats.wordpress.com/1172/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ithreats.wordpress.com/1172/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/ithreats.wordpress.com/1172/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/ithreats.wordpress.com/1172/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/ithreats.wordpress.com/1172/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/ithreats.wordpress.com/1172/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ithreats.wordpress.com/1172/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ithreats.wordpress.com/1172/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ithreats.wordpress.com/1172/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ithreats.wordpress.com/1172/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ithreats.wordpress.com/1172/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ithreats.wordpress.com/1172/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ithreats.net&amp;blog=3681895&amp;post=1172&amp;subd=ithreats&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://ithreats.net/2011/01/07/drag-and-drop/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/4d7b7d253fb250ab3887bbcbccd15411?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">meths</media:title>
		</media:content>

		<media:content url="http://ithreats.files.wordpress.com/2011/01/replacable.png" medium="image">
			<media:title type="html">Replacable</media:title>
		</media:content>

		<media:content url="http://ithreats.files.wordpress.com/2011/01/installed.png" medium="image">
			<media:title type="html">Installed</media:title>
		</media:content>
	</item>
	</channel>
</rss>
