<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>H e s s a m x</title>
	<atom:link href="http://hessamx.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://hessamx.wordpress.com</link>
	<description></description>
	<lastBuildDate>Sun, 15 May 2011 14:39:21 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='hessamx.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>H e s s a m x</title>
		<link>http://hessamx.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://hessamx.wordpress.com/osd.xml" title="H e s s a m x" />
	<atom:link rel='hub' href='http://hessamx.wordpress.com/?pushpress=hub'/>
		<item>
		<title>moved !</title>
		<link>http://hessamx.wordpress.com/2007/05/04/moved/</link>
		<comments>http://hessamx.wordpress.com/2007/05/04/moved/#comments</comments>
		<pubDate>Fri, 04 May 2007 14:18:04 +0000</pubDate>
		<dc:creator>hessam</dc:creator>
		
		<guid isPermaLink="false">http://hessamx.wordpress.com/2007/05/04/moved/</guid>
		<description><![CDATA[I didn’t post for quite sometime is because I am really busy with my school exams. and start again next month . and this weblog completely moved to hessamx.net and this weblog closed ! If you added my link in your weblog or website please change it.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hessamx.wordpress.com&amp;blog=468901&amp;post=103&amp;subd=hessamx&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I didn’t post for quite sometime is because I am really busy with my school exams.<br />
and start again next month . and this weblog completely moved to <a target="_blank" href="http://hessamx.net">hessamx.net</a> and this weblog closed !<br />
<strong>If you added my link in your weblog or website please change it.</strong></p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/hessamx.wordpress.com/103/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/hessamx.wordpress.com/103/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hessamx.wordpress.com/103/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hessamx.wordpress.com/103/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hessamx.wordpress.com/103/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hessamx.wordpress.com/103/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hessamx.wordpress.com/103/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hessamx.wordpress.com/103/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hessamx.wordpress.com/103/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hessamx.wordpress.com/103/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hessamx.wordpress.com/103/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hessamx.wordpress.com/103/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hessamx.wordpress.com/103/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hessamx.wordpress.com/103/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hessamx.wordpress.com/103/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hessamx.wordpress.com/103/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hessamx.wordpress.com&amp;blog=468901&amp;post=103&amp;subd=hessamx&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hessamx.wordpress.com/2007/05/04/moved/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/ff888dfa073975af6f8183a0a2acd11a?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">hessam</media:title>
		</media:content>
	</item>
		<item>
		<title>Analysis of Malware Spread via SPAM and ANI vulnerability</title>
		<link>http://hessamx.wordpress.com/2007/04/09/analysis-of-malware-spread-via-spam-and-ani-vulnerability/</link>
		<comments>http://hessamx.wordpress.com/2007/04/09/analysis-of-malware-spread-via-spam-and-ani-vulnerability/#comments</comments>
		<pubDate>Mon, 09 Apr 2007 12:04:56 +0000</pubDate>
		<dc:creator>hessam</dc:creator>
				<category><![CDATA[malware]]></category>

		<guid isPermaLink="false">http://hessamx.wordpress.com/2007/04/09/analysis-of-malware-spread-via-spam-and-ani-vulnerability/</guid>
		<description><![CDATA[i posted about ANI vulnerability malware some days ago and today i saw a paper on websense security labs about analysis of malware spread via spam and ANI vuln. view this paper on websense<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hessamx.wordpress.com&amp;blog=468901&amp;post=102&amp;subd=hessamx&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>i posted about ANI vulnerability malware some days ago and today i saw a paper on websense security labs about analysis of malware spread via spam and ANI vuln.<br />
<a href="http://www.websense.com/securitylabs/blog/blog.php?BlogID=121" target="_blank">view this paper on websense</a></p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/hessamx.wordpress.com/102/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/hessamx.wordpress.com/102/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hessamx.wordpress.com/102/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hessamx.wordpress.com/102/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hessamx.wordpress.com/102/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hessamx.wordpress.com/102/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hessamx.wordpress.com/102/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hessamx.wordpress.com/102/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hessamx.wordpress.com/102/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hessamx.wordpress.com/102/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hessamx.wordpress.com/102/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hessamx.wordpress.com/102/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hessamx.wordpress.com/102/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hessamx.wordpress.com/102/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hessamx.wordpress.com/102/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hessamx.wordpress.com/102/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hessamx.wordpress.com&amp;blog=468901&amp;post=102&amp;subd=hessamx&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hessamx.wordpress.com/2007/04/09/analysis-of-malware-spread-via-spam-and-ani-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/ff888dfa073975af6f8183a0a2acd11a?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">hessam</media:title>
		</media:content>
	</item>
		<item>
		<title>Perl Underground 4</title>
		<link>http://hessamx.wordpress.com/2007/04/09/perl-underground-4/</link>
		<comments>http://hessamx.wordpress.com/2007/04/09/perl-underground-4/#comments</comments>
		<pubDate>Mon, 09 Apr 2007 11:59:52 +0000</pubDate>
		<dc:creator>hessam</dc:creator>
		
		<guid isPermaLink="false">http://hessamx.wordpress.com/2007/04/09/perl-underground-4/</guid>
		<description><![CDATA[Perl Underground talk about exploiters perl codes. in this ezine they focused on bad perl codes. this is really nice . Read this ezine on milw0rm.com<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hessamx.wordpress.com&amp;blog=468901&amp;post=101&amp;subd=hessamx&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Perl Underground talk about exploiters perl codes. in this ezine they focused on bad perl codes.<br />
this is really nice .<br />
Read this ezine on <a href="http://www.milw0rm.com/papers/143" target="_blank">milw0rm.com</a></p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/hessamx.wordpress.com/101/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/hessamx.wordpress.com/101/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hessamx.wordpress.com/101/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hessamx.wordpress.com/101/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hessamx.wordpress.com/101/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hessamx.wordpress.com/101/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hessamx.wordpress.com/101/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hessamx.wordpress.com/101/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hessamx.wordpress.com/101/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hessamx.wordpress.com/101/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hessamx.wordpress.com/101/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hessamx.wordpress.com/101/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hessamx.wordpress.com/101/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hessamx.wordpress.com/101/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hessamx.wordpress.com/101/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hessamx.wordpress.com/101/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hessamx.wordpress.com&amp;blog=468901&amp;post=101&amp;subd=hessamx&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hessamx.wordpress.com/2007/04/09/perl-underground-4/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/ff888dfa073975af6f8183a0a2acd11a?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">hessam</media:title>
		</media:content>
	</item>
		<item>
		<title>New worm use the .ani zero day vulnerability</title>
		<link>http://hessamx.wordpress.com/2007/04/02/new-worm-use-the-ani-zero-day-vulnerability/</link>
		<comments>http://hessamx.wordpress.com/2007/04/02/new-worm-use-the-ani-zero-day-vulnerability/#comments</comments>
		<pubDate>Mon, 02 Apr 2007 13:01:44 +0000</pubDate>
		<dc:creator>hessam</dc:creator>
				<category><![CDATA[Analysis]]></category>
		<category><![CDATA[malware]]></category>

		<guid isPermaLink="false">http://hessamx.wordpress.com/2007/04/02/new-worm-use-the-ani-zero-day-vulnerability/</guid>
		<description><![CDATA[Some days ago researchers declared an alert for Microsoft Windows Cursor and Icon(.ANI) zero day vulnerability . now they declared an alert for a new worm . &#8220;It&#8217;s a bad news that the Windows Animated Cursor Handling zero-day vulnerability has been used by malwares in China now. We have received this kind of new worm [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hessamx.wordpress.com&amp;blog=468901&amp;post=99&amp;subd=hessamx&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p class="content">Some days ago researchers declared an alert for Microsoft Windows Cursor and Icon(.ANI) zero day vulnerability . now they declared an alert for a new worm .<br />
&#8220;It&#8217;s a bad news that the Windows Animated Cursor Handling zero-day vulnerability has been used by malwares in China now. We have received this kind of new worm today. It has the same behavior as Worm.Win32.Fujacks. It also can infects .HTML .ASPX .HTM .PHP .JSP .ASP and .EXE files, and inserts the malicious links which contained Windows Animated Cursor Handling zero-day vulnerability into .HTML .ASPX .HTM .PHP .JSP .ASP files. It also can send out Chinese spams which are include the same zero-day vulnerability link. &#8220;<br />
view analysis on CISRT</p>
<p>http://www.cisrt.org/enblog/read.php?68</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/hessamx.wordpress.com/99/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/hessamx.wordpress.com/99/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hessamx.wordpress.com/99/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hessamx.wordpress.com/99/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hessamx.wordpress.com/99/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hessamx.wordpress.com/99/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hessamx.wordpress.com/99/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hessamx.wordpress.com/99/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hessamx.wordpress.com/99/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hessamx.wordpress.com/99/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hessamx.wordpress.com/99/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hessamx.wordpress.com/99/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hessamx.wordpress.com/99/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hessamx.wordpress.com/99/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hessamx.wordpress.com/99/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hessamx.wordpress.com/99/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hessamx.wordpress.com&amp;blog=468901&amp;post=99&amp;subd=hessamx&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hessamx.wordpress.com/2007/04/02/new-worm-use-the-ani-zero-day-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/ff888dfa073975af6f8183a0a2acd11a?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">hessam</media:title>
		</media:content>
	</item>
		<item>
		<title>Security Links !!</title>
		<link>http://hessamx.wordpress.com/2007/03/21/security-links/</link>
		<comments>http://hessamx.wordpress.com/2007/03/21/security-links/#comments</comments>
		<pubDate>Wed, 21 Mar 2007 13:05:23 +0000</pubDate>
		<dc:creator>hessam</dc:creator>
				<category><![CDATA[Security Websites]]></category>

		<guid isPermaLink="false">http://hessamx.wordpress.com/2007/03/21/security-links/</guid>
		<description><![CDATA[ArazSamadi have a nice list of security websites and weblog you can view this list here . FIRST global security netsec Mega security Digg security Donna&#8217;s SecurityFlash Symantec SR blog Mike Rothman ISC sans Mike Rothman frsirt osvdb milw0rm secunia nnov.ru security National Vulnerability DB ONLamp &#8211; Security securiteam SecurityFocus (list is long &#8230; read more [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hessamx.wordpress.com&amp;blog=468901&amp;post=98&amp;subd=hessamx&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a target="_blank" href="http://arazsamadi.blogspot.com">ArazSamadi</a> have a nice list of security websites and weblog you can view this list here .</p>
<li><a href="http://www.first.org/newsroom/globalsecurity/"><font color="#5588aa">FIRST global security</font></a></li>
<li><a href="http://netsec.blogspot.com/"><font color="#5588aa">netsec</font></a></li>
<li><a href="http://www.megasecurity.org/Main.html"><font color="#5588aa">Mega security</font></a></li>
<li><a href="http://digg.com/security/"><font color="#5588aa">Digg security</font></a></li>
<li><a href="http://msmvps.com/blogs/donna/"><font color="#5588aa">Donna&#8217;s SecurityFlash</font></a></li>
<li><a href="http://www.symantec.com/enterprise/security_response/weblog/"><font color="#5588aa">Symantec SR blog</font></a></li>
<li><a href="http://securityincite.com/blog/mike-rothman"><font color="#5588aa">Mike Rothman</font></a></li>
<li><a href="http://isc.sans.org/"><font color="#5588aa">ISC sans</font></a></li>
<li><a href="http://securityincite.com/blog/mike-rothman"><font color="#5588aa">Mike Rothman</font></a></li>
<li><a href="http://www.frsirt.com/english/"><font color="#5588aa">frsirt</font></a></li>
<li><a href="http://www.osvdb.org/"><font color="#5588aa">osvdb</font></a></li>
<li><a href="http://www.milw0rm.com/"><font color="#5588aa">milw0rm</font></a></li>
<li><a href="http://www.secunia.com/"><font color="#5588aa">secunia</font></a></li>
<li><a href="http://www.security.nnov.ru/"><font color="#5588aa">nnov.ru security</font></a></li>
<li><a href="http://nvd.nist.gov/"><font color="#5588aa">National Vulnerability DB</font></a></li>
<li><a href="http://www.onlamp.com/security/"><font color="#5588aa">ONLamp &#8211; Security</font></a></li>
<li><a href="http://www.securiteam.com/"><font color="#5588aa">securiteam</font></a></li>
<li><a href="http://www.securityfocus.com/"><font color="#5588aa">SecurityFocus</font></a><br />
(list is long &#8230; read more )</p>
<p><span id="more-98"></span></li>
<li><a href="http://www.first.org/newsroom/globalsecurity/"><font color="#5588aa">FIRST global security</font></a></li>
<li><a href="http://netsec.blogspot.com/"><font color="#5588aa">netsec</font></a></li>
<li><a href="http://www.megasecurity.org/Main.html"><font color="#5588aa">Mega security</font></a></li>
<li><a href="http://digg.com/security/"><font color="#5588aa">Digg security</font></a></li>
<li><a href="http://msmvps.com/blogs/donna/"><font color="#5588aa">Donna&#8217;s SecurityFlash</font></a></li>
<li><a href="http://www.symantec.com/enterprise/security_response/weblog/"><font color="#5588aa">Symantec SR blog</font></a></li>
<li><a href="http://securityincite.com/blog/mike-rothman"><font color="#5588aa">Mike Rothman</font></a></li>
<li><a href="http://isc.sans.org/"><font color="#5588aa">ISC sans</font></a></li>
<li><a href="http://securityincite.com/blog/mike-rothman"><font color="#5588aa">Mike Rothman</font></a></li>
<li><a href="http://www.frsirt.com/english/"><font color="#5588aa">frsirt</font></a></li>
<li><a href="http://www.osvdb.org/"><font color="#5588aa">osvdb</font></a></li>
<li><a href="http://www.milw0rm.com/"><font color="#5588aa">milw0rm</font></a></li>
<li><a href="http://www.secunia.com/"><font color="#5588aa">secunia</font></a></li>
<li><a href="http://www.security.nnov.ru/"><font color="#5588aa">nnov.ru security</font></a></li>
<li><a href="http://nvd.nist.gov/"><font color="#5588aa">National Vulnerability DB</font></a></li>
<li><a href="http://www.onlamp.com/security/"><font color="#5588aa">ONLamp &#8211; Security</font></a></li>
<li><a href="http://www.securiteam.com/"><font color="#5588aa">securiteam</font></a></li>
<li><a href="http://www.securityfocus.com/"><font color="#5588aa">SecurityFocus</font></a></li>
<li><a href="http://www.snpx.com/index.shtml"><font color="#5588aa">Security News Portal</font></a></li>
<li><a href="http://www.securitytracker.com/"><font color="#5588aa">SecurityTracker</font></a></li>
<li><a href="http://www.cert.org/"><font color="#5588aa">CERT</font></a></li>
<li><a href="http://www.us-cert.gov/"><font color="#5588aa">US-CERT</font></a></li>
<li><a href="http://www.windowsecurity.com/"><font color="#5588aa">Windowsecurity</font></a></li>
<li><a href="http://www.osnews.com/"><font color="#5588aa">osnews</font></a></li>
<li><a href="http://hessamx.wordpress.com/wp-admin/"></a></li>
<li><a href="http://www.undeadly.org/"><font color="#5588aa">undeadly</font></a></li>
<li><a href="http://www.eweek.com/category2/0,1738,1237860,00.asp"><font color="#5588aa">eWeek &#8211; security</font></a></li>
<li><a href="http://www.computerworld.com/blogs/security"><font color="#5588aa">computerworld &#8211; secblogs</font></a></li>
<li><a href="http://www.securitycurve.com/blog/"><font color="#5588aa">Security Curve</font></a></li>
<li><a href="http://www.infosecwriters.com/"><font color="#5588aa">Infosecwriters</font></a></li>
<li><a href="http://blogs.zdnet.com/threatchaos/"><font color="#5588aa">threat chaos</font></a></li>
<li><a href="http://www.packetstormsecurity.org/"><font color="#5588aa">packetstorm</font></a></li>
<li><a href="http://www.matasano.com/log/"><font color="#5588aa">matasanochargen</font></a></li>
<li><a href="http://news.zdnet.com/2001-1009_22-0.html"><font color="#5588aa">zdnet security</font></a></li>
<li><a href="http://www.spamroll.com/"><font color="#5588aa">spamroll</font></a></li>
<li><a href="http://www.theconvergingnetwork.com/"><font color="#5588aa">converging network</font></a></li>
<li><a href="http://www.mckeay.net/secure/"><font color="#5588aa">Mckeay blog</font></a></li>
<li><a href="http://blogs.washingtonpost.com/securityfix/"><font color="#5588aa">Brian Krebs WP</font></a></li>
<li><a href="http://www.bloginfosec.com/"><font color="#5588aa">Kenneth F. Belva</font></a></li>
<li><a href="http://msmvps.com/blogs/harrywaldron/"><font color="#5588aa">Harry Waldron</font></a></li>
<li><a href="http://www.darknet.org.uk/"><font color="#5588aa">darknet</font></a></li>
<li><a href="http://blogs.ittoolbox.com/security/adventures"><font color="#5588aa">Adventures</font></a></li>
<li><a href="http://slashdot.org/search.pl?tid=172"><font color="#5588aa">Slashdot &#8211; security</font></a></li>
<li><a href="http://www.darkreading.com/"><font color="#5588aa">Dark reading</font></a></li>
<li><a href="http://blogs.securiteam.com/"><font color="#5588aa">securiteam blog</font></a></li>
<li><a href="http://www.emergentchaos.com/"><font color="#5588aa">Emergent Chaos</font></a></li>
<li><a href="http://www.f-secure.com/weblog/"><font color="#5588aa">f-secure</font></a></li>
<li><a href="http://taosecurity.blogspot.com/"><font color="#5588aa">TaoSecurity</font></a></li>
<li><a href="http://www.ranum.com/index.html"><font color="#5588aa">Marcus J. Ranum</font></a></li>
<li><a href="http://hessamx.wordpress.com/wp-admin/"></a></li>
<li><a href="http://news.com.com/2001-1009_3-0.html?tag=ne.tab.hd"><font color="#5588aa">CNET news.com &#8211; threats</font></a></li>
<li><a href="http://blogs.technet.com/msrc/default.aspx"><font color="#5588aa">microsoft src</font></a></li>
<li><a href="http://www.wormblog.com/"><font color="#5588aa">worm blog</font></a></li>
<li><a href="http://www.pauldotcom.com/"><font color="#5588aa">pauldotcom</font></a></li>
<li><a href="http://www.it-security-blog.com/"><font color="#5588aa">IT security</font></a></li>
<li><a href="http://netsecurity.about.com/"><font color="#5588aa">netsecurity</font></a></li>
<li><a href="http://blogs.ittoolbox.com/security/investigator"><font color="#5588aa">investigator</font></a></li>
<li><a href="http://msinfluentials.com/blogs/jesper/"><font color="#5588aa">Jesper&#8217;s Blog</font></a></li>
<li><a href="http://anti-virus-rants.blogspot.com/"><font color="#5588aa">Kurt Wismer</font></a></li>
<li><a href="http://www.lightbluetouchpaper.org/"><font color="#5588aa">light blue</font></a></li>
<li><a href="http://www.freedom-to-tinker.com/"><font color="#5588aa">Ed Felten</font></a></li>
<li><a href="http://hhi.corecom.com/weblogindex.htm"><font color="#5588aa">Dave Piscitello</font></a></li>
<li><a href="http://www.stillsecureafteralltheseyears.com/"><font color="#5588aa">still secure</font></a></li>
<li><a href="http://www.757.org/~joat/cgi-bin/blosxom.cgi/"><font color="#5588aa">joatBLOG</font></a></li>
<li><a href="http://ha.ckers.org/"><font color="#996699">ha.ckers</font></a></li>
<li><a href="http://blogs.msdn.com/michael_howard/"><font color="#5588aa">Micheal Howard</font></a></li>
<li><a href="http://www.cerias.purdue.edu/weblogs/"><font color="#5588aa">CERIAS Weblogs</font></a></li>
<li><a href="http://www.osvdb.org/blog/"><font color="#5588aa">OSVDB Blog</font></a></li>
<li><a href="http://www.sans.org/newsletters/risk/"><font color="#5588aa">SANS @Risk</font></a></li>
<li><a href="http://hessamx.wordpress.com/wp-admin/"></a></li>
<li><a href="http://www.websense.com/securitylabs/blog/"><font color="#5588aa">websense secblog</font></a></li>
<li><a href="http://www.security-protocols.com/"><font color="#5588aa">security protocols</font></a></li>
<li><a href="http://www.offensivecomputing.net/"><font color="#996699">offensive computing</font></a></li>
<li><a href="http://chuvakin.blogspot.com/"><font color="#5588aa">Anton Chuvakin</font></a></li>
<li><a href="http://silverstr.ufies.org/blog/"><font color="#5588aa">SilverStr</font></a></li>
<li><a href="http://www.vitalsecurity.org/"><font color="#5588aa">vital security</font></a></li>
<li><a href="http://slashdot.org/search.pl?tid=158"><font color="#5588aa">Slashdot &#8211; privacy</font></a></li>
<li><a href="http://asert.arbornetworks.com/"><font color="#5588aa">arbor security blog</font></a></li>
<li><a href="http://technobabylon.typepad.com/tb/"><font color="#5588aa">Technobabylon</font></a></li>
<li><a href="http://bubbler.net/5A-pages/560399"><font color="#5588aa">Montreal Blog</font></a></li>
<li><a href="http://spiresecurity.typepad.com/spire_security_viewpoint/"><font color="#5588aa">spire security</font></a></li>
<li><a href="http://radio.weblogs.com/0111797/"><font color="#5588aa">Mark O&#8217;Neill</font></a></li>
<li><a href="http://weblog.infoworld.com/zeroday/"><font color="#5588aa">zeroday</font></a></li>
<li><a href="http://www.professionalsecuritytesters.org/"><font color="#5588aa">Pro securitytesters</font></a></li>
<li><a href="http://metasploit.blogspot.com/"><font color="#5588aa">metasploit blog</font></a></li>
<li><a href="http://www.gocsi.com/blog/"><font color="#5588aa">CSI Blog</font></a></li>
<li><a href="http://hessamx.wordpress.com/wp-admin/"></a></li>
<li><a href="http://www.networkworld.com/weblogs/security/"><font color="#5588aa">security notes</font></a></li>
<li><a href="http://www.modsecurity.org/blog/"><font color="#5588aa">Web Security</font></a></li>
<li><a href="http://blog.ncircle.com/"><font color="#5588aa">the VERT</font></a></li>
<li><a href="http://www.haxorthematrix.com/"><font color="#5588aa">haxorthematrix</font></a></li>
<li><a href="http://securityawareness.blogspot.com/"><font color="#5588aa">security awareness</font></a></li>
<li><a href="http://blog.eweek.com/blogs/larry_seltzer/"><font color="#5588aa">Larry Fseltzer</font></a></li>
<li><a href="http://thurston.halfcat.org/blog/"><font color="#5588aa">Risk Management</font></a></li>
<li><a href="http://identity20.com/"><font color="#5588aa">Identity 2.0</font></a></li>
<li><a href="http://usablesecurity.com/"><font color="#5588aa">usable security</font></a></li>
<li><a href="http://browserfun.blogspot.com/"><font color="#5588aa">Browser Fun</font></a></li>
<li><a href="http://blogs.msdn.com/aaron_margosis/"><font color="#5588aa">Aaron Margosis</font></a></li>
<li><a href="http://infosecpotpourri.blogspot.com/"><font color="#5588aa">infosec potpourri</font></a></li>
<li><a href="http://addxorrol.blogspot.com/"><font color="#5588aa">add xor rol</font></a></li>
<li><a href="http://nzight.blogspot.com/"><font color="#5588aa">nzight</font></a></li>
<li><a href="http://esgblogs.typepad.com/erics_blog/"><font color="#5588aa">Eric Ogren</font></a></li>
<li><a href="http://rationalsecurity.typepad.com/blog/"><font color="#5588aa">Rational Security</font></a></li>
<li><a href="http://yaisb.blogspot.com/"><font color="#5588aa">ryan&#8217;s blog</font></a></li>
<li><a href="http://www.computer.org/portal/site/security"><font color="#5588aa">computer.org sec</font></a></li>
<li><a href="http://www.hexblog.com/"><font color="#5588aa">hexblog</font></a></li>
<li><a href="http://theory.kaos.to/blog/"><font color="#5588aa">kaos.to blog</font></a></li>
<li><a href="http://www.deloitte.com/dtt/section_node/0,1042,sid%3D5863,00.html"><font color="#5588aa">deloitte security</font></a></li>
<li><a href="http://uninformed.org/"><font color="#5588aa">uninformed</font></a></li>
<li><a href="http://hessamx.wordpress.com/wp-admin/"></a></li>
<li><a href="http://thedjbway.org/"><font color="#5588aa">the djb way</font></a></li>
<li><a href="http://www.alw.nih.gov/Security/security-groups.html"><font color="#5588aa">security groups</font></a></li>
<li><a href="http://www.wiretapped.net/"><font color="#5588aa">wiretapped</font></a></li>
<li><a href="http://cve.mitre.org/cve/"><font color="#5588aa">CVE mitre</font></a></li>
<li><a href="http://cve.mitre.org/cce/"><font color="#5588aa">CCE mitre</font></a></li>
<li><a href="http://cwe.mitre.org/"><font color="#5588aa">CWE mitre</font></a></li>
<li><a href="http://www.sans.org/reading_room/"><font color="#5588aa">SANS Reading Room</font></a></li>
<li><a href="http://www.sysinternals.com/Blog/"><font color="#5588aa">Mark sysinternals</font></a></li>
<li><a href="http://blog.simorgh-ev.com">simorgh-ev</a></li>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/hessamx.wordpress.com/98/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/hessamx.wordpress.com/98/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hessamx.wordpress.com/98/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hessamx.wordpress.com/98/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hessamx.wordpress.com/98/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hessamx.wordpress.com/98/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hessamx.wordpress.com/98/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hessamx.wordpress.com/98/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hessamx.wordpress.com/98/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hessamx.wordpress.com/98/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hessamx.wordpress.com/98/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hessamx.wordpress.com/98/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hessamx.wordpress.com/98/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hessamx.wordpress.com/98/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hessamx.wordpress.com/98/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hessamx.wordpress.com/98/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hessamx.wordpress.com&amp;blog=468901&amp;post=98&amp;subd=hessamx&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hessamx.wordpress.com/2007/03/21/security-links/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/ff888dfa073975af6f8183a0a2acd11a?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">hessam</media:title>
		</media:content>
	</item>
		<item>
		<title>Cpanel BruteForce problems</title>
		<link>http://hessamx.wordpress.com/2007/03/21/cpanel-bruteforce-problems/</link>
		<comments>http://hessamx.wordpress.com/2007/03/21/cpanel-bruteforce-problems/#comments</comments>
		<pubDate>Wed, 21 Mar 2007 12:49:29 +0000</pubDate>
		<dc:creator>hessam</dc:creator>
				<category><![CDATA[Other]]></category>

		<guid isPermaLink="false">http://hessamx.wordpress.com/2007/03/21/cpanel-bruteforce-problems/</guid>
		<description><![CDATA[some months ago i coded a perl script. this perl script is a Cpanel BruteForce . some visitors (damn to skidds) mail  me about &#8220;how to use it ?&#8221; or &#8220;how can i found password list for it?&#8221;. this script have not special password list and for example you can use milw0rm password list . and if this [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hessamx.wordpress.com&amp;blog=468901&amp;post=97&amp;subd=hessamx&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>some months ago i<a href="http://http://hessamx.wordpress.com/2006/10/12/cpanel-brute-force-vulnerability/"> coded a perl script</a>. this perl script is a Cpanel BruteForce .<br />
some visitors (damn to skidds) mail  me about &#8220;how to use it ?&#8221; or &#8220;how can i found password list for it?&#8221;.<br />
this script have not special password list and for example you can use<a target="_blank" href="http://milw0rm.com/mil-dic.php"> milw0rm password list</a> . and if this script have low speed use <a target="_blank" href="http://www.simorgh-ev.com/advisory/2006/cpanel-bruteforce-vule/pack-Cpanel-bf-vule.zip">php script</a>. and can other information about usage in script.</p>
<p>[PLEASE DON'T ASK ME ABOUT THIS SCRIPT ]</p>
<p>=====<br />
Site again started with new desing <a href="http://www.hessamx.net/">www.hessamx.net</a></p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/hessamx.wordpress.com/97/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/hessamx.wordpress.com/97/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hessamx.wordpress.com/97/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hessamx.wordpress.com/97/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hessamx.wordpress.com/97/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hessamx.wordpress.com/97/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hessamx.wordpress.com/97/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hessamx.wordpress.com/97/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hessamx.wordpress.com/97/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hessamx.wordpress.com/97/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hessamx.wordpress.com/97/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hessamx.wordpress.com/97/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hessamx.wordpress.com/97/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hessamx.wordpress.com/97/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hessamx.wordpress.com/97/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hessamx.wordpress.com/97/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hessamx.wordpress.com&amp;blog=468901&amp;post=97&amp;subd=hessamx&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hessamx.wordpress.com/2007/03/21/cpanel-bruteforce-problems/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/ff888dfa073975af6f8183a0a2acd11a?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">hessam</media:title>
		</media:content>
	</item>
		<item>
		<title>Exploiting Windows NT 4 Buffer Overruns</title>
		<link>http://hessamx.wordpress.com/2007/03/15/exploiting-windows-nt-4-buffer-overruns/</link>
		<comments>http://hessamx.wordpress.com/2007/03/15/exploiting-windows-nt-4-buffer-overruns/#comments</comments>
		<pubDate>Thu, 15 Mar 2007 07:36:40 +0000</pubDate>
		<dc:creator>hessam</dc:creator>
				<category><![CDATA[Exploiting]]></category>
		<category><![CDATA[Papers]]></category>

		<guid isPermaLink="false">http://hessamx.wordpress.com/2007/03/15/exploiting-windows-nt-4-buffer-overruns/</guid>
		<description><![CDATA[This paper show how to exploiting buffer overruns on windows nt 4. &#8220;This document is for educational purposes only and explains what a buffer overrun is and shows how they can be exploited on the Windows NT 4 operating system using RASMAN.EXE as a case study. We will take a look at Windows NT processes, [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hessamx.wordpress.com&amp;blog=468901&amp;post=96&amp;subd=hessamx&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>This paper show how to exploiting buffer overruns on windows nt 4.<br />
&#8220;<em>This document is for educational purposes only and explains what a<br />
buffer overrun is and shows how they can be exploited on the Windows<br />
NT 4 operating system using RASMAN.EXE as a case study. We will take a<br />
look at Windows NT processes, virtual address space, the dynamics of a<br />
buffer overrun and cover certain key issues such as explaining what a<br />
stack is and what the ESP, EBP and EIP CPU registers are and do. With<br />
these covered we&#8217;ll look into the buffer overrun found in RASMAN.EXE.<br />
This document may be freely copied and distributed only in its<br />
entirety and if credit is given.</em>&#8220;<br />
<a target="_blank" href="http://milw0rm.persiangig.com/ntbuf.txt">View this paper</a> .</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/hessamx.wordpress.com/96/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/hessamx.wordpress.com/96/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hessamx.wordpress.com/96/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hessamx.wordpress.com/96/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hessamx.wordpress.com/96/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hessamx.wordpress.com/96/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hessamx.wordpress.com/96/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hessamx.wordpress.com/96/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hessamx.wordpress.com/96/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hessamx.wordpress.com/96/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hessamx.wordpress.com/96/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hessamx.wordpress.com/96/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hessamx.wordpress.com/96/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hessamx.wordpress.com/96/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hessamx.wordpress.com/96/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hessamx.wordpress.com/96/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hessamx.wordpress.com&amp;blog=468901&amp;post=96&amp;subd=hessamx&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hessamx.wordpress.com/2007/03/15/exploiting-windows-nt-4-buffer-overruns/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/ff888dfa073975af6f8183a0a2acd11a?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">hessam</media:title>
		</media:content>
	</item>
		<item>
		<title>Month of PHP Bugs</title>
		<link>http://hessamx.wordpress.com/2007/03/06/month-of-php-bugs/</link>
		<comments>http://hessamx.wordpress.com/2007/03/06/month-of-php-bugs/#comments</comments>
		<pubDate>Tue, 06 Mar 2007 13:43:31 +0000</pubDate>
		<dc:creator>hessam</dc:creator>
				<category><![CDATA[Other]]></category>

		<guid isPermaLink="false">http://hessamx.wordpress.com/2007/03/06/month-of-php-bugs/</guid>
		<description><![CDATA[ Month of PHP Bugs started and now have 13  advisrories : 1 &#8211; PHP 4 Userland ZVAL Reference Counter Overflow Vulnerability 2 &#8211; PHP Executor Deep Recursion Stack Overflow 3 &#8211; PHP Variable Destructor Deep Recursion Stack Overflow 4 &#8211; PHP 4 unserialize() ZVAL Reference Counter Overflow  5 &#8211; PHP unserialize() 64 bit Array Creation Denial [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hessamx.wordpress.com&amp;blog=468901&amp;post=95&amp;subd=hessamx&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p> <a target="_blank" href="http://www.php-security.org/">Month of PHP Bugs</a> started and now have 13  advisrories :<br />
1 &#8211; <a href="http://www.php-security.org/MOPB/MOPB-01-2007.html">PHP 4 Userland ZVAL Reference Counter Overflow Vulnerability</a><br />
2 &#8211; <a href="http://www.php-security.org/MOPB/MOPB-02-2007.html">PHP Executor Deep Recursion Stack Overflow</a><br />
3 &#8211; <a href="http://www.php-security.org/MOPB/MOPB-03-2007.html">PHP Variable Destructor Deep Recursion Stack Overflow</a><br />
4 &#8211; <a href="http://www.php-security.org/MOPB/MOPB-04-2007.html">PHP 4 unserialize() ZVAL Reference Counter Overflow</a> <br />
5 &#8211; <a href="http://www.php-security.org/MOPB/MOPB-05-2007.html">PHP unserialize() 64 bit Array Creation Denial of Service Vulnerability</a><br />
6 &#8211; <a href="http://www.php-security.org/MOPB/BONUS-06-2007.html">Zend Platform Insecure File Permission Local Root Vulnerability</a><br />
7 &#8211; <a href="http://www.php-security.org/MOPB/BONUS-07-2007.html">Zend Platform ini_modifier Local Root Vulnerability</a><br />
8 &#8211; <a href="http://www.php-security.org/MOPB/MOPB-08-2007.html">PHP 4 phpinfo() XSS Vulnerability (Deja-vu)</a> (!!)<br />
9 &#8211; <a href="http://www.php-security.org/MOPB/MOPB-09-2007.html">PHP wddx_deserialize() String Append Buffer Overflow Vulnerability</a><br />
10 &#8211; <a href="http://www.php-security.org/MOPB/MOPB-10-2007.html">PHP php_binary Session Deserialization Information Leak Vulnerability</a> <br />
11 &#8211; <a href="http://www.php-security.org/MOPB/MOPB-11-2007.html">PHP WDDX Session Deserialization Information Leak Vulnerability</a><br />
12 &#8211; <a href="http://www.php-security.org/MOPB/BONUS-12-2007.html">mod_security POST Rules Bypass Vulnerability</a> <br />
13 &#8211; <a href="http://www.php-security.org/MOPB/MOPB-13-2007.html">PHP 4 Ovrimos Extension Multiple Vulnerabilities</a></p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/hessamx.wordpress.com/95/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/hessamx.wordpress.com/95/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hessamx.wordpress.com/95/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hessamx.wordpress.com/95/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hessamx.wordpress.com/95/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hessamx.wordpress.com/95/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hessamx.wordpress.com/95/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hessamx.wordpress.com/95/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hessamx.wordpress.com/95/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hessamx.wordpress.com/95/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hessamx.wordpress.com/95/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hessamx.wordpress.com/95/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hessamx.wordpress.com/95/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hessamx.wordpress.com/95/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hessamx.wordpress.com/95/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hessamx.wordpress.com/95/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hessamx.wordpress.com&amp;blog=468901&amp;post=95&amp;subd=hessamx&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hessamx.wordpress.com/2007/03/06/month-of-php-bugs/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/ff888dfa073975af6f8183a0a2acd11a?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">hessam</media:title>
		</media:content>
	</item>
		<item>
		<title>malware analysis (Nailuj)</title>
		<link>http://hessamx.wordpress.com/2007/03/04/malware-analysis-nailuj/</link>
		<comments>http://hessamx.wordpress.com/2007/03/04/malware-analysis-nailuj/#comments</comments>
		<pubDate>Sun, 04 Mar 2007 14:02:04 +0000</pubDate>
		<dc:creator>hessam</dc:creator>
				<category><![CDATA[Analysis]]></category>
		<category><![CDATA[malware]]></category>

		<guid isPermaLink="false">http://hessamx.wordpress.com/2007/03/04/malware-analysis-nailuj/</guid>
		<description><![CDATA[again analysis a malware .&#8221;The malware, named Nailuj by some antivirus companies, is composed of 3 files: VideoAti0.exe, VideoAti0.dll and VideoAti0.sys. I won’t talk about all the files, but will focus my attention on only one, the sys file. This malware represents a nice target for those who want to approach a malware for the [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hessamx.wordpress.com&amp;blog=468901&amp;post=94&amp;subd=hessamx&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>again analysis a malware .&#8221;<font size="2"><font face="Verdana, sans-serif">The malware, named <em>Nailuj</em> by some antivirus companies, is composed of 3 files: VideoAti0.exe, VideoAti0.dll and VideoAti0.sys. I won’t talk about all the files, but will focus my attention on only one, the sys file. This malware represents a nice target for those who want to approach a malware for the very first time because it uses well-known techniques, such as hiding files and hooking functions. Nothing hard once you have dealt with them at least once. In addition, the sys file is compiled in debug mode and every operation performed by the malware is documented inside the code. Yes, every time it does something it reveals its success or failure, printing out a comment using DbgPrint function. This is really useful because you know what it will do before starting to analyze the code, not so bad&#8221;<br />
</font></font><font size="2"><font face="Verdana, sans-serif"><span id="more-94"></span></p>
<p></font></font><a target="_blank" href="http://www.box.net/public/static/3q0dhvghdu.pdf">Download This paper in pdf format</a></p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/hessamx.wordpress.com/94/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/hessamx.wordpress.com/94/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hessamx.wordpress.com/94/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hessamx.wordpress.com/94/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hessamx.wordpress.com/94/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hessamx.wordpress.com/94/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hessamx.wordpress.com/94/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hessamx.wordpress.com/94/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hessamx.wordpress.com/94/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hessamx.wordpress.com/94/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hessamx.wordpress.com/94/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hessamx.wordpress.com/94/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hessamx.wordpress.com/94/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hessamx.wordpress.com/94/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hessamx.wordpress.com/94/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hessamx.wordpress.com/94/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hessamx.wordpress.com&amp;blog=468901&amp;post=94&amp;subd=hessamx&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hessamx.wordpress.com/2007/03/04/malware-analysis-nailuj/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/ff888dfa073975af6f8183a0a2acd11a?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">hessam</media:title>
		</media:content>
	</item>
		<item>
		<title>Analysis of the worm &#8220;Tibick.D&#8221;</title>
		<link>http://hessamx.wordpress.com/2007/02/23/analysis-of-the-worm-tibickd/</link>
		<comments>http://hessamx.wordpress.com/2007/02/23/analysis-of-the-worm-tibickd/#comments</comments>
		<pubDate>Fri, 23 Feb 2007 17:40:07 +0000</pubDate>
		<dc:creator>hessam</dc:creator>
				<category><![CDATA[Analysis]]></category>
		<category><![CDATA[malware]]></category>

		<guid isPermaLink="false">http://hessamx.wordpress.com/2007/02/23/analysis-of-the-worm-tibickd/</guid>
		<description><![CDATA[The aim of this article is to give an introduction to the field of malware analysis. The worm dissected later in this article is neither new nor unknown and has been analyzed already. A very simple and primitive worm has been chosen to make this article most understandable especially to those who never reversed a [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hessamx.wordpress.com&amp;blog=468901&amp;post=93&amp;subd=hessamx&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>The aim of this article is to give an introduction to the field of malware analysis. The worm dissected later in this article is neither new nor unknown and has been analyzed already. A very simple and primitive worm has been chosen to make this article most understandable especially to those who never reversed a worm before or are (relatively) new to reverse engineering.<br />
This article might be not very interesting for advanced (malware-)reversers.<br />
<span id="more-93"></span><a target="_blank" href="http://lesco.le.funpic.de/files/articles/rev_malware1/tibick.d.html">view this paper (HTML format)</a></p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/hessamx.wordpress.com/93/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/hessamx.wordpress.com/93/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hessamx.wordpress.com/93/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hessamx.wordpress.com/93/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hessamx.wordpress.com/93/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hessamx.wordpress.com/93/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hessamx.wordpress.com/93/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hessamx.wordpress.com/93/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hessamx.wordpress.com/93/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hessamx.wordpress.com/93/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hessamx.wordpress.com/93/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hessamx.wordpress.com/93/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hessamx.wordpress.com/93/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hessamx.wordpress.com/93/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hessamx.wordpress.com/93/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hessamx.wordpress.com/93/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hessamx.wordpress.com&amp;blog=468901&amp;post=93&amp;subd=hessamx&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hessamx.wordpress.com/2007/02/23/analysis-of-the-worm-tibickd/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/ff888dfa073975af6f8183a0a2acd11a?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">hessam</media:title>
		</media:content>
	</item>
	</channel>
</rss>
