<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Inspirated &#187; Security</title>
	<atom:link href="http://inspirated.com/tag/security/feed" rel="self" type="application/rss+xml" />
	<link>http://inspirated.com</link>
	<description>krkhan&#039;s blog</description>
	<lastBuildDate>Mon, 02 Jan 2012 20:58:28 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>GoDaddy/WordPress ninoplas Base64 virus and the fix</title>
		<link>http://inspirated.com/2010/03/02/wordpress-ninoplas-virus-and-the-fix</link>
		<comments>http://inspirated.com/2010/03/02/wordpress-ninoplas-virus-and-the-fix#comments</comments>
		<pubDate>Tue, 02 Mar 2010 14:40:53 +0000</pubDate>
		<dc:creator>krkhan</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[BASH]]></category>
		<category><![CDATA[Fix]]></category>
		<category><![CDATA[GoDaddy]]></category>
		<category><![CDATA[Rants]]></category>
		<category><![CDATA[Script]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[WordPress]]></category>

		<guid isPermaLink="false">http://inspirated.com/?p=268</guid>
		<description><![CDATA[Update: The virus seems to have affected only GoDaddy websites, hence the change in title. Few hours ago I opened my website and noticed some rather strange Javascript hanging around the bottom. After some inspection, it became evident that every page on my blog was trying to load an IFrame to some place called ninoplas.com. [...]]]></description>
			<content:encoded><![CDATA[<!-- Start Shareaholic LikeButtonSetTop Automatic --><!-- End Shareaholic LikeButtonSetTop Automatic --><p><ins datetime="2010-03-03T16:24:34+00:00">Update: The virus seems to have affected only GoDaddy websites, hence the change in title.</ins></p>
<p>Few hours ago I opened my website and noticed some rather strange Javascript hanging around the bottom. After some inspection, it became evident that <em>every</em> page on my blog was trying to load an IFrame to some place called <code>ninoplas.com</code>. Turns out, I wasn&#8217;t alone and there are <a href="http://wordpress.org/support/topic/370546">other users</a> as well who are affected by this. Judging by the fact that different blogs were attacked at the same time, this was in all probability the result of a security hole in some plugin or the core itself.</p>
<p>The virus acted by adding a piece of encrypted code on the first line of <em>all</em> PHP files on the server. It&#8217;s rather unsettling to consider the extend of damage that could have been caused with the write access to those files. Still, the damage could be rectified by simply deleting those lines. I wrote a tiny script for doing this job which cleans the ninoplas virus from all the PHP files in the current directory:</p>
<p style="text-align: center"><a href="http://inspirated.com/uploads/clean-ninoplas.sh">clean-ninoplas.sh</a></p>
<p style="text-align: center; font-size: x-small">Warning: While this script has worked for me, I am in <strong>no</strong> way providing any guarantee for how it behaves on other blogs. Backup your blog as well as database before executing this script.<br />
<strong>You have been warned.</strong></p>
<p>Using the fix is a simple matter of:</p>

<div class="wp_syntax"><div class="code"><pre class="bash" style="font-family:monospace;">-bash-$ <span style="color: #7a0874; font-weight: bold;">cd</span> wordpress
-bash-$ <span style="color: #c20cb9; font-weight: bold;">wget</span> http:<span style="color: #000000; font-weight: bold;">//</span>inspirated.com<span style="color: #000000; font-weight: bold;">/</span>uploads<span style="color: #000000; font-weight: bold;">/</span>clean-ninoplas.sh
-bash-$ <span style="color: #c20cb9; font-weight: bold;">sh</span> clean-ninoplas.sh</pre></div></div>

<p>And don&#8217;t forget to backup everything again after cleaning up. The security hole &#8212; if there is one &#8212; has still not been tracked and if it&#8217;s in the core or some plugin which you&#8217;re still using, the virus might not be so benevolent next time.</p>
<div class="shr-publisher-268"></div><!-- Start Shareaholic LikeButtonSetBottom Automatic --><!-- End Shareaholic LikeButtonSetBottom Automatic --><hr />
<p><small><a href="http://inspirated.com/2010/03/02/wordpress-ninoplas-virus-and-the-fix">Permalink</a> |
<a href="http://inspirated.com/2010/03/02/wordpress-ninoplas-virus-and-the-fix#comments">69 comments</a>
<br/>
Post tags: <a href="http://inspirated.com/tag/bash" rel="tag">BASH</a>, <a href="http://inspirated.com/tag/fix" rel="tag">Fix</a>, <a href="http://inspirated.com/tag/godaddy" rel="tag">GoDaddy</a>, <a href="http://inspirated.com/tag/rants" rel="tag">Rants</a>, <a href="http://inspirated.com/tag/script" rel="tag">Script</a>, <a href="http://inspirated.com/tag/security" rel="tag">Security</a>, <a href="http://inspirated.com/tag/virus" rel="tag">Virus</a>, <a href="http://inspirated.com/tag/wordpress" rel="tag">WordPress</a><br/>
</small></p>]]></content:encoded>
			<wfw:commentRss>http://inspirated.com/2010/03/02/wordpress-ninoplas-virus-and-the-fix/feed</wfw:commentRss>
		<slash:comments>69</slash:comments>
		</item>
		<item>
		<title>Next Generation Intelligent Networks Research Center</title>
		<link>http://inspirated.com/2008/11/29/next-generation-intelligent-networks-research-center</link>
		<comments>http://inspirated.com/2008/11/29/next-generation-intelligent-networks-research-center#comments</comments>
		<pubDate>Sat, 29 Nov 2008 14:27:35 +0000</pubDate>
		<dc:creator>krkhan</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Kernel]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[nexGIN RC]]></category>
		<category><![CDATA[Rants]]></category>
		<category><![CDATA[Research]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>

		<guid isPermaLink="false">http://www.inspirated.com/wordpress/?p=170</guid>
		<description><![CDATA[&#8220;Research is what I&#8217;m doing when I don&#8217;t know what I&#8217;m doing.&#8221; &#8212; Wernher von Braun As soon as the next semester rolls over, I will be joining nexGIN RC as a research student. My task will be to participate in developmental efforts on the National ICT R&#038;D funded project &#8220;An Intelligent Secure Kernel for [...]]]></description>
			<content:encoded><![CDATA[<!-- Start Shareaholic LikeButtonSetTop Automatic --><!-- End Shareaholic LikeButtonSetTop Automatic --><blockquote><p>&#8220;Research is what I&#8217;m doing when I don&#8217;t know what I&#8217;m doing.&#8221; &#8212; <em>Wernher von Braun</em></p></blockquote>
<p>As soon as the next semester rolls over, I will be joining <a href="http://nexginrc.org/">nexGIN RC</a> as a research student. My task will be to participate in developmental efforts on the National <abbr title="Information and Communication Technology">ICT</abbr> <abbr title="Research and Development">R&#038;D</abbr> funded project <a href="http://www.ictrdf.org.pk/fp-isk.htm">&#8220;An Intelligent Secure Kernel for Next Generation Mobile Computing Devices&#8221;</a>. Here&#8217;s an excerpt from the project&#8217;s executive summary:</p>
<blockquote><p>The project aims to develop secure kernel framework that enable self-monitoring, and consequently self-healing operation for an operating system of mobile devices. This is expected to produce a fully functional Secure Linux Kernel that will be run on tablet PCs / smartphones. The developed framework will be fully aware of system conditions and resource usage and will schedule different threads intelligently based on each thread/process&rsquo; behavior, thus providing a truly secure computing experience in which malware that manages to escape detection by intrusion detection systems gets thwarted in the scheduler.</p></blockquote>
<p>From the looks of it, there will be substantial poking around Linux involved in this one. So even though my research area primarily revolved around back-heeled through balls, spoon-chip goals, splendid crosses, powerful curlers, Totti, De Rossi, Batistuta, Montella, Ibrahimovic and Cruyff until now, I&#8217;ll be trying to redirect the efforts towards kernel development. What could possibly be more fun? Oh yes, watching Roma top the Champions League Group A ahead of Chelsea, but digressing that much isn&#8217;t suitable for a single post <img src='http://inspirated.com/wordpress/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' />  .</p>
<div class="shr-publisher-170"></div><!-- Start Shareaholic LikeButtonSetBottom Automatic --><!-- End Shareaholic LikeButtonSetBottom Automatic --><hr />
<p><small><a href="http://inspirated.com/2008/11/29/next-generation-intelligent-networks-research-center">Permalink</a> |
<a href="http://inspirated.com/2008/11/29/next-generation-intelligent-networks-research-center#comments">One comment</a>
<br/>
Post tags: <a href="http://inspirated.com/tag/kernel" rel="tag">Kernel</a>, <a href="http://inspirated.com/tag/linux" rel="tag">Linux</a>, <a href="http://inspirated.com/tag/nexgin-rc" rel="tag">nexGIN RC</a>, <a href="http://inspirated.com/tag/rants" rel="tag">Rants</a>, <a href="http://inspirated.com/tag/research" rel="tag">Research</a>, <a href="http://inspirated.com/tag/security" rel="tag">Security</a>, <a href="http://inspirated.com/tag/technology" rel="tag">Technology</a><br/>
</small></p>]]></content:encoded>
			<wfw:commentRss>http://inspirated.com/2008/11/29/next-generation-intelligent-networks-research-center/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>The (possible) Indian WiFi crackdown</title>
		<link>http://inspirated.com/2008/09/17/the-possible-indian-wifi-crackdown</link>
		<comments>http://inspirated.com/2008/09/17/the-possible-indian-wifi-crackdown#comments</comments>
		<pubDate>Wed, 17 Sep 2008 17:47:55 +0000</pubDate>
		<dc:creator>krkhan</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[India]]></category>
		<category><![CDATA[Law]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Stupid]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Terrorism]]></category>
		<category><![CDATA[WiFi]]></category>

		<guid isPermaLink="false">http://www.inspirated.com/wordpress/?p=164</guid>
		<description><![CDATA[The blasts go off, the government comes under pressure, and going by the books, they pull out an egregiously absurd law out of their asses: They inculpate WiFi hotspots, as one of them was used by the terrorists to send an email. &#8220;We cannot blame anyone if we forget to lock our own rooms. The [...]]]></description>
			<content:encoded><![CDATA[<!-- Start Shareaholic LikeButtonSetTop Automatic --><!-- End Shareaholic LikeButtonSetTop Automatic --><p>The <a href="http://en.wikipedia.org/wiki/2008_New_Delhi_bombings">blasts go off</a>, the government comes under pressure, and going by the books, they pull out an egregiously absurd law out of their asses: They <a href="http://www.hindu.com/thehindu/holnus/001200809161616.htm">inculpate WiFi hotspots</a>, as one of them was used by the terrorists to send an email.</p>
<blockquote><p>&#8220;We cannot blame anyone if we forget to lock our own rooms. The ISPs should provide all these features of password and password protection,&#8221; said <del datetime="2008-09-17T17:45:26+00:00">a Ministry of Communication and Information Technology Indian Computer Emergency Response Team (CERTC-in) senior official</del> an incompetent dork. </p></blockquote>
<p>First of all, I do <strong>not</strong> sympathize with terrorists&#8217; motives because of Indians getting targeted (as distasteful as that sounds, some people did suggest it when I argued with them about WiFi-blaming being ridiculous). With that said, I find it hard to believe that clamping down on hotspot security is going to reduce the level of terrorist threats. The Indian government shall have to outlaw real life mailboxes, phone-calls and anonymity all together as well as install GPS-trackers on every Indian resident for an approach like this to work. On the other hand, exploiting public fear by labeling inane regulations as being Anti-Terrorist is much more convenient than implementing adept law enforcing, don&#8217;t you think so?</p>
<div class="shr-publisher-164"></div><!-- Start Shareaholic LikeButtonSetBottom Automatic --><!-- End Shareaholic LikeButtonSetBottom Automatic --><hr />
<p><small><a href="http://inspirated.com/2008/09/17/the-possible-indian-wifi-crackdown">Permalink</a> |
<a href="http://inspirated.com/2008/09/17/the-possible-indian-wifi-crackdown#comments">No comment</a>
<br/>
Post tags: <a href="http://inspirated.com/tag/india" rel="tag">India</a>, <a href="http://inspirated.com/tag/law" rel="tag">Law</a>, <a href="http://inspirated.com/tag/security" rel="tag">Security</a>, <a href="http://inspirated.com/tag/stupid" rel="tag">Stupid</a>, <a href="http://inspirated.com/tag/technology" rel="tag">Technology</a>, <a href="http://inspirated.com/tag/terrorism" rel="tag">Terrorism</a>, <a href="http://inspirated.com/tag/wifi" rel="tag">WiFi</a><br/>
</small></p>]]></content:encoded>
			<wfw:commentRss>http://inspirated.com/2008/09/17/the-possible-indian-wifi-crackdown/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

<!-- Dynamic Page Served (once) in 0.421 seconds -->

