<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-6281858739286835733</id><updated>2012-02-17T14:19:38.465-08:00</updated><category term='Dunamic cryptographic trapdoors'/><category term='Python'/><category term='Honeynet'/><category term='cyberwarfare'/><category term='Malware'/><category term='iAWACS'/><category term='cyber attack'/><category term='Androguard'/><category term='Diffing'/><category term='TOR Attack'/><category term='Similarity'/><category term='Android'/><category term='Java'/><category term='DroidDream'/><category term='Perseus'/><category term='Skype'/><title type='text'>Operational cryptology and virology lab</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://cvo-lab.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://cvo-lab.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Eric Filiol</name><uri>http://www.blogger.com/profile/04835548005201063894</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/-X0IVCfnSjNo/TrmrvRiBBaI/AAAAAAAAADY/5fPBjidBQfk/s220/shadow_runner.jpeg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>43</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-6281858739286835733.post-1719653512591972244</id><published>2011-11-05T10:46:00.000-07:00</published><updated>2011-11-06T01:24:26.640-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Dunamic cryptographic trapdoors'/><category scheme='http://www.blogger.com/atom/ns#' term='TOR Attack'/><category scheme='http://www.blogger.com/atom/ns#' term='cyberwarfare'/><title type='text'>Let us stop with the buzz on TOR</title><content type='html'>&lt;div style="text-align: justify;"&gt;Hi to all&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Since a few weeks a huge buzz has arised around the TOR security and especially regarding the attack we have designed and experimented. I decided not to react, not to feed the buzz since I do not like it and if controversy may sometimes be constructive, in the present case, things have gone too far: stupid comments on comments from others (on which basis since we have published only a very few things yet?),  personal attacks close sometimes to libelling, huge emotions, doubts and fear that may be understood however, collective hysteria...&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;However, going on sticking away would in some sense backing this buzz. It is time to remind that the only possible goal is to have more security, to determine whether really our attack can put seriously TOR security into question and go ahead to try to find solutions to improve. Security is a too serious thing to be only a playground for buzz. Even if -- especially as a former military cryptanalyst -- I do not fully agree on a few conceptual choices in TOR, there must be no doubt for anyone about our will to contribute to the TOR security and this from the very beginning. We must not forget that a few people who use TOR are putting sometimes their life into danger (political opponents, militaries...) for a more democratic and free society. In this respect, we cannot waste a precious time. Up to me, the issue is very clear:  there is absolutely no doubt that we need a solution like TOR even this solution is far from being perfect. But is there such a thing as a perfect solution, especially if you add political and national security issues?&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;When I decided to work on TOR -- by mid of 2010 -- I was just interested in the crypto part, looking for some application of the concept of dynamic cryptographic trapdoor that I had imagined a few years ago. So far I could test it only in non public yet real networks. Hence it was not possible to publish anything on those results. So at the beginning, I had nothing against TOR and I still don't.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;When it was clear that TOR could also succumbed to this concept, I imagined the attack under the present light of media. If I have a rather good knowledge of network technology, it was not sufficient and I needed to have more skilled guys, especially to find ways to force 3-node routes through compromised nodes with a very high probability. Two of my best  students of our &lt;a href="https://sites.google.com/site/esieanismaster/"&gt;N&amp;amp;IS Specialised master&lt;/a&gt;, Seun from Nigeria and Leonard from Tanzania -- two really excellent students -- have joined the party on April 2011. They have worked very hard, have done an excellent job both at the academic level and at the operational/technical level. I can say that as a tutor, I am really proud of their work. Of course, for  anyone who knows how research works, you never totally start from scratch and Seun and Leonard's first tasks were to establish a bibliography on the existing network approaches used by previous researchers: Murdoch, Evans, Danezis, Pappas, Bendiken... who all have been mentioned in the slides. Then they have developped their own tools/approaches to fit my operational intent. Just as it is required in any research work. And other people doing hacking or research are doing the same.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;We have just done research, serious, good and operational research up to me. We have tested our attack in conditions close to the reality. People will make their own ideas. I decided at that time not to make buzz, just to present this work in hacking conferences. Unfortunately my employer -- an academic institution -- has required from me to present my attack to French journalists. I have accepted since an employer is always right...or you have to resign. But at  the very end, I did not really mind: who cares about news published in French in the world? Then things went wrong and the hype created by others has gone too far. The TOR foundation contacted me in a form that was probably not very fair -- to my perception  at last -- and myself I have to make a throrough criticism of myself when facing the resulting buzz. After 22 years in the Army (in the French Marine Corps Infantry), I suppose that I have kept a not very flexible and accomodating mind. Sorry for that.  We have decided that it was necessary to restore the contact with the TOR foundation and its president Roger Dingledine to go beyond our differences in opinions, views and interpretations and go ahead towards more security in TOR in a more constructive way.  Any other end would have been totally irresponsible from Seun and me. &lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Our attack works not because the TOR source code has flaws. Once again, it is well-written and in a secure way. It is more related to conceptual issues. We have just analyzed the TOR network at a higher level, by considering it as a critical infrastructure and using a large, multi-level and coordinated attacks. Up to me according to personal information, which are confirmed partly on the TOR website, I am convinced that China (especially in 2009 and late 2010) has already tried similar attacks and has been, at least partly successful. Of course we cannot accept that.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;The main problem comes from the fact that &lt;/div&gt;&lt;div&gt;&lt;ol&gt;&lt;li style="text-align: justify;"&gt;the TOR network relies on volunteers which most of the time do not secure their computers. That is dramatic. Just imagine the security nightmare in a big company where every user would be free to choose the operationg system, the way to configure it... We will not publish all what we have detected. But be sure that we have seen horrible things as far as security is concerned. In this respect, we think that an overall computer security policy should be enforced and any OR not complying with it should be banned from the network.&lt;/li&gt;&lt;li style="text-align: justify;"&gt;TCP is a nightmare as well and this is the main issue. I am not a network expert  but I have the feeling that it will difficult to built more security at that level. We have managed to return a few of the TOR protections against DDoS against TOR itself when considering local, surgical strikes.&lt;/li&gt;&lt;/ol&gt;&lt;div style="text-align: justify;"&gt;But to be honest, being able to force 3-node circuits can be exploited only if there exists a significant part of ORs that have been compromised. So back to the first point.&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Up to me there is some hope and technical improvements should be possible. Among many possible ideas. we propose:&lt;/div&gt;&lt;div&gt;&lt;ul&gt;&lt;li style="text-align: justify;"&gt;as an emergency measure, to ban weak ORs that are not secure enough. This requires to make fingerprinting and active auditing what we did actually but only partly for legal reasons.&lt;/li&gt;&lt;li style="text-align: justify;"&gt;to add steganography techniques in TOR. Remember that using cryptography focuses attention and hence attacks. Why not a steganographic version of TOR?&lt;/li&gt;&lt;li style="text-align: justify;"&gt;to limit not so say prevent the installation of dynamic cryptographic backdoors (memory protection by hardware-based virtualization for instance, malicious cryptography techniques to prevent memory tampering, process protection techniques [we have developped a few in our lab]...).&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Seun intends to dedicate his PhD thesis to the enhancement of the TOR security with innovative propositions. He is just waiting for a PhD grant. We are ready to contribute and to be involved anyway.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;We have sent all source code and slides to the TOR foundation in order to help it to design and release a potentially more secure version of TOR. Recent exchanges with Roger seem to show that somehow our work is considered as significant and was not greatly exaggerated. That is sufficient to us.  I let him confirm or not. We will release the source code and data as scheduled on November 10th (right after PacSec 2011) unless the TOR foundation recommends to wait a little bit more. As researchers and hackers we just need our contribution to be recognized. If it has helped finally to take part to the enhancement of overall TOR security, well we will proud of that.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Special thanks to Dragos, Rodrigo and Filipe.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Eric Filiol &amp;amp; Oluwaseun REMI-OMOSOWON&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6281858739286835733-1719653512591972244?l=cvo-lab.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/1719653512591972244'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/1719653512591972244'/><link rel='alternate' type='text/html' href='http://cvo-lab.blogspot.com/2011/11/let-us-stop-with-buzz-on-tor.html' title='Let us stop with the buzz on TOR'/><author><name>Eric Filiol</name><uri>http://www.blogger.com/profile/04835548005201063894</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/-X0IVCfnSjNo/TrmrvRiBBaI/AAAAAAAAADY/5fPBjidBQfk/s220/shadow_runner.jpeg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6281858739286835733.post-8645250765232865376</id><published>2011-11-01T01:42:00.000-07:00</published><updated>2011-12-29T09:59:52.533-08:00</updated><title type='text'>TOR Attack Technical Details</title><content type='html'>Hi to all&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;As announced in a &lt;a href="http://cvo-lab.blogspot.com/2011/10/first-feedbacks-from-h2hc-and-our-tor.html"&gt;previous one&lt;/a&gt;, this post presents and details the different technical details on our TOR attack. These data will be released little by little but everything should be finally available before the end of November. So stay tuned to follow regular additions to this post.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;We do prefer take time and release the most recent developments with respect to the TOR foundation updates, patches... But we also understand that people are looking forward to have those technical details. Since some of them are ready and since making them public does not challenge the interests of H2HC2011/PacSec 2011 organizers, well why wait more?&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;An updated version of the attack (to adapt to the forthcoming updates and patches of the TOR code in November and December and to present the TOR security evaluation dedicated botnet we are currently developping) will be presented at the 28th Chaos Communication Congress (28C3) in Berlin.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Here are the data provided:&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;ul&gt;&lt;li&gt;The Google Earth maps of existing ORs (public and hidden ones; &lt;a href="https://docs.google.com/leaf?id=0B6BlkqAoxXq1YzRhMjRlMzMtZWY0Mi00MzliLWE0NzgtYTZlMDBhM2UwYTg0&amp;amp;hl=en_US"&gt;allOS ORs&lt;/a&gt; and &lt;a href="https://docs.google.com/leaf?id=0B6BlkqAoxXq1M2ZhYzdkOGYtM2ZhZC00ZjdkLWJhNjItMDFkMGI5YWZlZWJk&amp;amp;hl=en_US"&gt;Windows ORs&lt;/a&gt;) at the date of November 1st, 2011. Hidden TOR relay bridges (195 extracted by now; text list &lt;a href="https://docs.google.com/leaf?id=0B6BlkqAoxXq1ZjI3YWU3ZDMtNjAzZi00N2JkLTk4ODYtZTE1M2VhZDRjMWE1&amp;amp;hl=en_US"&gt;here&lt;/a&gt;) have been automatically extracted with the &lt;i&gt;tor_brige library&lt;/i&gt; provided hereafter. This map is essentiel and is part of the &lt;i&gt;intelligence step&lt;/i&gt; of the attack. Building large, coordinated, multilevel attacks -- as militaries usually do -- requires to have this generalized view of the target. New maps at the date of November 10th, 2011 (310 hidden relay bridges extracted so far): &lt;a href="https://docs.google.com/uc?id=0B6BlkqAoxXq1YTkwNjk3NTItMWY0Ni00ZTExLTgzZTYtZWIzYjZlNzg3Njcx&amp;amp;export=download&amp;amp;hl=en_US"&gt;all ORS&lt;/a&gt; and &lt;a href="https://docs.google.com/uc?id=0B6BlkqAoxXq1NzM3Nzg0ZDUtNjA1Zi00MDQ2LWIzYjMtODlmN2NiMGI1YWU4&amp;amp;export=download&amp;amp;hl=en_US"&gt;Windows ORs.&lt;/a&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;The &lt;i&gt;&lt;a href="https://docs.google.com/leaf?id=0B6BlkqAoxXq1ZjAxYmI2MTYtOGI4NS00NTcyLTlhOWItNTczZTFkMTU3NmI5&amp;amp;hl=en_US"&gt;tor_extend library&lt;/a&gt;&lt;/i&gt; which enables (1) to automate the extraction of hidden TOR nodes (relay bridges) and (2) to execute the spinning technique (second of the 3 combined techniques to force 3-node routes towards compromised nodes). This library has been written by Oluwaseun Remi-Omowoson. The library can also be accessed through the Rubyforge&lt;a href="http://rubyforge.org/projects/tor-extend/"&gt; &lt;/a&gt;&lt;a href="http://rubyforge.org/projects/tor-extend/"&gt;link&lt;/a&gt; and Rubygem &lt;a href="https://rubygems.org/gems/tor_extend"&gt;link&lt;/a&gt; (relevant documentation &lt;a href="http://tor-extend.rubyforge.org/"&gt;here&lt;/a&gt;). Simply typeset "&lt;span style="font-style: italic;"&gt;gem install tor-extend&lt;/span&gt;" to install.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;H2HC 2011/Pacsec 2011 &lt;a href="https://docs.google.com/viewer?a=v&amp;amp;pid=explorer&amp;amp;chrome=true&amp;amp;srcid=0B6BlkqAoxXq1ZTRjZWYwMTgtZmUzZi00YWJjLWI4ZjMtY2IwYWUyYmE1YTk2&amp;amp;hl=en_US"&gt;slides&lt;/a&gt;.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;PacSec &lt;a href="http://www.youtube.com/watch?v=7We3aRb0tSg"&gt;video&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;Technical paper which also contains the SCAPY script code to play the &lt;i&gt;TCP Reset technique&lt;/i&gt; (first of the 3 techniques combined to force 3-node routes towards compromised nodes). Available by end of January 2012.&lt;/li&gt;&lt;li&gt;The &lt;a href="https://docs.google.com/viewer?a=v&amp;amp;pid=explorer&amp;amp;chrome=true&amp;amp;srcid=0B6BlkqAoxXq1ZTBiNzNiNzktMzNhMi00YmFjLTgyZWQtYTJlM2IyNWE2Nzdk&amp;amp;hl=en_US"&gt;tor_extend library version 2.0.0&lt;/a&gt; (28C3 version). Contains everything in a single file (source code, documentation, ruby code, Google Earth map of ORs including 355 hidden relays extracted so far...). 28C3 &lt;a href="https://docs.google.com/viewer?a=v&amp;amp;pid=explorer&amp;amp;chrome=true&amp;amp;srcid=0B6BlkqAoxXq1ZjliYWZkMGYtNGQ1NC00NGU5LWJlMjctMGIzMDBlOTRkZWEy&amp;amp;hl=en_US"&gt;slides&lt;/a&gt;. &lt;span style="font-weight: bold;"&gt;These data will be the last public version available&lt;/span&gt;. Very important point following feedbacks and comments from Roger Dingledine (thanks Roger!): in our slides we focus on Windows ORs/relays without correlating to bandwidth. This was just a choice among many other possible. Optimally it is true that we have to target/infect primarily the nodes with high bandwidth. And following this dicussion it is clear that many other options are possible. So, up to the choice of the target subset to infect, the general concept/approach of our attack remains valid.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;The malware part (installing the dynamic cryptographic trapdoor) is not public. The malware also embeds a few structures to contribute to forcing 3-route nodes (refer to the paper).&lt;/li&gt;&lt;/ul&gt;Please note that the source code provided (when relevant) is the PoC version only (not optimized). Optimized versions are not public (since they are part of the TOR security evaluation botnet which is currently developped).&lt;br /&gt;&lt;br /&gt;To conclude, we would like to stress on the fact that TOR is not only solution available (just to counter stupid comments claiming that without TOR the security world would be empty). We recommand the excellent book (free) "&lt;a href="http://en.flossmanuals.net/_booki/bypassing-censorship/bypassing-censorship.pdf"&gt;How to bypass Internet censorship&lt;/a&gt;" which describes various tools which are worth mentioning and considering.&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;E.F.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6281858739286835733-8645250765232865376?l=cvo-lab.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/8645250765232865376'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/8645250765232865376'/><link rel='alternate' type='text/html' href='http://cvo-lab.blogspot.com/2011/11/tor-attack-technical-details.html' title='TOR Attack Technical Details'/><author><name>Eric Filiol</name><uri>http://www.blogger.com/profile/04835548005201063894</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/-X0IVCfnSjNo/TrmrvRiBBaI/AAAAAAAAADY/5fPBjidBQfk/s220/shadow_runner.jpeg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6281858739286835733.post-6059620336541090027</id><published>2011-10-30T04:04:00.000-07:00</published><updated>2011-11-02T00:35:04.624-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Dunamic cryptographic trapdoors'/><category scheme='http://www.blogger.com/atom/ns#' term='cyber attack'/><category scheme='http://www.blogger.com/atom/ns#' term='TOR Attack'/><category scheme='http://www.blogger.com/atom/ns#' term='cyberwarfare'/><title type='text'>First Feedbacks from H2HC and our TOR Attack</title><content type='html'>Hi to all&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;The talk given at H2HC 2011 in Sao Paulo has caused a lot of reactions and interests in our work (especially this night from a TOR developper whose mail was far more constructive and positive than previous ones). It is probably time to go ahead the recent stupid buzz and reactions. To put things into perspective, people must know that we did choose to enter this buzz and wait until our talk and that forthcoming in PacSec 2011. We expect to be more constructive in this way.&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;We perfectly understand the concerns of the TOR community. Be sure that contrary to stupid  allegations it is not our intent not to contribute for more security in  TOR (but honestly first emails from the TOR foundation were more on strong requirement mode -- not to say intimidation --  than with a real collaboration spirit ensuring the interests of conferences  organizers). We are not easy men and we do like everything close to intimidation. And we do not like useless buzz.&lt;br /&gt;&lt;br /&gt;People first must know and be convinced that we do not have anything against  TOR. This network is just the only real &lt;span style="font-weight: bold;"&gt;public&lt;/span&gt; case on which we can test  the concept of dynamic trapdoors and publish something with the expectation to be useful and constructive at the very final end.&lt;br /&gt;&lt;br /&gt;As far as vulnerabilities are concerned -- TOR community is concerned with potential bugs --, in fact we cannot speak of  sotware vulnerabilities. The TOR code is rather very well and securely  written. Our attack relates more to the conceptual designs and of the exploitation of different aspects on which those designs rely on. We worked at a higher level  by considering the TOR network as a critical infrastructure and we have developped operational cyberwarfare scenarios (these approaches are part of the research topics our our lab). to take the control over TOR as would do rogue non-democratic countries , terrorists or  reduced sized groups of bad guys.&lt;br /&gt;&lt;br /&gt;We manage to force 3-node circuits  to go through a few nodes -- with  very high probability -- we have compromised in an initial step with malware using malicious cryptography techniques installing dynamic cryptographic backdoors. To do that, most of the time we just turn protection  mechanisms in place (for instance to prevent large DDoS) back against  TOR itself. The TCP reset attack cannot be avoided since it exploit a part of  the TCP implementation. Most the techniques we used (local and targeted  congestion path, spinning technique ou TCP reset) cannot really be  avoided. It is a problem of conceptual design both for TOR but also for the protocols it relies on (mostly TCP). It is a common approach in cyberattacks to turn protections set up by the target... against the target! Awful indeed but really efficient.&lt;br /&gt;&lt;br /&gt;So we do not want to criticize TOR uselessly since the problem is not TOR in itself only. This network is a first solution intending to provide some sort of secure environment that must be followed by other generation of OR or other similar solutions. But since we now are very convinced that it is effectively possible to take control over TOR when working both a low and high level at the same time (this is the reason why we needed to have a precise and complete map of all the OR even the hidden ones; and we manage to find all hidden nodes, China or any other bad guys are able to do it as well). Nowadays hacking techniques and methods still have only a limited and reduced view (instance of binaries or of systems) but they did not apply  yet what military world is using: large, high level views to organize, plan and conduct coordinated attacks, combining several technical bricks and tools.&lt;br /&gt;&lt;br /&gt;So, we are currently preparing all stuff (source code , paper, slides) and as  soon as they are ready we will  send them to the TOR foundation and make them publicly available. We already made suggestions to a few TOR developpers. Seun is currently working to adapt the attack to the recent update (that corrects partly the spinning technique). He is very confident at succeeding in this.&lt;br /&gt;&lt;br /&gt;Seun should prepare a Phd and we intend to  provide new approaches to enable and propose some sort of third generation of TOR that  would contribute to solve the present conceptual problems. Part of the solution would  be to use steganography to provide TRANSEC aspects. But we should also propose to protect the code loaded in memory to limit the techniques of dynamic  cryptographic trapdoors. And we have many other ideas coming from malicious cryptography techniques we have recently developped.&lt;br /&gt;&lt;br /&gt;Once again, the very final goal of our work is to provide a better  solution at the end. That is why we did not want to enter the buzz and stay aside to  go on working&lt;br /&gt;We hope that people will understand&lt;br /&gt;&lt;br /&gt;To finish I would like to thank people at H2HC (Rodrigo, Filipe and all the very nice guys I have met) as well people from PacSec (Dragos and his team) for their confidence and trust. We owe very much to them&lt;br /&gt;&lt;br /&gt;Have a nice (hacking) day to all&lt;br /&gt;&lt;br /&gt;E.F.&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6281858739286835733-6059620336541090027?l=cvo-lab.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/6059620336541090027'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/6059620336541090027'/><link rel='alternate' type='text/html' href='http://cvo-lab.blogspot.com/2011/10/first-feedbacks-from-h2hc-and-our-tor.html' title='First Feedbacks from H2HC and our TOR Attack'/><author><name>Eric Filiol</name><uri>http://www.blogger.com/profile/04835548005201063894</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/-X0IVCfnSjNo/TrmrvRiBBaI/AAAAAAAAADY/5fPBjidBQfk/s220/shadow_runner.jpeg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6281858739286835733.post-1573884055888346920</id><published>2011-10-17T05:17:00.000-07:00</published><updated>2011-10-17T05:46:08.566-07:00</updated><title type='text'>Future publications of the lab</title><content type='html'>Hi&lt;br /&gt;&lt;br /&gt;People from the lab have an intense technical production and are about to present papers in the next months. Here are the main ones:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;H2HC 2011 - Sao Paulo, Brazil - &lt;a href="http://www.h2hc.com.br/treinamentos.php?lang=en&amp;amp;venue=saopaulo#cryptography2"&gt;&lt;span style="font-style: italic;"&gt;Tutorial in cryptanalysis&lt;/span&gt; &lt;/a&gt;(8 hours) (E. Filiol).&lt;/li&gt;&lt;li&gt;H2HC 2011 - Sao Paulo, Brazil - &lt;a style="font-style: italic;" href="http://www.h2hc.com.br/palestrantes.php#Speaker7"&gt;The TOR Attack&lt;/a&gt;&lt;span style="font-style: italic;"&gt;. (E. Filiol)&lt;br /&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://pacsec.jp/speakers.html"&gt;PacSec 2011 &lt;/a&gt;- Tokyo, Japan - &lt;span style="font-style: italic;"&gt;The TOR Attack&lt;/span&gt; (E. Filiol)&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://congreso.seguridad.unam.mx/2011/main-en.dsc"&gt;Computer Security 2011&lt;/a&gt;, Mexico City, &lt;span style="font-style: italic;"&gt;Mexico. Analyzing Android Applications&lt;/span&gt; (A. Desnos + G. Gueguen).&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.amadeusonline.org/images/programme-medays-2011-fr-2.pdf"&gt;Medays 2011&lt;/a&gt;, Tanger, Morocco. &lt;span style="font-style: italic;"&gt;E-Security: Comment lutter contre l'émergence permanente de nouveaux risques&lt;/span&gt; (E. Filiol).&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Black Hat Abu Dhabi 2011. &lt;a style="font-style: italic;" href="http://www.blackhat.com/html/bh-ad-11/bh-ad-11-briefings.html"&gt;Android: from Reversing to Decompilation&lt;/a&gt; (A. Desnos + G. Gueguen).&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Malcon 2011, India. &lt;a style="font-style: italic;" href="http://malcon.org/cfp/qualified-papers-malcon-2011/"&gt;How to make your Home Botnet&lt;/a&gt;. (B. David).&lt;br /&gt;&lt;/li&gt;&lt;li&gt;HICSS 2012, Hawai, USA. &lt;span style="font-style: italic;"&gt;Android: Static Analysis Using Similarity Distance&lt;/span&gt; (A. Desnos).&lt;/li&gt;&lt;li&gt;HICSS 2012, Hawai, USA. &lt;span style="font-style: italic;"&gt;New Trends in Security Evaluation of Bayesian Network-based Malware Detection Models&lt;/span&gt; (E. Filiol + S. Josse).&lt;/li&gt;&lt;/ul&gt;All papers, slides and tools are and should be soon available.&lt;br /&gt;Have a nice day&lt;br /&gt;&lt;br /&gt;E. F.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6281858739286835733-1573884055888346920?l=cvo-lab.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/1573884055888346920'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/1573884055888346920'/><link rel='alternate' type='text/html' href='http://cvo-lab.blogspot.com/2011/10/future-publications-of-lab.html' title='Future publications of the lab'/><author><name>Eric Filiol</name><uri>http://www.blogger.com/profile/04835548005201063894</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/-X0IVCfnSjNo/TrmrvRiBBaI/AAAAAAAAADY/5fPBjidBQfk/s220/shadow_runner.jpeg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6281858739286835733.post-1848700680162309171</id><published>2011-10-13T22:56:00.000-07:00</published><updated>2011-10-14T07:01:32.041-07:00</updated><title type='text'>Libre Office International Conférence in Paris Day I</title><content type='html'>Hi to all&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;From October 13th to October 15th, a major event in computing industry takes place in Paris: the International Libre Office Conference. The official website is &lt;a href="http://conference.libreoffice.org/"&gt;here&lt;/a&gt; while the detailed program is &lt;a href="http://conference.libreoffice.org/programme/"&gt;here&lt;/a&gt;. We will not describe all the technical contents of the different talks since the slides of all of them will be on the official website. &lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Jonathan Dechaux who attends the conference has harvested a lot of good/interesting news for the day I of the event. Here are the main of them among which are offical announcements:&lt;/div&gt;&lt;div&gt;&lt;ul&gt;&lt;li&gt;Libre Office is already used by 25 000 000 users and it is expected that in the next forthcoming years the number will grow to 200 000 000 users .&lt;/li&gt;&lt;li&gt;The suite is going to be part of the software on the USB key delivered for free to 800 000 Paris aera students ("Ile de France"). The Paris area moreover has joined the LibreOffice fundation as well as the Brazilian government.&lt;/li&gt;&lt;li&gt;The cloud version of LibreOffice has been officially announced (with a Firefox plug-in). The GTK, ODF and HTML5 technologies has been chosen. The result will be LibreOffice Online. You can watch a demo video &lt;a href="http://people.gnome.org/%7Emichael/data/2011-10-10-lool-demo.webm"&gt;here&lt;/a&gt;. &lt;span style="font-size:85%;"&gt;&lt;span style="font-size: 10pt;"&gt;&lt;br /&gt; .&lt;/span&gt;&lt;/span&gt;The only problem (from a security point of view) lies in the fact that it will still integrate Macros and therefore is likely to become a Pandora box.&lt;/li&gt;&lt;li&gt;Libre Office is going to equip 500 000 computers of the French government.&lt;/li&gt;&lt;li&gt;The suite is about to be available on Android and iOS.&lt;/li&gt;&lt;/ul&gt;There were the news from day I. More info &lt;a href="http://wp.me/p1byPE-bW"&gt;here.&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Have a nice day&lt;/div&gt;&lt;div&gt;E.F.&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style=";font-family:Tahoma;font-size:100%;"  &gt;&lt;span class="Apple-style-span"  style="font-size:13px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6281858739286835733-1848700680162309171?l=cvo-lab.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/1848700680162309171'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/1848700680162309171'/><link rel='alternate' type='text/html' href='http://cvo-lab.blogspot.com/2011/10/libre-office-international-conference.html' title='Libre Office International Conférence in Paris Day I'/><author><name>Eric Filiol</name><uri>http://www.blogger.com/profile/04835548005201063894</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/-X0IVCfnSjNo/TrmrvRiBBaI/AAAAAAAAADY/5fPBjidBQfk/s220/shadow_runner.jpeg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6281858739286835733.post-8709026777989214638</id><published>2011-06-29T06:22:00.001-07:00</published><updated>2011-06-29T06:30:12.476-07:00</updated><title type='text'>Publication ESIEA Espoir Recherche</title><content type='html'>Bonjour à tous&lt;br /&gt;&lt;br /&gt;Baptiste David, étudiant ESIEA et espoir recherche de deuxième année au laboratoire a présenté ses travaux menés sur l'identification en PERL des équations différentielles, lors des "&lt;a href="http://journeesperl.fr/fpw2011/"&gt;Journées PERL 2011&lt;/a&gt;", à Paris les 24 et 25 juin 2011.&lt;br /&gt;&lt;br /&gt;Les slides sont disponibles &lt;a href="https://docs.google.com/leaf?id=0B6BlkqAoxXq1ZWIzNzY4MjYtNmIxMS00YzM0LWI1OWUtMmYzOTkzNjExMmUz&amp;amp;hl=en_US"&gt;ici&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Bonne journée à tous&lt;br /&gt;&lt;br /&gt;E.F.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6281858739286835733-8709026777989214638?l=cvo-lab.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/8709026777989214638'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/8709026777989214638'/><link rel='alternate' type='text/html' href='http://cvo-lab.blogspot.com/2011/06/publication-esiea-espoir-recherche.html' title='Publication ESIEA Espoir Recherche'/><author><name>Eric Filiol</name><uri>http://www.blogger.com/profile/04835548005201063894</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/-X0IVCfnSjNo/TrmrvRiBBaI/AAAAAAAAADY/5fPBjidBQfk/s220/shadow_runner.jpeg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6281858739286835733.post-4396602241824010374</id><published>2011-06-28T05:21:00.000-07:00</published><updated>2011-06-28T11:19:42.197-07:00</updated><title type='text'>CVO recrute sur Laval</title><content type='html'>Bonjour à tous,&lt;br /&gt;&lt;br /&gt;Le laboratoire de cryptologie et de virologie opérationnelles recrute et propose deux postes (CDI) sur Laval.&lt;br /&gt;&lt;br /&gt;&lt;ul style="text-align: justify;"&gt;&lt;li&gt;Un jeune docteur en informatique/mathématiques discrètes ayant un bonne connaissance de la programmation sécurisée, du reverse engineering et de l'analyse de malware et de programmes. Le poste comporte une mission d'enseignement, de recherche et d'animation scientifique. La préparation d'une HDR sera un des objectif à moyen terme pour ce poste. Sans renier l'approche académique, le recrutement privilégiera une  pré-disposition pour l'approche technique de type Hacker. Une bonne connaissance de l'anglais (écrit/parlé) est obligatoire.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Un ingénieur ou titulaire d'un master 2 en informatique/sécurité/cryptologie souhaitant en parallèle préparer une thèse. Bonne maitrise de la programmation (C, C++, python), des outils de calcul formel (Magma, Mathematica...). Le poste comporte une mission d'enseignement, de recherche et de développement. Une bonne connaissance de l'anglais (écrit/parlé) est obligatoire. &lt;/li&gt;&lt;/ul&gt;Du fait de l'environnement de travail du laboratoire, les candidats devront se soumettre à une enquête de sécurité.&lt;br /&gt;&lt;br /&gt;Les candidats intéressés enverront un CV et une lettre de motivation à filiol@esiea.fr&lt;br /&gt;&lt;br /&gt;Bonne journée à tous.&lt;br /&gt;&lt;br /&gt;E.F.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6281858739286835733-4396602241824010374?l=cvo-lab.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/4396602241824010374'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/4396602241824010374'/><link rel='alternate' type='text/html' href='http://cvo-lab.blogspot.com/2011/06/cvo-recrute-sur-laval.html' title='CVO recrute sur Laval'/><author><name>Eric Filiol</name><uri>http://www.blogger.com/profile/04835548005201063894</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/-X0IVCfnSjNo/TrmrvRiBBaI/AAAAAAAAADY/5fPBjidBQfk/s220/shadow_runner.jpeg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6281858739286835733.post-7184911938714260763</id><published>2011-06-28T05:14:00.000-07:00</published><updated>2011-06-28T05:18:25.610-07:00</updated><title type='text'>Cyberwarfare book</title><content type='html'>Hi to all of you&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;We have the pleasure to announce the availibility of the book entitled "&lt;a style="font-style: italic;" href="http://iste.co.uk/index.php?f=x&amp;amp;ACTION=View&amp;amp;id=433"&gt;Cyberwar and Information Warfare&lt;/a&gt;" published by Wiley.&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/-jk2xh6FCxGk/TgnGLrVQhjI/AAAAAAAAABo/5mssSasLmNA/s1600/doc_fbxvoagdbdrk_medium.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 85px; height: 128px;" src="http://2.bp.blogspot.com/-jk2xh6FCxGk/TgnGLrVQhjI/AAAAAAAAABo/5mssSasLmNA/s200/doc_fbxvoagdbdrk_medium.jpg" alt="" id="BLOGGER_PHOTO_ID_5623243513661523506" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;Our laboratory has written the chapter entitled "&lt;span style="font-style: italic;"&gt;Operational Aspects of a Cyberattack: Intelligence, Planning and Conduct&lt;/span&gt;". This chapter is used as the basis of our course in Cyberwarfare techniques given at ESIEA Laval.&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;Have a nice reading.&lt;br /&gt;&lt;br /&gt;E.F.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6281858739286835733-7184911938714260763?l=cvo-lab.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/7184911938714260763'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/7184911938714260763'/><link rel='alternate' type='text/html' href='http://cvo-lab.blogspot.com/2011/06/cyberwarfare-book.html' title='Cyberwarfare book'/><author><name>Eric Filiol</name><uri>http://www.blogger.com/profile/04835548005201063894</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/-X0IVCfnSjNo/TrmrvRiBBaI/AAAAAAAAADY/5fPBjidBQfk/s220/shadow_runner.jpeg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-jk2xh6FCxGk/TgnGLrVQhjI/AAAAAAAAABo/5mssSasLmNA/s72-c/doc_fbxvoagdbdrk_medium.jpg' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-6281858739286835733.post-1500825817789354231</id><published>2011-06-23T23:37:00.000-07:00</published><updated>2011-06-23T23:58:27.232-07:00</updated><title type='text'>LibPerseus Challenge Results</title><content type='html'>Hi to all&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;We have the pleasure to announce that Guillaume Delugré and Gabriel Campana from Sogeti/ESEC France (a really nice R&amp;amp;D company in Security) has won the challenge. They have sent the plaintext text corresponding to the chall3.coded file. Congratulations to them. They did a really nice work which will be very useful for the Perseus project. They will be recently awarded with the prize.&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Their attack (more details &lt;a href="https://docs.google.com/leaf?id=0B6BlkqAoxXq1ZjdlOWM2MzQtMTJmNS00MTg5LTgzZDAtYjM1MWFkYWVjOTJk&amp;amp;hl=en_US&amp;amp;authkey=CIy17-0J"&gt;here&lt;/a&gt;) is a clever and nice  implementation attack &lt;span style="font-weight: bold;"&gt;which does not hence put the Perseus (mathematical) concept into question&lt;/span&gt;.  Their attack shows that going from the theory to implementation is always complex and prone to security weakness.&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;The attack exploits the fact that&lt;br /&gt;&lt;ul style="text-align: justify;"&gt;&lt;li&gt;the plaintext is split into blocks of constant size (for performance purposes, it is more practical to consider this approach since forthcoming parallel decoding of blocks will overcome the complexity of the Viterbi decoding) each block being encoded with the same encoder.&lt;/li&gt;&lt;li&gt;due to a bad (and stupid) bug in our implementation the noise pattern was always the same (by mistake we forgot to declare a few variables as static and then each call to the noise generator resets its state). Ironically, this dramatic weakness could have been detected by our cryptanalysis library &lt;a href="http://code.google.com/p/mediggo/"&gt;Mediggo&lt;/a&gt; (tool detectsinglefile.c) which precisely has been designed to detect this kind of flaw. But development speed and security are seldom compatible (shoemakers are often the worst shod -:))&lt;/li&gt;&lt;li&gt;It seems that implementation of the puncturing is a little faulty as well.&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div style="text-align: justify;"&gt;What is clear is that without the help of Guillaume and Gabriel, we would probably never detect this (infamous) bugs. Thousands thanks to them and to their contribution.&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;The bugs will be of course corrected in the new implementations of the Perseus lib which is under currentl development with the help of DFT-Technologies (which has performed the industrial specifications of LibPerseus and will perform the final code auditing). This implementation is about to be made public and officially presented during the RMLL 2011 in July in Strasbourg. Here are the new features that takes Guillaume and Gabriel's attack into account:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;This implementation considers blocks of variable sizes (ranging from 512 to 4096).&lt;/li&gt;&lt;li&gt;Each block is encoded with a different encoder.&lt;/li&gt;&lt;li&gt;The noise pattern of course will be variable itself.&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;div style="text-align: justify;"&gt;As originally implemented in the Perseus library itself, normally the message should be a single block. We are presently developping a polynomial-memory decoder that will make decoding very quick and will enable to consider message as a single block. More to come... &lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Of course, we hope that contributors will volunteer to evaluate this implementation. Once again congratulations to Guillaume and Gabriel. We would like also thank all people who support, sponsor the Perseus project and all those who contribute with comments and feedbacks.&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;E.F.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6281858739286835733-1500825817789354231?l=cvo-lab.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/1500825817789354231'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/1500825817789354231'/><link rel='alternate' type='text/html' href='http://cvo-lab.blogspot.com/2011/06/libperseus-challenge-results.html' title='LibPerseus Challenge Results'/><author><name>Eric Filiol</name><uri>http://www.blogger.com/profile/04835548005201063894</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/-X0IVCfnSjNo/TrmrvRiBBaI/AAAAAAAAADY/5fPBjidBQfk/s220/shadow_runner.jpeg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6281858739286835733.post-4550939807149307515</id><published>2011-06-17T06:14:00.000-07:00</published><updated>2011-06-17T07:55:55.684-07:00</updated><title type='text'>LibPerseus Challenge Reset</title><content type='html'>Hi to all&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;Following a number of requests (especially from our sponsors and our supporting partners regarding the Perseus project), feedbacks and critics about the (obvious) lack of precision and data with respect to the LibPerseus challenge, we were strongly advised to reset this challenge today in order to offer more precise and thorough conditions:&lt;br /&gt;&lt;/div&gt;&lt;ul style="text-align: justify;"&gt;&lt;li&gt;files and binaries have been reset (the previous version was inappropriate since it made encoder collision possible thus providing different possible solutions while only one should exist within the parameter space considered).&lt;br /&gt;&lt;/li&gt;&lt;li&gt;More info given on plaintext files to recover&lt;br /&gt;&lt;/li&gt;&lt;li&gt;binary program that produced the new challenge files is provided (beta version at the present time). The source code will be made public as soon as possible.    &lt;/li&gt;&lt;li&gt;Legal aspects of the challenge checked and clarified (thanks to Mr Auger, esquirre, bailiff in Laval, France who has pointed to us a few legal imprecision).&lt;/li&gt;&lt;li&gt;Time limit of the challenge and award have been consequently extended for fairness.&lt;/li&gt;&lt;/ul&gt;&lt;div style="text-align: justify;"&gt;The link to the challenge page is &lt;a href="http://cvo-lab.blogspot.com/2011/05/iawacsrssil-2011-libperseus-challenge.html"&gt;here&lt;/a&gt;&lt;br /&gt;We apologize for the inconvenience. Thanks to all who make us aware of the necessity to reset this challenge and help us to improve it. Thanks to our sponsors and partners (mainly DFT-Technologies).&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;E.F.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6281858739286835733-4550939807149307515?l=cvo-lab.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/4550939807149307515'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/4550939807149307515'/><link rel='alternate' type='text/html' href='http://cvo-lab.blogspot.com/2011/06/libperseus-challenge-reset.html' title='LibPerseus Challenge Reset'/><author><name>Eric Filiol</name><uri>http://www.blogger.com/profile/04835548005201063894</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/-X0IVCfnSjNo/TrmrvRiBBaI/AAAAAAAAADY/5fPBjidBQfk/s220/shadow_runner.jpeg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6281858739286835733.post-8635547711464783596</id><published>2011-06-10T14:45:00.000-07:00</published><updated>2011-06-10T14:46:10.042-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Androguard'/><category scheme='http://www.blogger.com/atom/ns#' term='Diffing'/><category scheme='http://www.blogger.com/atom/ns#' term='Android'/><category scheme='http://www.blogger.com/atom/ns#' term='Skype'/><title type='text'>Android diffing tool : skype vulnerability</title><content type='html'>The original article is &lt;a href="http://androguard.blogspot.com/2011/06/android-diffing-tool-skype.html"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6281858739286835733-8635547711464783596?l=cvo-lab.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://androguard.blogspot.com/2011/06/android-diffing-tool-skype.html' title='Android diffing tool : skype vulnerability'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/8635547711464783596'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/8635547711464783596'/><link rel='alternate' type='text/html' href='http://cvo-lab.blogspot.com/2011/06/android-diffing-tool-skype.html' title='Android diffing tool : skype vulnerability'/><author><name>Anthony Desnos</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-6281858739286835733.post-7336528670746437790</id><published>2011-06-05T13:11:00.000-07:00</published><updated>2011-06-06T14:36:21.428-07:00</updated><title type='text'>PERSEUS Principles</title><content type='html'>Hi &lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;A few recent comments seem to prove that people speak a lot about Perseus without a clear knowledge of what it is and claim that the mathematical principles are not neither known nor published. Well. This is not the case (otherwise the challenge would not be fair and would not comply to Kerckhoffs' laws).&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Here are the main technical data (published for more than one year):&lt;/div&gt;&lt;div&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.esiea-recherche.eu/data/iawacs2010/slides/filiol_deligne_iawacs2010.pdf"&gt;Slides&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://arxiv.org/abs/1101.0057"&gt;Technical paper&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://code.google.com/p/libperseus/"&gt;Source code &lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div style="text-align: justify;"&gt;Moreover the industrial support and development (secure implementations for example) is provided by &lt;a href="http://www.dft-techno.com/"&gt;DFT Technologies.&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Due to some misunderstanding about the challenge conditions and the fact that no binaries are provided (we wish to make the concept to be tested/evaluated and not a particular implementation), we have just issued a new version of the PERSEUS Lib which uses random generation by means of the /dev/random primitives (in your application just remind that /dev/random is a blocking device and the kernel will have to be helped eventually during the encoder generation).&lt;br /&gt;&lt;br /&gt;Of course, that does not affect the conditions and validity of the challenge but we just want to calm down and take into account some wise comments and feedbacks (and we need constructive feedbacks all the time). Once again the use of &lt;span style="font-style: italic;"&gt;rand()&lt;/span&gt; was far from being optimal (we plead guilty since we were aware of this weakness and even exploit it in the past) but by laziness or lack of care we concentrated on the concept rather on the security of the implementation. Now it is fixed as well as the x00 bug (that was relevant for the python version only). We hope that now people will concentrate on the concept security itself. The PERSEUS concept can be very useful to many people as confirmed by many feedbacks.&lt;br /&gt;&lt;br /&gt;For people who use personal attacks against my work, I will not make any comment. They do not deserve it. They have just to keep in mind that it is far easier to criticize than taking risks by fighting in the arena, trying to make security progress. and proposing new trends in data security. For those who pointed out our lack of care with the &lt;span style="font-style: italic;"&gt;rand()&lt;/span&gt; primitive, well they were right so thanks to them. They did their job.&lt;br /&gt;&lt;br /&gt;Now let us go ahead.&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;E.F.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6281858739286835733-7336528670746437790?l=cvo-lab.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/7336528670746437790'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/7336528670746437790'/><link rel='alternate' type='text/html' href='http://cvo-lab.blogspot.com/2011/06/perseus-principles.html' title='PERSEUS Principles'/><author><name>Eric Filiol</name><uri>http://www.blogger.com/profile/04835548005201063894</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/-X0IVCfnSjNo/TrmrvRiBBaI/AAAAAAAAADY/5fPBjidBQfk/s220/shadow_runner.jpeg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6281858739286835733.post-694665912376044962</id><published>2011-05-31T05:46:00.000-07:00</published><updated>2011-05-31T05:47:47.854-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Similarity'/><category scheme='http://www.blogger.com/atom/ns#' term='Androguard'/><category scheme='http://www.blogger.com/atom/ns#' term='Diffing'/><category scheme='http://www.blogger.com/atom/ns#' term='Android'/><title type='text'>Similarity of android applications or "rip-off indicator"</title><content type='html'>The original article is &lt;a href="http://androguard.blogspot.com/2011/05/similarity-of-android-applications-or.html"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6281858739286835733-694665912376044962?l=cvo-lab.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://androguard.blogspot.com/2011/05/similarity-of-android-applications-or.html' title='Similarity of android applications or &quot;rip-off indicator&quot;'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/694665912376044962'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/694665912376044962'/><link rel='alternate' type='text/html' href='http://cvo-lab.blogspot.com/2011/05/similarity-of-android-applications-or.html' title='Similarity of android applications or &quot;rip-off indicator&quot;'/><author><name>Anthony Desnos</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-6281858739286835733.post-2393887530472388952</id><published>2011-05-26T13:30:00.000-07:00</published><updated>2011-05-26T13:45:03.036-07:00</updated><title type='text'>Additional information about the libperseus challenge</title><content type='html'>Hi guys&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;(French version below) &lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;I have received (strange) questions about the &lt;a href="http://cvo-lab.blogspot.com/2011/05/iawacsrssil-2011-libperseus-challenge.html"&gt;Perseus lib chalenge&lt;/a&gt; asking to provide the binaries/source code that has been used to produce the two files for the challenge. Well,&lt;/div&gt;&lt;div style="text-align: justify;"&gt;the source code is for months available &lt;a href="http://code.google.com/p/libperseus/"&gt;here&lt;/a&gt;. And the binaries have been produced from it directly.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;It is important to stress on the fact that the problem is algorithmic by nature (mathematical problem) and that you will have to do more than simply trying to base your attack on flaws or anything like that. It is here useless. It would be simple. Just consider that you have wiretapped the files (this is the operational reality) and you have the source code (Kerckhoffs conditions). &lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Indeed security is a little bit more difficult to overcome when there is no flaw. &lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;(French version)&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;J'ai eu des questions récemment (étranges) concernant le c&lt;a href="http://cvo-lab.blogspot.com/2011/05/iawacsrssil-2011-libperseus-challenge.html"&gt;hallenge Perseus&lt;/a&gt; me demandant de fournir le code source et les binaires ayant servi à produire les deux fichiers du challenge. Le code source est disponible depuis des mois sur le s&lt;a href="http://code.google.com/p/libperseus/"&gt;ite de la librairie&lt;/a&gt; et le binaire a été produit directement à partir de ce code source.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Il est important de rappeler que le problème est par nature algorithmique et que vous devrez faire une peu plus que de chercher à fonder une attaque sur une vulnérabilité (qui en l'espèce n'existe pas). Cela n'a ici pas de sens. Considérez que vous avez intercepté les fichiers (cas des conditions opérationnelles) et que vous connaissez le procédé (règle de Kerckhoffs). C'est suffisant.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Contourner la sécurité quand il n'y a pas de faille d'implémentation est certes plus dur mais c'est plus excitant.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Bon courage à tous et à samedi aux RSSIL&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;E.F. &lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6281858739286835733-2393887530472388952?l=cvo-lab.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/2393887530472388952'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/2393887530472388952'/><link rel='alternate' type='text/html' href='http://cvo-lab.blogspot.com/2011/05/additional-information-about-libperseus.html' title='Additional information about the libperseus challenge'/><author><name>Eric Filiol</name><uri>http://www.blogger.com/profile/04835548005201063894</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/-X0IVCfnSjNo/TrmrvRiBBaI/AAAAAAAAADY/5fPBjidBQfk/s220/shadow_runner.jpeg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6281858739286835733.post-7605759357887465410</id><published>2011-05-25T00:10:00.000-07:00</published><updated>2011-06-17T07:48:02.585-07:00</updated><title type='text'>iAWACS/RSSIL 2011 LibPerseus challenge</title><content type='html'>Hi to all&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;(French version below) &lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;The &lt;a href="http://code.google.com/p/libperseus/"&gt;LibPerseus&lt;/a&gt; challenge purpose is to  evaluate the Perseus technology and to prove/show that it is indeed unbreakable  unless  having tremendous time/computing resources at one's disposal. Hence the aim is to test Perseus technology strength and security in a real context (and not with respect to academic conditions).&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;b&gt;Technical scheme&lt;/b&gt;: three files have been protected by means of the Perseus library. They have been eavesdrop. No information about the computer from which they have been produced is available.&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="https://docs.google.com/uc?id=0B6BlkqAoxXq1MTRlYTIxMDQtZGU4ZC00N2I3LTlmMjktZDViODA3YTg2NjVm&amp;amp;export=download&amp;amp;hl=en_US"&gt;File 1&lt;/a&gt; protected by an random punctured convolutional encoder E1. SHA-1 Digest 5628084D6EF360406B19C6E57F5F4BD0CF019910. Size 190,986 bytes.&lt;/li&gt;&lt;li&gt;&lt;a href="https://docs.google.com/uc?id=0B6BlkqAoxXq1NWZlMzA3MTgtNzk5OC00YjQ3LThiOWItYzJhMjhlZTBkYjU5&amp;amp;export=download&amp;amp;hl=en_US"&gt;File 2&lt;/a&gt; protected by an random punctured convolutional encoder E2. SHA-1 Digest 7C5F5BE3F8C3143D428402C8B6B01C04033DEA0B. Size 263,996 bytes&lt;/li&gt;&lt;li&gt;&lt;a href="https://docs.google.com/uc?id=0B6BlkqAoxXq1NWY2MGE1ZmQtNWNkYi00YzRmLThjMGMtZTI3ZWMzZjIwODNj&amp;amp;export=download&amp;amp;hl=en_US"&gt;File 3&lt;/a&gt; protected by an random punctured convolutional encoder E3. SHA-1 Digest CAE5BF0CD032EBC9652CE3B3318ACD500BEE84D6. Size 26,482,752 bytes&lt;/li&gt;&lt;li&gt;&lt;a href="https://docs.google.com/uc?id=0B6BlkqAoxXq1NGY4ZTMxZWQtYTU0Mi00OTUwLWE5NDEtZGZlYjE3OWFjMmJj&amp;amp;export=download&amp;amp;authkey=CPe027MG&amp;amp;hl=en_US"&gt;Binary file&lt;/a&gt; (windows) of the program (warning: this is a beta version which is non optimized and that may contain residual bugs to be reported. As soon as frozen, source code and documentation will be published). SHA-1 Digest value 20CEF319E3D209D6EC288998F90C0E737720ED17. Size 5,022,669 bytes. A Linux version of the binaries can be provided upon request.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;The solution E1, E2 and E3 are UNIQUE and the files (before protection by Perseus) to recover are plaintext (not encrypted). So anyone finding a solution is able to determine whether it is the correct one or not. Since E1, E2 and E3 are unique, the files to recover are also unique (no encoder collision).&lt;/li&gt;&lt;li&gt;Solution (plaintext file) 1 has the SHA-1 Digest value AAE42E6E0F80B1803A218CB1BE7A1ED12AD29B06&lt;/li&gt;&lt;li&gt;Solution  (plaintext file) 2 has the SHA-1 Digest value F35BBE9B4754DE431FA1C45C96C2561282679D84&lt;/li&gt;&lt;li&gt;Solution  (plaintext file) 3 has the SHA-1 Digest value 0F03FF24CC007A37DE82BB567674CEBCDF9FE4DE&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Here are the condition for the challenge:&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;ul&gt;&lt;li&gt;Opening date: May 25th, 2011. Reset on June 17th, 2011.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;End of the challenge: March 31&lt;sup&gt;st&lt;/sup&gt;, 2012.&lt;/li&gt;&lt;li&gt;The solution (plaintext file) must sent to iawacs@esiea.fr. &lt;/li&gt;&lt;li&gt;There is only one prize (award) of 4,000 euros which cannot be divided. One prize, one winner only.&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-weight: bold;"&gt;Rules of the challenge:&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;ul&gt;&lt;li&gt;The prize (4,000 euros) will be awarded to the first  people (internet time will  be taken as reference in case of multiple answers) only who is able to recover  at least one of the t hree documents protected with Perseus.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;The method used will have to be described on a technical basis and the source of the attack algroithm provided to the organizers of the challenge.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Any partial solution, hint or valuable information will be considered for a honor award. &lt;/li&gt;&lt;li&gt;Results and solutions will be published on this blog.&lt;/li&gt;&lt;/ul&gt;Have a nice challenge and good luck guys!&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;E.F.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;*************************************************************************************&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;b&gt;&lt;i&gt;Version française&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;Le  challenge Perseus vise à évaluer la technologie Perseus en la soumettant à l'analyse de tous. Il s'agit de démontrer qu'à moins de disposer de ressources temps/mémoire exorbitantes, il est effectivement impossible de casser en pratique cette technologie.  Le but au travers de ce  challenge est de tester la force et la sécurité de Perseus en conditions opérationnelles (et non académique). &lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;b&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-style: normal; font-weight: normal;"&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;b&gt;Thème technique &lt;/b&gt;: trois fichiers ont été protégés avec la librairie Perseus. Ils doivent être considérés comme le produit d'une interception et par conséquent aucune information relative à l'ordinateur les ayant produit n'est disponible.&lt;br /&gt;&lt;ul style="text-align: justify;"&gt;&lt;li&gt;&lt;a href="https://docs.google.com/uc?id=0B6BlkqAoxXq1MTRlYTIxMDQtZGU4ZC00N2I3LTlmMjktZDViODA3YTg2NjVm&amp;amp;export=download&amp;amp;hl=en_US"&gt;File 1&lt;/a&gt; protégé par un codeur convolutif poinçonné bruité E1. SHA-1 Digest  5628084D6EF360406B19C6E57F5F4BD0CF019910. Taille 190,986 octets.&lt;/li&gt;&lt;li&gt;&lt;a href="https://docs.google.com/uc?id=0B6BlkqAoxXq1NWZlMzA3MTgtNzk5OC00YjQ3LThiOWItYzJhMjhlZTBkYjU5&amp;amp;export=download&amp;amp;hl=en_US"&gt;File 2&lt;/a&gt; &lt;b&gt;&lt;i&gt;&lt;b&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-style: normal; font-weight: normal;"&gt;protégé par un codeur convolutif poinçonné bruité&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/i&gt;&lt;/b&gt; E2. SHA-1 Digest 7C5F5BE3F8C3143D428402C8B6B01C04033DEA0B. Taille 263,996 octets.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="https://docs.google.com/uc?id=0B6BlkqAoxXq1NWY2MGE1ZmQtNWNkYi00YzRmLThjMGMtZTI3ZWMzZjIwODNj&amp;amp;export=download&amp;amp;hl=en_US"&gt;File 3&lt;/a&gt;  &lt;b&gt;&lt;i&gt;&lt;b&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-style: normal; font-weight: normal;"&gt;protégé par un codeur convolutif poinçonné bruité &lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/i&gt;&lt;/b&gt;E3. SHA-1 Digest  CAE5BF0CD032EBC9652CE3B3318ACD500BEE84D6. Taille 26,482,752 octets&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="https://docs.google.com/uc?id=0B6BlkqAoxXq1NGY4ZTMxZWQtYTU0Mi00OTUwLWE5NDEtZGZlYjE3OWFjMmJj&amp;amp;export=download&amp;amp;authkey=CPe027MG&amp;amp;hl=en_US"&gt;Binaires&lt;/a&gt; Windows du programme ayant généré ces fichiers (attention il s'agit d'une version bêta, non optimisée, susceptible de faire l'objet d'une remontée de bugs ; cette application, son code source et sa documentation seront publiés prochainement une fois le code stabilisé). Empreinte SHA-1 20CEF319E3D209D6EC288998F90C0E737720ED17. Taille 5 022 669 octets. Une version Linux peut être fournie sur demande.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Les solutions E1, E2 et E3 sont  UNIQUES  et les fichiers (avant protection par Perseus) à retrouver sont des fichiers en clair (non chiffrés). Ainsi, toute personne pensant avoir une solution peut elle-même déterminer si cette solution est la bonne ou non. Comme E1, E2 et E3 sont uniques, les fichiers à retrouver le sont aussi. (aucune collision de codeur possible dans l'espace des paramètres imposés).&lt;/li&gt;&lt;li&gt;Solution (fichier clair) 1 a pour valeur d'empreinte SHA-1 AAE42E6E0F80B1803A218CB1BE7A1ED12AD29B06&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Solution  (&lt;b&gt;&lt;i&gt;&lt;b&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-style: normal; font-weight: normal;"&gt;fichier clair&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/i&gt;&lt;/b&gt;) 2 &lt;b&gt;&lt;i&gt;&lt;b&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-style: normal; font-weight: normal;"&gt;a pour valeur d'empreinte SHA-1&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/i&gt;&lt;/b&gt; F35BBE9B4754DE431FA1C45C96C2561282679D84&lt;/li&gt;&lt;li&gt;Solution  (&lt;b&gt;&lt;i&gt;&lt;b&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-style: normal; font-weight: normal;"&gt;fichier clair&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/i&gt;&lt;/b&gt;) 3 &lt;b&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-style: normal; font-weight: normal;"&gt;&lt;b&gt;&lt;i&gt;&lt;b&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-style: normal; font-weight: normal;"&gt;a pour valeur d'empreinte SHA-1 &lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/i&gt;&lt;/b&gt;&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;0F03FF24CC007A37DE82BB567674CEBCDF9FE4DE&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;b&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-style: normal; font-weight: normal;"&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;span style="font-weight: bold;"&gt;Conditions du challenge:&lt;/span&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;b&gt;&lt;i&gt;&lt;span&gt;&lt;b&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-style: normal; font-weight: normal;"&gt;&lt;ul&gt;&lt;li&gt;Ouverture : 25 mai 2011. Réinitialisé le 17 juin 2011.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Fin du challenge : 31 mars 2012.&lt;/li&gt;&lt;li&gt;La solution (un des trois fichiers en clair définis ci-dessus au moins) doit être envoyée à iawacs@esiea.fr &lt;/li&gt;&lt;li&gt;Un seul prix de 4000 euros, indivisible (un seul prix, un seul gagnant possible) sera attribué.&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify; font-weight: bold;"&gt;Règles du challenge :&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;ul&gt;&lt;li&gt;Le  prix (4000 euros) sera attribué à la première personne qui enverra au moins l'un des trois documents protégés par Perseus (document original AVANT codage tel que définis supra). Le temps Internet (date du mail) sera utilisé pour départager les éventuels concurrents ayant fourni une solution correcte.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Le procédé utilisé devra faire l'objet d'une description technique et le code source devra être communiqué aux organisateurs.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Toute information technique partielle sera étudiée et pourra faire l'objet d'un prix d'honneur.&lt;/li&gt;&lt;li&gt;Les résultats seront publiés sur ce blog.&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;Bonne chance à tous&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;E.F.&lt;/div&gt;&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6281858739286835733-7605759357887465410?l=cvo-lab.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/7605759357887465410'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/7605759357887465410'/><link rel='alternate' type='text/html' href='http://cvo-lab.blogspot.com/2011/05/iawacsrssil-2011-libperseus-challenge.html' title='iAWACS/RSSIL 2011 LibPerseus challenge'/><author><name>Eric Filiol</name><uri>http://www.blogger.com/profile/04835548005201063894</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/-X0IVCfnSjNo/TrmrvRiBBaI/AAAAAAAAADY/5fPBjidBQfk/s220/shadow_runner.jpeg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6281858739286835733.post-3245983597624335721</id><published>2011-05-22T09:16:00.000-07:00</published><updated>2011-05-25T00:34:46.336-07:00</updated><title type='text'>iAWACS 2011 Forensics challenge</title><content type='html'>Hi to all&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;(French version below) &lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;The Forensics challenge for iAWACS 2011 is now open. It is inspired from a real case on which a new information hiding techniques has been created. The aim is to test its strength and its security on a almost real implementation (and not with respect to academic conditions).&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;b&gt;Tactical scheme&lt;/b&gt;: a terrorist attack against the RSSIL 2011 event has been prepared according to some intelligence reports. A terrorist has been caught by the French police forces while he was about to recuperate a cell phone hidden in a geocache. Despite the efforts of the Police forensics and technical teams, the analysis of the cell phone has not been successful yet. However, the analysis proved that the Dcim directory is containing a secret message hidden. &lt;/div&gt;&lt;div style="text-align: justify;"&gt;The terrorist confessed that he was waiting for a call to him on this cell phone to receive instructions about another geocache. This second one contains a SD card with the application to access the secret message.  Unfortunately, this call will never happen (newspapers have leaked on this arrest).&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;So will you be clever and imaginative enough to recover the secret message and prevent the attack against RSSIL 2011?&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Here are the condition for the challenge:&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;ul&gt;&lt;li&gt;Opening date: May 22&lt;sup&gt;nd&lt;/sup&gt;, 2011. The file &lt;a href="http://www.esiea-recherche.eu/data/dcim.tgz"&gt;dcim.tgz&lt;/a&gt; contains the Camera directory (the phone is a Samsung Galaxy S).&lt;/li&gt;&lt;li&gt;Award ceremony (if any winner) or technical hints at the &lt;a href="http://www.rssil.org/"&gt;RSSIL 2011&lt;/a&gt; event to go on with the challenge.&lt;/li&gt;&lt;li&gt;End of the challenge: December 31&lt;sup&gt;st&lt;/sup&gt;, 2011.&lt;/li&gt;&lt;li&gt;The solution must sent to iawacs@esiea.fr. &lt;/li&gt;&lt;/ul&gt;&lt;span style="font-weight: bold;"&gt;Rules of the challenge:&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;ul&gt;&lt;li&gt;The prize (5000 euros) will be awarded to anyone able to recover the message and the hiding mechanism only.&lt;/li&gt;&lt;li&gt;The technical mechanism will not be disclosed (unless by a potential winner who is free to publish any information with respect to it) by the organizers of the challenge. Only the secret message will be published once the challenge is closed.&lt;/li&gt;&lt;li&gt;Any partial solution, hint or valuable information will be considered for a honor award. &lt;/li&gt;&lt;/ul&gt;Have a nice challenge and good luck guys!&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;E.F.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;*************************************************************************************&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;b&gt;&lt;i&gt;Version française&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;b&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;b&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-style: normal; font-weight: normal;"&gt;&lt;div style="text-align: justify;"&gt;Le challenge forensics d'iAWACS 2011 est maintenant ouvert. Ce challenge est inspiré d'un cas réel à partir duquel une nouvelle technique de dissimulation d'information a été conçue. Le but au travers de ce challenge est de tester la force et la sécurité de ce procédé sur une implémentation en conditions opérationnelles (et non académique). &lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;b&gt;Thème tactique &lt;/b&gt;: une attaque terroriste contre RSSIL 2011 est en préparation selon des rapports des services de renseignement. Un terroriste a été arrêté par les forces de police au moment où il récupérait un téléphone mobile dans une géocache. Malgré les efforts de la police scientifique, l'analyse du téléphone a échoué. Toutefois, certaines pistes ayant été pu être écartées avec raison, les experts sont convaincus que le répertoire Dcim contient un message secret. &lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Le terroriste a avoué qu'il attendait un appel sur ce portable qui devait lui indiquer l'emplacement d'une seconde géocache. Cette dernière devait lui permettre via une application sur une SD card d'accéder au message secret et donc à ses instructions. Malheureusement ce appel n'arrivera maintenant plus, les journalistes ayant révélé la capture du terroriste.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Serez vous assez malin et imaginatif pour trouver ce message secret et ainsi empêcher l'attentat contre les RSSIL 2011 ?&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify; font-weight: bold;"&gt;Conditions du challenge:&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;ul&gt;&lt;li&gt;Ouverture : 22 mai 2011. Le fichier &lt;a href="http://www.esiea-recherche.eu/data/dcim.tgz"&gt;dcim.tgz&lt;/a&gt; contient le répertoire "Camera" (le téléphone est un Samsung Galaxy S).&lt;/li&gt;&lt;li&gt;Remise du prix (s'il y a un gagnant) ou indices techniques pour prolonger le challenge durant les &lt;a href="http://www.rssil.org/"&gt;RSSIL 2011&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;Fin du challenge : 31 décembre 2011.&lt;/li&gt;&lt;li&gt;La solution doit être envoyée à iawacs@esiea.fr &lt;/li&gt;&lt;/ul&gt;&lt;span style="font-weight: bold;"&gt;Règles du challenge :&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;ul&gt;&lt;li&gt;Le prix (5000 euros) sera attribué à la première personne qui enverra le message secret avec une description du mécanisme de dissimulation des données. &lt;/li&gt;&lt;li&gt;Ce procédé ne sera pas rendu public par les organisateurs (en revanche le gagnant est libre de publier toute information technique à ce sujet). Seule la solution (le message secret) sera publique. &lt;/li&gt;&lt;li&gt;Toute information technique partielle sera étudiée et pourra faire l'objet d'un prix d'honneur.&lt;/li&gt;&lt;/ul&gt;Bonne chance à tous&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;E.F.&lt;/div&gt;&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6281858739286835733-3245983597624335721?l=cvo-lab.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/3245983597624335721'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/3245983597624335721'/><link rel='alternate' type='text/html' href='http://cvo-lab.blogspot.com/2011/05/iawacs-2011-forensics-challenge.html' title='iAWACS 2011 Forensics challenge'/><author><name>Eric Filiol</name><uri>http://www.blogger.com/profile/04835548005201063894</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/-X0IVCfnSjNo/TrmrvRiBBaI/AAAAAAAAADY/5fPBjidBQfk/s220/shadow_runner.jpeg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6281858739286835733.post-3123032307010314411</id><published>2011-05-19T02:06:00.000-07:00</published><updated>2011-05-19T02:07:27.298-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Androguard'/><category scheme='http://www.blogger.com/atom/ns#' term='Diffing'/><category scheme='http://www.blogger.com/atom/ns#' term='Android'/><title type='text'>Diffing Android Applications</title><content type='html'>The original article is &lt;a href="http://androguard.blogspot.com/2011/05/diffing-android-applications.html"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6281858739286835733-3123032307010314411?l=cvo-lab.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://androguard.blogspot.com/2011/05/diffing-android-applications.html' title='Diffing Android Applications'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/3123032307010314411'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/3123032307010314411'/><link rel='alternate' type='text/html' href='http://cvo-lab.blogspot.com/2011/05/diffing-android-applications.html' title='Diffing Android Applications'/><author><name>Anthony Desnos</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-6281858739286835733.post-271229543370296224</id><published>2011-05-17T13:20:00.001-07:00</published><updated>2011-05-17T13:22:04.976-07:00</updated><title type='text'>Specialized master in Cyberwarfare</title><content type='html'>Hi&lt;br /&gt;You are interested in pentesting or want to become a cyber warrior. Our N&amp;amp;IS (&lt;span style="font-style: italic;"&gt;Network and Information Security&lt;/span&gt;) specialized master is for you. Visit this &lt;a href="https://sites.google.com/site/esieanismaster/"&gt;link&lt;/a&gt;, read and enlist.&lt;br /&gt;The scientific support is ensured by our lab.&lt;br /&gt;&lt;br /&gt;E. F.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6281858739286835733-271229543370296224?l=cvo-lab.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/271229543370296224'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/271229543370296224'/><link rel='alternate' type='text/html' href='http://cvo-lab.blogspot.com/2011/05/specialized-master-in-cyberwarfare.html' title='Specialized master in Cyberwarfare'/><author><name>Eric Filiol</name><uri>http://www.blogger.com/profile/04835548005201063894</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/-X0IVCfnSjNo/TrmrvRiBBaI/AAAAAAAAADY/5fPBjidBQfk/s220/shadow_runner.jpeg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6281858739286835733.post-2305261903387032733</id><published>2011-05-17T05:17:00.000-07:00</published><updated>2011-05-21T02:03:43.540-07:00</updated><title type='text'>Post-doc or junior researchers positions</title><content type='html'>Hi,&lt;br /&gt;&lt;br /&gt;Well sometimes Christmas comes sooner than expected. I have three potential positions for post-doc or junior researchers for a period ranging from 12 to 24 months.&lt;br /&gt;The conditions are the following:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Non-French nationality&lt;/li&gt;&lt;li&gt;Having a PhD&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Being less than 38 years old&lt;/li&gt;&lt;/ul&gt;We are looking for researchers having the following profile:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Computer science with a good level in discrete mathematics&lt;/li&gt;&lt;li&gt;Skills in programming (C, python)&lt;/li&gt;&lt;li&gt;Hacker approach and mind strongly appreciated&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Strong sense of contact and friendship&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;The research can be either in operational cryptology, computer virology or cyberwarfare.&lt;br /&gt;&lt;br /&gt;If you are interested, please send an email with CV at drdi@esiea.fr&lt;br /&gt;&lt;br /&gt;Have a nice day&lt;br /&gt;&lt;br /&gt;E. F.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6281858739286835733-2305261903387032733?l=cvo-lab.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/2305261903387032733'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/2305261903387032733'/><link rel='alternate' type='text/html' href='http://cvo-lab.blogspot.com/2011/05/post-doc-or-junior-researchers.html' title='Post-doc or junior researchers positions'/><author><name>Eric Filiol</name><uri>http://www.blogger.com/profile/04835548005201063894</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/-X0IVCfnSjNo/TrmrvRiBBaI/AAAAAAAAADY/5fPBjidBQfk/s220/shadow_runner.jpeg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6281858739286835733.post-5625998122410558662</id><published>2011-05-17T03:03:00.000-07:00</published><updated>2011-05-17T03:07:30.404-07:00</updated><title type='text'>EICAR 2011 Paper on Mobile Botnets</title><content type='html'>Hi&lt;br /&gt;Many people ask us why the &lt;a href="http://www.eicar.org/conference/presentations.htm"&gt;EICAR 2011&lt;/a&gt; paper on "&lt;span style="font-style: italic;"&gt;Mobile Botnet&lt;/span&gt;" was announced but not presented. Well the two Chinese authors cancelled at the very last minute. "Visa problem" was the official reason.&lt;br /&gt;Read the &lt;a href="https://docs.google.com/viewer?a=v&amp;amp;pid=explorer&amp;amp;chrome=true&amp;amp;srcid=0B6BlkqAoxXq1YjNiNWI1NDgtZjE5Ni00ZTg4LTkwOTEtMDNhMmI3Yjc0NTQ5&amp;amp;hl=en"&gt;paper&lt;/a&gt; and make your own advice&lt;br /&gt;&lt;br /&gt;Have a nice reading&lt;br /&gt;E.F. (EICAR 2011 Program Chair)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6281858739286835733-5625998122410558662?l=cvo-lab.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/5625998122410558662'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/5625998122410558662'/><link rel='alternate' type='text/html' href='http://cvo-lab.blogspot.com/2011/05/eicar-2011-paper-on-mobile-botnets.html' title='EICAR 2011 Paper on Mobile Botnets'/><author><name>Eric Filiol</name><uri>http://www.blogger.com/profile/04835548005201063894</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/-X0IVCfnSjNo/TrmrvRiBBaI/AAAAAAAAADY/5fPBjidBQfk/s220/shadow_runner.jpeg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6281858739286835733.post-9126348292088739100</id><published>2011-05-16T08:54:00.000-07:00</published><updated>2011-05-16T09:33:20.189-07:00</updated><title type='text'>McAfee Quarantine file and sequels from our EICAR 2011 paper</title><content type='html'>Hi&lt;br /&gt;Following our talk at &lt;a href="http://www.eicar.org/conference/programme.htm"&gt;EICAR 2011&lt;/a&gt; (first day), we have announced the release of some technical data. Of course, for fairness Peter Szor at McAFee has been contacted about our paper and the present post and his feedback and comments have been very constructive. In this respect, McAfee decision to recruit Peter is likely to be a wise and strategic decision which could result in a significantly better AV. Wait and see...&lt;br /&gt;&lt;br /&gt;We would like address the problem of the quarantine file (referring to Section Wake up! in the &lt;a href="https://sites.google.com/site/ericfiliol/home/international-conferences/internationalconferencefiles/eicar11filiol_zacardelle.pdf?attredirects=0&amp;amp;d=1"&gt;paper) &lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Why the McAfee Quarantine Wake-up Proof of Concept happened? Our PoC  relies on two factors:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;The McAfee Quarantine Directory is accessible to ALL users. It can be read and by the fact extracted to other directories.&lt;/li&gt;&lt;li&gt;The McAfee Quarantined files are protected by a weak key encryption&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;Our Proof of Concept is based on the EICAR test file (to avoid working with real malware):&lt;br /&gt;&lt;ol&gt;&lt;li&gt;As soon as the EICAR is detected by the McAfee Antivirus protection software, it is moved to the Quarantine directory and deleted.&lt;/li&gt;&lt;li&gt;All McAfee Quarantine files are under the BUP extension which in fact “extractable” from the 7zip open source software.&lt;/li&gt;&lt;li&gt;As soon as you can extract it with 7zip file, you still not able to restore the original file.&lt;/li&gt;&lt;li&gt;Details gives you all the information to restore the file (name and extension of the original virus).&lt;/li&gt;&lt;li&gt;You need to XOR all the files previously extracted by the key “0x6A”&lt;br /&gt;&lt;/li&gt;&lt;/ol&gt;Our PoC consists in reading the content of BUP file and recovering the virus under the File_0. We have demonstrated that it was clearly possible to activate all quarantined files and thus performed a lot of different attack scenarii (from DoS to covering a new viral attack).&lt;br /&gt;&lt;br /&gt;McAfee has been informed, through its Indian development team at Tata, India, during the EICAR 2011 conference and will fix as soon as possible this critical issue (probably in the next McAfee Roadmap). It is worth mentionning that weak management in quarantine directories and weak encryption has been identified for a few other AV vendors and products. To be continues then...&lt;br /&gt;&lt;br /&gt;Source code (PERL):&lt;br /&gt;&lt;br /&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;o:officedocumentsettings&gt;   &lt;o:relyonvml/&gt;   &lt;o:allowpng/&gt;  &lt;/o:OfficeDocumentSettings&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:worddocument&gt;   &lt;w:view&gt;Normal&lt;/w:View&gt;   &lt;w:zoom&gt;0&lt;/w:Zoom&gt;   &lt;w:trackmoves/&gt;   &lt;w:trackformatting/&gt;   &lt;w:donotshowrevisions/&gt;   &lt;w:donotprintrevisions/&gt;   &lt;w:donotshowmarkup/&gt;   &lt;w:donotshowcomments/&gt;   &lt;w:donotshowinsertionsanddeletions/&gt;   &lt;w:donotshowpropertychanges/&gt;   &lt;w:hyphenationzone&gt;21&lt;/w:HyphenationZone&gt;   &lt;w:punctuationkerning/&gt;   &lt;w:validateagainstschemas/&gt;   &lt;w:saveifxmlinvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;   &lt;w:ignoremixedcontent&gt;false&lt;/w:IgnoreMixedContent&gt;   &lt;w:alwaysshowplaceholdertext&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;   &lt;w:donotpromoteqf/&gt;   &lt;w:lidthemeother&gt;FR&lt;/w:LidThemeOther&gt;   &lt;w:lidthemeasian&gt;X-NONE&lt;/w:LidThemeAsian&gt;   &lt;w:lidthemecomplexscript&gt;X-NONE&lt;/w:LidThemeComplexScript&gt;   &lt;w:compatibility&gt;    &lt;w:breakwrappedtables/&gt;    &lt;w:snaptogridincell/&gt;    &lt;w:wraptextwithpunct/&gt;    &lt;w:useasianbreakrules/&gt;    &lt;w:dontgrowautofit/&gt;    &lt;w:splitpgbreakandparamark/&gt;    &lt;w:dontvertaligncellwithsp/&gt;    &lt;w:dontbreakconstrainedforcedtables/&gt;    &lt;w:dontvertalignintxbx/&gt;    &lt;w:word11kerningpairs/&gt;    &lt;w:cachedcolbalance/&gt;   &lt;/w:Compatibility&gt;   &lt;w:donotoptimizeforbrowser/&gt;   &lt;m:mathpr&gt;    &lt;m:mathfont val="Cambria Math"&gt;    &lt;m:brkbin val="before"&gt;    &lt;m:brkbinsub val="&amp;#45;-"&gt;    &lt;m:smallfrac val="off"&gt;    &lt;m:dispdef/&gt;    &lt;m:lmargin val="0"&gt;    &lt;m:rmargin val="0"&gt;    &lt;m:defjc val="centerGroup"&gt;    &lt;m:wrapindent val="1440"&gt;    &lt;m:intlim val="subSup"&gt;    &lt;m:narylim val="undOvr"&gt;   &lt;/m:mathPr&gt;&lt;/w:WordDocument&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:latentstyles deflockedstate="false" defunhidewhenused="true" defsemihidden="true" defqformat="false" defpriority="99" latentstylecount="267"&gt;   &lt;w:lsdexception locked="false" priority="0" semihidden="false" unhidewhenused="false" qformat="true" name="Normal"&gt;   &lt;w:lsdexception locked="false" priority="9" semihidden="false" unhidewhenused="false" qformat="true" name="heading 1"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 2"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 3"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 4"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 5"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 6"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 7"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 8"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 9"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 1"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 2"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 3"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 4"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 5"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 6"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 7"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 8"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 9"&gt;   &lt;w:lsdexception locked="false" priority="35" qformat="true" name="caption"&gt;   &lt;w:lsdexception locked="false" priority="10" semihidden="false" unhidewhenused="false" qformat="true" name="Title"&gt;   &lt;w:lsdexception locked="false" priority="1" name="Default Paragraph Font"&gt;   &lt;w:lsdexception locked="false" priority="11" semihidden="false" unhidewhenused="false" qformat="true" name="Subtitle"&gt;   &lt;w:lsdexception locked="false" priority="22" semihidden="false" unhidewhenused="false" qformat="true" name="Strong"&gt;   &lt;w:lsdexception locked="false" priority="20" semihidden="false" unhidewhenused="false" qformat="true" name="Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="59" semihidden="false" unhidewhenused="false" name="Table Grid"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Placeholder Text"&gt;   &lt;w:lsdexception locked="false" priority="1" semihidden="false" unhidewhenused="false" qformat="true" name="No Spacing"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Revision"&gt;   &lt;w:lsdexception locked="false" priority="34" semihidden="false" unhidewhenused="false" qformat="true" name="List Paragraph"&gt;   &lt;w:lsdexception locked="false" priority="29" semihidden="false" unhidewhenused="false" qformat="true" name="Quote"&gt;   &lt;w:lsdexception locked="false" priority="30" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Quote"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="19" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="21" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="31" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Reference"&gt;   &lt;w:lsdexception locked="false" priority="32" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Reference"&gt;   &lt;w:lsdexception locked="false" priority="33" semihidden="false" unhidewhenused="false" qformat="true" name="Book Title"&gt;   &lt;w:lsdexception locked="false" priority="37" name="Bibliography"&gt;   &lt;w:lsdexception locked="false" priority="39" qformat="true" name="TOC Heading"&gt;  &lt;/w:LatentStyles&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 10]&gt; &lt;style&gt;  /* Style Definitions */  table.MsoNormalTable  {mso-style-name:"Tableau Normal";  mso-tstyle-rowband-size:0;  mso-tstyle-colband-size:0;  mso-style-noshow:yes;  mso-style-priority:99;  mso-style-qformat:yes;  mso-style-parent:"";  mso-padding-alt:0cm 5.4pt 0cm 5.4pt;  mso-para-margin:0cm;  mso-para-margin-bottom:.0001pt;  mso-pagination:widow-orphan;  font-size:11.0pt;  font-family:"Cambria","serif";  mso-ascii-font-family:Cambria;  mso-ascii-theme-font:minor-latin;  mso-fareast-font-family:"Times New Roman";  mso-fareast-theme-font:minor-fareast;  mso-hansi-font-family:Cambria;  mso-hansi-theme-font:minor-latin;} &lt;/style&gt; &lt;![endif]--&gt;  &lt;div style="border: 1pt solid windowtext; padding: 1pt 4pt;"&gt;  &lt;p class="MsoNormal" style="border: medium none; padding: 0cm;"&gt;&lt;span style="font-size: 8pt; font-family: Courier;"&gt;#!/usr/bin/perl&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="border: medium none; padding: 0cm;"&gt;&lt;span style="font-size: 8pt; font-family: Courier;"&gt;# &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="border: medium none; padding: 0cm;"&gt;&lt;span style="font-size: 8pt; font-family: Courier;" lang="EN-US"&gt;# Date:&lt;span style=""&gt;         &lt;/span&gt;EICAR 2011 (Austria)&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="border: medium none; padding: 0cm;"&gt;&lt;span style="font-size: 8pt; font-family: Courier;" lang="EN-US"&gt;# Description:&lt;span style=""&gt;  &lt;/span&gt;It is a Proof Of Concept of decoding the McAfee VirusScan Quarantine BUP files (All McAfee versions)&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="border: medium none; padding: 0cm;"&gt;&lt;span style="font-size: 8pt; font-family: Courier;" lang="EN-US"&gt;# Requirements: It uses open-source 7zip compression tool&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="border: medium none; padding: 0cm;"&gt;&lt;span style="font-size: 8pt; font-family: Courier;" lang="EN-US"&gt;# Todo:&lt;span style=""&gt;         &lt;/span&gt;Implement the 7zip decompression algorithm to avoid using 7zip program&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="border: medium none; padding: 0cm;"&gt;&lt;span style="font-size: 8pt; font-family: Courier;" lang="EN-US"&gt;#&lt;span style=""&gt;               &lt;/span&gt;This program should parse the Details file to be able to name File_x with their original names &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="border: medium none; padding: 0cm;"&gt;&lt;span style="font-size: 8pt; font-family: Courier;" lang="EN-US"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="border: medium none; padding: 0cm;"&gt;&lt;span style="font-size: 8pt; font-family: Courier;" lang="EN-US"&gt;my $BUPFILE = $ARGV[0] or die "BUP File is required\n";&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="border: medium none; padding: 0cm;"&gt;&lt;span style="font-size: 8pt; font-family: Courier;" lang="EN-US"&gt;my $cmd = `7z e $BUPFILE -oBUP/`;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="border: medium none; padding: 0cm;"&gt;&lt;span style="font-size: 8pt; font-family: Courier;" lang="EN-US"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="border: medium none; padding: 0cm;"&gt;&lt;span style="font-size: 8pt; font-family: Courier;" lang="EN-US"&gt;opendir(DBUP, "./BUP/");&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="border: medium none; padding: 0cm;"&gt;&lt;span style="font-size: 8pt; font-family: Courier;" lang="EN-US"&gt;while (my $ditem = readdir(DBUP)) {&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="border: medium none; padding: 0cm;"&gt;&lt;span style="font-size: 8pt; font-family: Courier;" lang="EN-US"&gt;&lt;span style=""&gt;        &lt;/span&gt;# Extract the information of infected file (Details file stores product version, detected virus, DAT signature us&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="border: medium none; padding: 0cm;"&gt;&lt;span style="font-size: 8pt; font-family: Courier;" lang="EN-US"&gt;ed...&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="border: medium none; padding: 0cm;"&gt;&lt;span style="font-size: 8pt; font-family: Courier;" lang="EN-US"&gt;&lt;span style=""&gt;        &lt;/span&gt;if ((-f "./BUP/$ditem") &amp;amp;&amp;amp; ($ditem =~ m/details/i)) {&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="border: medium none; padding: 0cm;"&gt;&lt;span style="font-size: 8pt; font-family: Courier;" lang="EN-US"&gt;&lt;span style=""&gt;                &lt;/span&gt;open(fd, "&amp;lt;./BUP/$ditem") or die "File error $!\n";&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="border: medium none; padding: 0cm;"&gt;&lt;span style="font-size: 8pt; font-family: Courier;" lang="EN-US"&gt;&lt;span style=""&gt;                &lt;/span&gt;open(fout, "&amp;gt;./BUP/$ditem.details") or die "File error $!\n";&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="border: medium none; padding: 0cm;"&gt;&lt;span style="font-size: 8pt; font-family: Courier;" lang="EN-US"&gt;&lt;span style=""&gt;                &lt;/span&gt;while(&lt;fd&gt;) {&lt;/fd&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="border: medium none; padding: 0cm;"&gt;&lt;span style="font-size: 8pt; font-family: Courier;" lang="EN-US"&gt;&lt;span style=""&gt;                        &lt;/span&gt;print fout map { pack("c", 0x6A ^ ord($_)) } split (//, $_);&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="border: medium none; padding: 0cm;"&gt;&lt;span style="font-size: 8pt; font-family: Courier;" lang="EN-US"&gt;&lt;span style=""&gt;           &lt;/span&gt;&lt;span style=""&gt;     &lt;/span&gt;}&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="border: medium none; padding: 0cm;"&gt;&lt;span style="font-size: 8pt; font-family: Courier;" lang="EN-US"&gt;&lt;span style=""&gt;                &lt;/span&gt;close(fd);&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="border: medium none; padding: 0cm;"&gt;&lt;span style="font-size: 8pt; font-family: Courier;" lang="EN-US"&gt;&lt;span style=""&gt;                &lt;/span&gt;seek(fout, 0, 0);&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="border: medium none; padding: 0cm;"&gt;&lt;span style="font-size: 8pt; font-family: Courier;" lang="EN-US"&gt;&lt;span style=""&gt;                &lt;/span&gt;while(&lt;fout&gt;) {&lt;/fout&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="border: medium none; padding: 0cm;"&gt;&lt;span style="font-size: 8pt; font-family: Courier;" lang="EN-US"&gt;&lt;span style=""&gt;                        &lt;/span&gt;print;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="border: medium none; padding: 0cm;"&gt;&lt;span style="font-size: 8pt; font-family: Courier;" lang="EN-US"&gt;&lt;span style=""&gt;                &lt;/span&gt;}&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="border: medium none; padding: 0cm;"&gt;&lt;span style="font-size: 8pt; font-family: Courier;" lang="EN-US"&gt;&lt;span style=""&gt;                &lt;/span&gt;close(fout);&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="border: medium none; padding: 0cm;"&gt;&lt;span style="font-size: 8pt; font-family: Courier;" lang="EN-US"&gt;&lt;span style=""&gt;                &lt;/span&gt;exit;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="border: medium none; padding: 0cm;"&gt;&lt;span style="font-size: 8pt; font-family: Courier;" lang="EN-US"&gt;&lt;span style=""&gt;        &lt;/span&gt;}&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="border: medium none; padding: 0cm;"&gt;&lt;span style="font-size: 8pt; font-family: Courier;" lang="EN-US"&gt;&lt;span style=""&gt;        &lt;/span&gt;# Decoding the infected files if they are present.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="border: medium none; padding: 0cm;"&gt;&lt;span style="font-size: 8pt; font-family: Courier;" lang="EN-US"&gt;&lt;span style=""&gt;        &lt;/span&gt;if ((-f "./BUP/$ditem") &amp;amp;&amp;amp; ($ditem =~ /File/i)) {&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="border: medium none; padding: 0cm;"&gt;&lt;span style="font-size: 8pt; font-family: Courier;" lang="EN-US"&gt;&lt;span style=""&gt;                &lt;/span&gt;my $vir = rand(10) . ".vir";&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="border: medium none; padding: 0cm;"&gt;&lt;span style="font-size: 8pt; font-family: Courier;" lang="EN-US"&gt;&lt;span style=""&gt;                &lt;/span&gt;open(fd, "&amp;lt;./BUP/$ditem") or die "File error $!\n";&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="border: medium none; padding: 0cm;"&gt;&lt;span style="font-size: 8pt; font-family: Courier;" lang="EN-US"&gt;&lt;span style=""&gt; &lt;/span&gt;&lt;span style=""&gt;      &lt;/span&gt;&lt;span style=""&gt;  &lt;/span&gt;open(fout, "&amp;gt;./BUP/$vir") or die "Error file vir";&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="border: medium none; padding: 0cm;"&gt;&lt;span style="font-size: 8pt; font-family: Courier;" lang="EN-US"&gt;&lt;span style=""&gt;                &lt;/span&gt;while(&lt;fd&gt;) {&lt;/fd&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="border: medium none; padding: 0cm;"&gt;&lt;span style="font-size: 8pt; font-family: Courier;" lang="EN-US"&gt;&lt;span style=""&gt;                        &lt;/span&gt;print fout map { pack("c", 0x6A ^ ord($_)) } split(//, $_);&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="border: medium none; padding: 0cm;"&gt;&lt;span style="font-size: 8pt; font-family: Courier;" lang="EN-US"&gt;&lt;span style=""&gt;                &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="border: medium none; padding: 0cm;"&gt;&lt;span style="font-size: 8pt; font-family: Courier;" lang="EN-US"&gt;&lt;span style=""&gt;                &lt;/span&gt;}&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="border: medium none; padding: 0cm;"&gt;&lt;span style="font-size: 8pt; font-family: Courier;" lang="EN-US"&gt;&lt;span style=""&gt;                &lt;/span&gt;close(fout);&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="border: medium none; padding: 0cm;"&gt;&lt;span style="font-size: 8pt; font-family: Courier;" lang="EN-US"&gt;&lt;span style=""&gt;                &lt;/span&gt;close(fd);&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="border: medium none; padding: 0cm;"&gt;&lt;span style="font-size: 8pt; font-family: Courier;" lang="EN-US"&gt;&lt;span style=""&gt;        &lt;/span&gt;}&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="border: medium none; padding: 0cm;"&gt;&lt;span style="font-size: 8pt; font-family: Courier;" lang="EN-US"&gt;}&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="border: medium none; padding: 0cm;"&gt;&lt;span style="font-size: 8pt; font-family: Courier;" lang="EN-US"&gt;closedir(DBUP);&lt;/span&gt;&lt;/p&gt;  &lt;/div&gt; &lt;br /&gt;Regarding the ZouAV detection issues and concerns. Since our talk, this code has now two additional names. More to come in a forthcoming post.&lt;br /&gt;&lt;br /&gt;E.F.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6281858739286835733-9126348292088739100?l=cvo-lab.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/9126348292088739100'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/9126348292088739100'/><link rel='alternate' type='text/html' href='http://cvo-lab.blogspot.com/2011/05/mcafee-quarantine-file-and-sequels-from.html' title='McAfee Quarantine file and sequels from our EICAR 2011 paper'/><author><name>Eric Filiol</name><uri>http://www.blogger.com/profile/04835548005201063894</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/-X0IVCfnSjNo/TrmrvRiBBaI/AAAAAAAAADY/5fPBjidBQfk/s220/shadow_runner.jpeg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6281858739286835733.post-1414450913817460201</id><published>2011-05-16T07:32:00.001-07:00</published><updated>2011-05-16T07:32:38.762-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='Androguard'/><category scheme='http://www.blogger.com/atom/ns#' term='Android'/><title type='text'>Android zsone malware</title><content type='html'>The original article is &lt;a href="http://androguard.blogspot.com/2011/05/android-zsone-malware.html"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6281858739286835733-1414450913817460201?l=cvo-lab.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://androguard.blogspot.com/2011/05/android-zsone-malware.html' title='Android zsone malware'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/1414450913817460201'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/1414450913817460201'/><link rel='alternate' type='text/html' href='http://cvo-lab.blogspot.com/2011/05/android-zsone-malware.html' title='Android zsone malware'/><author><name>Anthony Desnos</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-6281858739286835733.post-3623581008543441839</id><published>2011-05-05T10:38:00.001-07:00</published><updated>2011-05-05T10:46:40.929-07:00</updated><title type='text'>EICAR 2011 Conference in Krems</title><content type='html'>&lt;span class="Apple-style-span"  style="font-family:verdana;"&gt;Hi to all&lt;/span&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-family:verdana;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;span class="Apple-style-span"  style="font-family:verdana;"&gt;We are leaving to tomorrow to Krems in Austria where the 20&lt;/span&gt;&lt;sup&gt;&lt;span class="Apple-style-span"  style="font-family:verdana;"&gt;th&lt;/span&gt;&lt;/sup&gt;&lt;span class="Apple-style-span"  style="font-family:verdana;"&gt; edition of the &lt;/span&gt;&lt;a href="http://www.eicar.org/conference/"&gt;&lt;span class="Apple-style-span"  style="font-family:verdana;"&gt;EICAR conference&lt;/span&gt;&lt;/a&gt;&lt;span class="Apple-style-span"  style="font-family:verdana;"&gt; will take place. This conference is the oldest one in Computer Virology and this year many critical topics will be addressed, especially about Cyberwarfare, the role of AV software with respect to the use of malware techniques by Police/Intelligence/Defense organizations and many other technical topics. The main theme for this jubilee edition is &lt;/span&gt;&lt;span class="Apple-style-span" style="font-size: 12px; "&gt;&lt;strong style="font-weight: bold; "&gt;&lt;span class="Apple-style-span"  style="font-family:verdana;"&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;&lt;span class="Apple-style-span" style="font-size: medium;"&gt;&lt;i&gt;“New trends in Malware and Antimalware techniques: myths, reality and context - What will be the AV role in a Cyber War scenario?&lt;/i&gt;&lt;/span&gt;&lt;/span&gt;” &lt;span class="Apple-style-span" style="font-weight: normal; font-size: medium;"&gt;A really hot issue indeed!&lt;/span&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;span class="Apple-style-span"  style="font-family:verdana;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;span class="Apple-style-span"  style="font-family:verdana;"&gt;The technical program is &lt;/span&gt;&lt;a href="http://www.eicar.org/conference/programme.htm"&gt;&lt;span class="Apple-style-span"  style="font-family:verdana;"&gt;here&lt;/span&gt;&lt;/a&gt;&lt;span class="Apple-style-span"  style="font-family:verdana;"&gt;. Slides and papers will be available on the conference website by mid May.&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;span class="Apple-style-span"  style="font-family:verdana;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;span class="Apple-style-span"  style="font-family:verdana;"&gt;E.F.&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6281858739286835733-3623581008543441839?l=cvo-lab.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/3623581008543441839'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/3623581008543441839'/><link rel='alternate' type='text/html' href='http://cvo-lab.blogspot.com/2011/05/eicar-2011-conference-in-krems.html' title='EICAR 2011 Conference in Krems'/><author><name>Eric Filiol</name><uri>http://www.blogger.com/profile/04835548005201063894</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/-X0IVCfnSjNo/TrmrvRiBBaI/AAAAAAAAADY/5fPBjidBQfk/s220/shadow_runner.jpeg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6281858739286835733.post-961324316790909536</id><published>2011-05-05T10:31:00.000-07:00</published><updated>2011-05-05T10:37:56.583-07:00</updated><title type='text'>Our research guest from Thailand</title><content type='html'>Hi to all&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;We have the great pleasure and honour to welcome Dr Bhume Bhumiratana from the Department of Computer Engineering, King Monkut's University of Technology, Thonburi, Thailand. He will stay in our lab for three months to discover the formal aspects of computer virology and especially the use of formal grammars in metamorphic techniques with application to the Android bytecode.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;His webpage is &lt;a href="http://cpe.kmutt.ac.th/index.php?id=336"&gt;here&lt;/a&gt;. &lt;/div&gt;&lt;div&gt;Welcome to Dr Bhume Bhumiratana&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6281858739286835733-961324316790909536?l=cvo-lab.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/961324316790909536'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/961324316790909536'/><link rel='alternate' type='text/html' href='http://cvo-lab.blogspot.com/2011/05/our-research-guest-from-thailand.html' title='Our research guest from Thailand'/><author><name>Eric Filiol</name><uri>http://www.blogger.com/profile/04835548005201063894</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/-X0IVCfnSjNo/TrmrvRiBBaI/AAAAAAAAADY/5fPBjidBQfk/s220/shadow_runner.jpeg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6281858739286835733.post-2318702670750986901</id><published>2011-03-21T02:29:00.000-07:00</published><updated>2011-03-22T00:36:04.120-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Honeynet'/><title type='text'>Honeynet Project : Day 1 (Public)</title><content type='html'>Efficient Bytecode Analysis : Linespeed Shellcode Detection (Georg Wicherski - McAfee)&lt;div&gt;&lt;ul&gt;&lt;li&gt;GetPC sequences ((call $+5, pop r32), (fnop, fnstenv [esp+0x0c], pop r32), structured exception handling)&lt;/li&gt;&lt;li&gt;detecting shellcodes (static) (eg: markov chains)&lt;/li&gt;&lt;li&gt;detecting shellcodes (getpc + backtraking + emulation)&lt;/li&gt;&lt;li&gt;libscizzle : identification of possible getpc sequences, bruteforce possible starting location around sequence, use efficient sandbox&lt;/li&gt;&lt;li&gt;libscizzle Code Execution (disassemble guest code, execute one basic blocks, emulate all other instructions, exception)&lt;/li&gt;&lt;li&gt;Performance of libscizzle : 99 MiB/sec to 795 MiB/sec, 1000x faster than libemu&lt;/li&gt;&lt;li&gt;Evaluation of libscizzle : no false positives, no false negatives&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;div&gt;High performance packet sniffing and traffic mining(Tillmann Wener)&lt;/div&gt;&lt;div&gt;&lt;ul&gt;&lt;li&gt;NIC -&gt; KERNEL -&gt; USERSPACE -&gt; FILE&lt;/li&gt;&lt;li&gt;pcap file format (straight-forward file format)&lt;/li&gt;&lt;li&gt;packet drops (sniffer too slow, lost information cannot be recovered), sniffing performance&lt;/li&gt;&lt;li&gt;multicap : minimiez memory allocations, no system calls to get packet times, memory-mapped dump files&lt;/li&gt;&lt;li&gt;streams : reassembly tcp streams&lt;/li&gt;&lt;li&gt;tools available @ http://src.carnivore.it&lt;/li&gt;&lt;/ul&gt;&lt;div&gt;Reversing android malware (Mahmud Ab rahman)&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;ul&gt;&lt;li&gt;Dalvik VM : registered based&lt;/li&gt;&lt;li&gt;Dex file format (odex : optimized dex)&lt;/li&gt;&lt;li&gt;infection methods : remote install (victim's gmail credential is required, browser market and install)&lt;/li&gt;&lt;li&gt;dex (baksmali)-&gt; class (jad)-&gt; java&lt;/li&gt;&lt;li&gt;SMS.trojan : oldest android malware&lt;/li&gt;&lt;li&gt;Geinimi : infecting legitimate software, C&amp;amp;C server, encrypted data, steal data&lt;/li&gt;&lt;li&gt;DroidDream : infecting legitimate software, android official market&lt;/li&gt;&lt;li&gt;Need new tools (GSOC Honeynet ?)&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;div&gt;&lt;div&gt;&lt;div&gt;VOIP Security (Sjur Usken and Ben Reardon)                                      &lt;/div&gt;&lt;div&gt;&lt;ul&gt;&lt;li&gt;SIP, request and response type, same familiar status codes as HTTP&lt;/li&gt;&lt;li&gt;Major difference between SIP and HTTP (in SIP, all devices are both server and client)&lt;/li&gt;&lt;li&gt;used to connect to the PSTN network&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;div&gt;Glastopf - Looking for trouble ? (Lukas Rist)&lt;/div&gt;&lt;div&gt;&lt;ul&gt;&lt;li&gt;Web application honeypot&lt;/li&gt;&lt;li&gt;collecting attacks&lt;/li&gt;&lt;li&gt;gain intelligence&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6281858739286835733-2318702670750986901?l=cvo-lab.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/2318702670750986901'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/2318702670750986901'/><link rel='alternate' type='text/html' href='http://cvo-lab.blogspot.com/2011/03/honeynet-project-day-1-public-live.html' title='Honeynet Project : Day 1 (Public)'/><author><name>Anthony Desnos</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-6281858739286835733.post-1950225195477530130</id><published>2011-03-20T03:36:00.000-07:00</published><updated>2011-03-20T03:41:56.096-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='iAWACS'/><title type='text'>iAWACS 2011</title><content type='html'>Hi !!&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;The CFP of iAWACS 2011 is &lt;a href="http://www.esiea-recherche.eu/data/iawacs11_cfp.txt"&gt;here&lt;/a&gt;. &lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;This year, we have 2 challenges :&lt;/div&gt;&lt;div&gt;&lt;ul&gt;&lt;li&gt;LibPerseus challenge. A file protected by the PERSEUS technology will        be proposed for analysis. The aim is to recover the underlying file.        Award 3000 euros.&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;Forensics challenge. The content of an Android Phone will be given (as        an iso image). In the tactical context of a terrorist attack to be        prepared, the aim will be to discover the critical information regarding        this attack in order to make it fail.        Award 5000 euros.&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;See ya !&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6281858739286835733-1950225195477530130?l=cvo-lab.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.esiea-recherche.eu/data/iawacs11_cfp.txt' title='iAWACS 2011'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/1950225195477530130'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/1950225195477530130'/><link rel='alternate' type='text/html' href='http://cvo-lab.blogspot.com/2011/03/iawacs-2011.html' title='iAWACS 2011'/><author><name>Anthony Desnos</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-6281858739286835733.post-5058610933473124994</id><published>2011-03-18T05:42:00.000-07:00</published><updated>2011-03-18T05:51:44.291-07:00</updated><title type='text'></title><content type='html'>Hi&lt;br /&gt;&lt;br /&gt;Following the Stuxnet conference (see&lt;a href="http://cvo-lab.blogspot.com/2011/03/stuxnet-conference.html"&gt; previous post in March&lt;/a&gt;), a number of sequels and reaction have been made with interesting feedbacks from various speakers (e.g. Jeffrey Carr). You will find everything &lt;a href="http://nanojv.wordpress.com/2011/03/16/stuxnet-conference-paris-0001/"&gt;here&lt;/a&gt;. You can also read a report in the &lt;a href="http://www.globes.co.il/serveen/globes/docview.asp?did=1000629925&amp;amp;fid=1725"&gt;Globes online journal&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;I do not agree on Jeffrey Carr's comments, at least for some of them. He seems not to be aware of how the hackers community is thinking, working and sharing things. More concerning, he seems to ignore most of the operational stuff when designing and deploying real attacks.&lt;br /&gt;&lt;br /&gt;However the echange of ideas was great. Thanks to him and to the organizers of this event.&lt;br /&gt;Have a nice day&lt;br /&gt;E.F.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6281858739286835733-5058610933473124994?l=cvo-lab.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/5058610933473124994'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/5058610933473124994'/><link rel='alternate' type='text/html' href='http://cvo-lab.blogspot.com/2011/03/hi-following-stuxnet-conference-see.html' title=''/><author><name>Eric Filiol</name><uri>http://www.blogger.com/profile/04835548005201063894</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/-X0IVCfnSjNo/TrmrvRiBBaI/AAAAAAAAADY/5fPBjidBQfk/s220/shadow_runner.jpeg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6281858739286835733.post-6916278530344809662</id><published>2011-03-15T08:17:00.000-07:00</published><updated>2011-03-15T08:18:02.577-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Android'/><title type='text'>Android + Permissions ?</title><content type='html'>The original article is &lt;a href="http://androguard.blogspot.com/2011/03/android-permissions.html"&gt;here.&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6281858739286835733-6916278530344809662?l=cvo-lab.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://androguard.blogspot.com/2011/03/android-permissions.html' title='Android + Permissions ?'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/6916278530344809662'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/6916278530344809662'/><link rel='alternate' type='text/html' href='http://cvo-lab.blogspot.com/2011/03/android-permissions.html' title='Android + Permissions ?'/><author><name>Anthony Desnos</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-6281858739286835733.post-3575414659312540842</id><published>2011-03-11T11:01:00.001-08:00</published><updated>2011-03-11T11:20:44.080-08:00</updated><title type='text'>Feedbacks from CanSecWest 2011</title><content type='html'>Hi&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;CanSecWest 2011 is nearly over. It is a very exciting place for hacking stuff. Without doubt it is one the very few hacking events that everyone concerned with operational IT security should attend. Thanks to Dragos and all the SecWest team. Perfect job and the party.... waouuuh what a party!!!! Just the kind of pure moment of pleasure that deserves to work hard on technical stuff during the year.&lt;br /&gt;&lt;br /&gt;As usual the technical program is rich and of a very high level. But no comment can replace reading the slides of the different talks. One of the strong point of CanSecWest up to me lies in the fact that the attendees are not just passive. They ask questions and are really interested. So sharing and exchanging ideas has been intense and constructive.&lt;br /&gt;&lt;br /&gt;After my talk on  Dynamic Cryptographic Backdoors, I had very interesting feedback from OpenBSD developpers. Regarding the second technique I have presented (patching and modifying encryption algorithms in memory to weaken them on-the-fly), they make a very interesting comment about encryption systems like Blowfish or Twofish. These two algorithms have some sort of polymorphism that makes almost impossible to use S-box signature. Well, it is partly true but using some local entropy measure should help to locate area to patch (or special functions like the PHT).&lt;br /&gt;&lt;br /&gt;But it is sure that this is a challenging problem. So we are going to address the particular case of Blowfish and Twofish. So to be continued...&lt;br /&gt;&lt;br /&gt;From that exchange I draw the conclusion that "polymorphic, design" in cryptographic algorithms provide more security against applied cryptanalysis techniques like that I have presented. In this respect, aside the fact that Twofish was not significantly weaker than Rijndael (damned academic research!), I am more than ever surprised about the fact that NIST did not select Twofish.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;E.F&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6281858739286835733-3575414659312540842?l=cvo-lab.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/3575414659312540842'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/3575414659312540842'/><link rel='alternate' type='text/html' href='http://cvo-lab.blogspot.com/2011/03/feedbacks-from-cansecwest-2011.html' title='Feedbacks from CanSecWest 2011'/><author><name>Eric Filiol</name><uri>http://www.blogger.com/profile/04835548005201063894</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/-X0IVCfnSjNo/TrmrvRiBBaI/AAAAAAAAADY/5fPBjidBQfk/s220/shadow_runner.jpeg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6281858739286835733.post-8065551221904067979</id><published>2011-03-09T10:10:00.000-08:00</published><updated>2011-03-09T10:17:15.102-08:00</updated><title type='text'>Voting machine attack</title><content type='html'>Hi&lt;br /&gt;&lt;br /&gt;Here is a prospective paper describing an unconventional yet efficient attack again voting machines, perverting the precautionary principle.&lt;br /&gt;Paper &lt;a href="https://docs.google.com/uc?id=0B6BlkqAoxXq1YTRmNDQxMDEtOGFhMS00NGFiLWJlOTctN2IwYWFiNDJhZGYw&amp;amp;export=download&amp;amp;hl=en"&gt;here&lt;/a&gt;.&lt;br /&gt;Have a nice reading&lt;br /&gt;&lt;br /&gt;E.F.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6281858739286835733-8065551221904067979?l=cvo-lab.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/8065551221904067979'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/8065551221904067979'/><link rel='alternate' type='text/html' href='http://cvo-lab.blogspot.com/2011/03/voting-machine-attack.html' title='Voting machine attack'/><author><name>Eric Filiol</name><uri>http://www.blogger.com/profile/04835548005201063894</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/-X0IVCfnSjNo/TrmrvRiBBaI/AAAAAAAAADY/5fPBjidBQfk/s220/shadow_runner.jpeg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6281858739286835733.post-1348132720501425373</id><published>2011-03-07T07:06:00.001-08:00</published><updated>2011-03-07T07:06:59.653-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='DroidDream'/><category scheme='http://www.blogger.com/atom/ns#' term='Android'/><title type='text'>DroidDream live session</title><content type='html'>Hi !&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;One new &lt;a href="http://androguard.blogspot.com/2011/03/droiddream-live-session.html"&gt;article&lt;/a&gt; about DroidDream.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6281858739286835733-1348132720501425373?l=cvo-lab.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://androguard.blogspot.com/2011/03/droiddream-live-session.html' title='DroidDream live session'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/1348132720501425373'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/1348132720501425373'/><link rel='alternate' type='text/html' href='http://cvo-lab.blogspot.com/2011/03/droiddream-live-session.html' title='DroidDream live session'/><author><name>Anthony Desnos</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-6281858739286835733.post-934746014399161410</id><published>2011-03-07T07:03:00.000-08:00</published><updated>2011-03-07T07:05:56.375-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='DroidDream'/><category scheme='http://www.blogger.com/atom/ns#' term='Android'/><title type='text'>DroidDream</title><content type='html'>Hi !&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Two articles about DroidDream malware : &lt;a href="http://androguard.blogspot.com/2011/03/droiddream.html"&gt;Part 1&lt;/a&gt; and &lt;a href="http://androguard.blogspot.com/2011/03/droiddream-part-2.html"&gt;Part 2&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6281858739286835733-934746014399161410?l=cvo-lab.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/934746014399161410'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/934746014399161410'/><link rel='alternate' type='text/html' href='http://cvo-lab.blogspot.com/2011/03/droiddream.html' title='DroidDream'/><author><name>Anthony Desnos</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-6281858739286835733.post-8686538012983103766</id><published>2011-03-05T03:12:00.001-08:00</published><updated>2011-03-05T03:19:58.195-08:00</updated><title type='text'>CanSecWest 2011</title><content type='html'>Hi to all&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;I will give a talk at CanSecWest 2011 in Vancouver (a very nice, among the best hacking conference) entitled "&lt;i&gt;Dynamic cryptographic trapdoors&lt;/i&gt;". Here is the &lt;a href="http://cansecwest.com/speakers.html"&gt;conference abstracts&lt;/a&gt;.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Come and learn how to&lt;/div&gt;&lt;div&gt;&lt;ul&gt;&lt;li&gt;make data evade from {vpn, ipsec, tor...}-protected networks&lt;/li&gt;&lt;li&gt;dynamically weaken strong cryptosystem for a limited period of time only (dynamic trapdoors) to enable easier cryptanalysis&lt;/li&gt;&lt;li&gt;how mathematical trapdoors could also be imagined and implemented.&lt;/li&gt;&lt;/ul&gt;Have a nice week end&lt;/div&gt;&lt;div&gt;Regards&lt;/div&gt;&lt;div&gt;E.F.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6281858739286835733-8686538012983103766?l=cvo-lab.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/8686538012983103766'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/8686538012983103766'/><link rel='alternate' type='text/html' href='http://cvo-lab.blogspot.com/2011/03/cansecwest-2011.html' title='CanSecWest 2011'/><author><name>Eric Filiol</name><uri>http://www.blogger.com/profile/04835548005201063894</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/-X0IVCfnSjNo/TrmrvRiBBaI/AAAAAAAAADY/5fPBjidBQfk/s220/shadow_runner.jpeg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6281858739286835733.post-3294820625914116068</id><published>2011-03-05T02:58:00.000-08:00</published><updated>2011-03-05T03:03:46.487-08:00</updated><title type='text'>Stuxnet conference</title><content type='html'>&lt;span style="font-style:italic;"&gt;Hi to all&lt;/span&gt;/bonjour a tous&lt;br /&gt;&lt;br /&gt;Here is the video teaser of the &lt;a href="http://nanojv.wordpress.com/2011/02/18/stuxnet-pandoras-box-or-stroke-of-genius/"&gt;Stuxnet conference&lt;/a&gt; on March 8th, 2011. &lt;div&gt;&lt;br /&gt;&lt;object style="height: 390px; width: 640px" width="640" height="390"&gt;&lt;param name="movie" value="http://www.youtube.com/v/diECE180IcU?version=3"&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;param name="allowScriptAccess" value="always"&gt;&lt;embed src="http://www.youtube.com/v/diECE180IcU?version=3" type="application/x-shockwave-flash" allowfullscreen="true" allowscriptaccess="always" width="640" height="390"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Voici la vidéo d'annonce de la &lt;a href="http://nanojv.wordpress.com/2011/02/22/stuxnet-boite-pandore-coup-genie-0001/"&gt;conférence Stuxnet&lt;/a&gt; à Paris le 8 mars 2011.&lt;div&gt;&lt;br /&gt;&lt;object style="height: 390px; width: 640px" width="640" height="390"&gt;&lt;param name="movie" value="http://www.youtube.com/v/xfJz-oFdxSE?version=3"&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;param name="allowScriptAccess" value="always"&gt;&lt;embed src="http://www.youtube.com/v/xfJz-oFdxSE?version=3" type="application/x-shockwave-flash" allowfullscreen="true" allowscriptaccess="always" width="640" height="390"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;&lt;br /&gt;Regards/Salutations&lt;br /&gt;&lt;br /&gt;E.F.&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6281858739286835733-3294820625914116068?l=cvo-lab.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/3294820625914116068'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/3294820625914116068'/><link rel='alternate' type='text/html' href='http://cvo-lab.blogspot.com/2011/03/stuxnet-conference.html' title='Stuxnet conference'/><author><name>Eric Filiol</name><uri>http://www.blogger.com/profile/04835548005201063894</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/-X0IVCfnSjNo/TrmrvRiBBaI/AAAAAAAAADY/5fPBjidBQfk/s220/shadow_runner.jpeg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6281858739286835733.post-5771445116646707477</id><published>2011-02-24T23:41:00.000-08:00</published><updated>2011-02-24T23:42:04.408-08:00</updated><title type='text'>Android apps Visualization</title><content type='html'>The original article is &lt;a href="http://androguard.blogspot.com/2011/02/android-apps-visualization.html"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6281858739286835733-5771445116646707477?l=cvo-lab.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://androguard.blogspot.com/2011/02/android-apps-visualization.html' title='Android apps Visualization'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/5771445116646707477'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/5771445116646707477'/><link rel='alternate' type='text/html' href='http://cvo-lab.blogspot.com/2011/02/android-apps-visualization.html' title='Android apps Visualization'/><author><name>Anthony Desnos</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-6281858739286835733.post-2548041952425545011</id><published>2011-02-01T23:07:00.000-08:00</published><updated>2011-02-01T23:10:04.321-08:00</updated><title type='text'>Libperseus now in Ruby</title><content type='html'>Hi &lt;br /&gt;The Perseus library  is now available as a Ruby binding written by Fabien Jobin.&lt;br /&gt; It is based on &lt;a href="https://github.com/ffi/ffi"&gt;ffi&lt;/a&gt;. &lt;br /&gt;&lt;br /&gt;The archive contains two files:&lt;br /&gt;  * ffi-perseus.rb&lt;br /&gt;  * perseus_test.rb&lt;br /&gt;&lt;br /&gt;The binding is made by ffi-perseus. It contains four functions only (to make its&lt;br /&gt;use as simple as possible):&lt;br /&gt;  *  perseus_init&lt;br /&gt;  *  perseus_code &lt;br /&gt;  *  perseus_decode&lt;br /&gt;  *  perseus_destroy&lt;br /&gt;as well as the parameter structure.&lt;br /&gt;&lt;br /&gt;The perseus_test.rb file shows how to use everything.&lt;br /&gt;&lt;br /&gt;Have fun with it&lt;br /&gt;E.F.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6281858739286835733-2548041952425545011?l=cvo-lab.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/2548041952425545011'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/2548041952425545011'/><link rel='alternate' type='text/html' href='http://cvo-lab.blogspot.com/2011/02/libperseus-now-in-ruby.html' title='Libperseus now in Ruby'/><author><name>Eric Filiol</name><uri>http://www.blogger.com/profile/04835548005201063894</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/-X0IVCfnSjNo/TrmrvRiBBaI/AAAAAAAAADY/5fPBjidBQfk/s220/shadow_runner.jpeg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6281858739286835733.post-8269588120640506909</id><published>2011-01-29T02:16:00.001-08:00</published><updated>2011-01-31T00:43:58.974-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Perseus'/><category scheme='http://www.blogger.com/atom/ns#' term='Java'/><category scheme='http://www.blogger.com/atom/ns#' term='Python'/><title type='text'>libperseus 1.0.1 (python + java binding)</title><content type='html'>Hi !&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;We have updated &lt;a href="http://code.google.com/p/libperseus/"&gt;libperseus library&lt;/a&gt;, and now you can use it with python (with ctypes) and java (with jni). The new stable version is now &lt;a href="http://code.google.com/p/libperseus/downloads/detail?name=libperseus-1.0.1.tgz"&gt;available&lt;/a&gt;.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;So, if you would like to use &lt;a href="http://cvo-lab.blogspot.com/2011/01/perseus-library-released.html"&gt;Perseus technology&lt;/a&gt;, the first thing to do is to compile the library :&lt;/div&gt;&lt;pre class="prettyprint"&gt;desnos@cvo:~/$ tar xvzf libperseus-1.0.1.tgz&lt;br /&gt;desnos@cvo:~/$ cd libperseus-1.0.1&lt;br /&gt;desnos@cvo:~/libperseus-1.0.1/$ make&lt;br /&gt;desnos@cvo:~/libperseus-1.0.1/$&lt;/pre&gt;&lt;div&gt;To use Perseus with &gt;= Python 2.5, you must have the shared library in your path and the perseus python module (see the "python" directory for examples) which encapsulate all stuff.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;The first thing to do is to create a new Perseus object, with four float (0.0 to 1.0) numbers to generate noise (if you don't specify these numbers, the module will do it)  :&lt;/div&gt;&lt;pre class="prettyprint"&gt;from random import random&lt;br /&gt;from perseus import Perseus&lt;br /&gt;&lt;br /&gt;p = Perseus(aleas=[ random() for i in range(0,4) ])&lt;/pre&gt;&lt;div&gt;and after you can code or decode your string with the code and decode methods of the Perseus object :&lt;/div&gt;&lt;pre class="prettyprint"&gt;encoded_data = p.code( "CVO BLOGSPOT" )&lt;br /&gt;decoded_data = p.decode( encoded_data )&lt;br /&gt;&lt;/pre&gt;&lt;div&gt;About the java binding (see the "java" directory for examples) , we have written a class to use it more easily. But the first thing to do before is to compile it  (you must edit the Makefile to setup the jni headers of your java installation : JAVA_INCLUDE) :&lt;/div&gt;&lt;pre class="prettyprint"&gt;desnos@cvo:~/libperseus-1.0.1/java/$ make&lt;/pre&gt;Next you can create a Perseus object (as in the Python module, you can specify or not the noise numbers) into a new class file :&lt;div&gt;&lt;pre class="prettyprint"&gt;Perseus p = new Perseus();&lt;/pre&gt;And you can use Code and Decode methods of the object :&lt;pre class="prettyprint"&gt;String data = new String( "CVO BLOGSPOT" );&lt;br /&gt;&lt;br /&gt;String encoded_data = p.Code( data );&lt;br /&gt;String decoded_data = p.Decode( encoded_data );&lt;/pre&gt;&lt;/div&gt;&lt;div&gt;Easy, no ? ;)&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Have fun !&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6281858739286835733-8269588120640506909?l=cvo-lab.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/8269588120640506909'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/8269588120640506909'/><link rel='alternate' type='text/html' href='http://cvo-lab.blogspot.com/2011/01/libperseus-101-python-java-binding.html' title='libperseus 1.0.1 (python + java binding)'/><author><name>Anthony Desnos</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-6281858739286835733.post-3739457400398375035</id><published>2011-01-04T07:38:00.000-08:00</published><updated>2011-01-04T07:41:48.579-08:00</updated><title type='text'>Andromede library available</title><content type='html'>&lt;div style="text-align: justify;"&gt;Hi to all&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;The Andromede library (stable version 0.2.0) has just been released on &lt;a href="http://code.google.com/p/andromeda/"&gt;code.google.com&lt;/a&gt;. This library implements a secure version of bittorrent protocol protected with the Perseus technology. You can now exchange your torrent files without fearing to be eavesdropped.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;The How-to in English should be available soon.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Have fun with this library&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;E.F.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6281858739286835733-3739457400398375035?l=cvo-lab.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/3739457400398375035'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/3739457400398375035'/><link rel='alternate' type='text/html' href='http://cvo-lab.blogspot.com/2011/01/andromede-library-available.html' title='Andromede library available'/><author><name>Eric Filiol</name><uri>http://www.blogger.com/profile/04835548005201063894</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/-X0IVCfnSjNo/TrmrvRiBBaI/AAAAAAAAADY/5fPBjidBQfk/s220/shadow_runner.jpeg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6281858739286835733.post-2621461189002092268</id><published>2011-01-03T23:40:00.000-08:00</published><updated>2011-01-03T23:47:53.156-08:00</updated><title type='text'>Perseus library released</title><content type='html'>Hi to all,&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;The PERSEUS library has just been released in its first stable version 1.0.0. You can find the source code &lt;a href="http://code.google.com/p/libperseus/"&gt;here&lt;/a&gt; and the extended version of the reference paper (presented at the iAWACS 2010 conference) &lt;a href="http://arxiv.org/abs/1101.0057"&gt;here&lt;/a&gt;.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;A new version of the library is under current development. It should be a major evolution since we managed to design a polynomial time decoding algorithm to replace the classical Viterbi algorithm. This will enable new applications with respect to PERSEUS. At the present time we intend to release in 2011:&lt;/div&gt;&lt;div&gt;&lt;ul&gt;&lt;li style="text-align: justify;"&gt;VoIP platforms protected with PERSEUS.&lt;/li&gt;&lt;li style="text-align: justify;"&gt;Android app to protect voice and sms communications.&lt;/li&gt;&lt;li style="text-align: justify;"&gt;File protection on hard disk.&lt;/li&gt;&lt;/ul&gt;We are about to release the Andromede library (end of January) which protect torrent protocol with PERSEUS. &lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Have a happy new year 2011&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;E.F.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6281858739286835733-2621461189002092268?l=cvo-lab.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/2621461189002092268'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/2621461189002092268'/><link rel='alternate' type='text/html' href='http://cvo-lab.blogspot.com/2011/01/perseus-library-released.html' title='Perseus library released'/><author><name>Eric Filiol</name><uri>http://www.blogger.com/profile/04835548005201063894</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/-X0IVCfnSjNo/TrmrvRiBBaI/AAAAAAAAADY/5fPBjidBQfk/s220/shadow_runner.jpeg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6281858739286835733.post-5101706227576659212</id><published>2010-12-04T09:29:00.000-08:00</published><updated>2010-12-04T09:37:51.948-08:00</updated><title type='text'>Our talk on icons at Malcon 2010 and Clubhack 2010</title><content type='html'>Hi to all&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;We have just given a talk (and also a tutorial) about Windows icons and how a malware attack can pervert and exploit them. We have experimented this -- using a undocument features in Windows -- under Windows 7 (simple user session without any privilege; UAC not allowed).&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;This attack enables to execute malware very easily simply using transparent icons. What are transparent icons ? Well an invisible icon that covers a normal icon. Any click on that latter will apparently lauch the normal, intended application but in fact the invisible icon is used first (executing the malware) than the malware just locate the mouse coordinate and transfers the action to the normal application. Simple, isn'it?&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;While we have presented this technique earlier in 2005 &lt;a href="http://www.springer.com/computer/security+and+cryptology/book/978-2-287-23939-7"&gt;here&lt;/a&gt;, we have extended it and added new atack variant. Any mouse-intoxicated used will be trapped!&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;More on the slides &lt;a href="https://sites.google.com/site/ericfiliol/home/list-of-publications/hackingconferencefiles/slides_icons.pdf?attredirects=0"&gt;here&lt;/a&gt;. &lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Have a nice reading!&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;E.F.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6281858739286835733-5101706227576659212?l=cvo-lab.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/5101706227576659212'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/5101706227576659212'/><link rel='alternate' type='text/html' href='http://cvo-lab.blogspot.com/2010/12/our-talk-on-icons-at-malcon-2010-and.html' title='Our talk on icons at Malcon 2010 and Clubhack 2010'/><author><name>Eric Filiol</name><uri>http://www.blogger.com/profile/04835548005201063894</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/-X0IVCfnSjNo/TrmrvRiBBaI/AAAAAAAAADY/5fPBjidBQfk/s220/shadow_runner.jpeg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6281858739286835733.post-8672399062588641948</id><published>2010-11-26T01:53:00.000-08:00</published><updated>2010-11-26T10:31:17.209-08:00</updated><title type='text'>What the interest to create a malicious registry key? A confirmation of our Hack.lu 2010 paper.</title><content type='html'>Hi to all&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;We have presented a few proof-of-concepts at the Hack.lu 2010 conference (one of the best hacking conferences indeed). The aim was to exploit the concept of trusted macros and trusted locations in both Office and OpenOffice documents (here are the &lt;a href="http://archive.hack.lu/2010/Filiol-Office-Documents-New-Weapons-of-Cyberwarfare-paper.pdf"&gt;technical paper&lt;/a&gt; and the &lt;a href="http://archive.hack.lu/2010/Filiol-Office-Documents-New-Weapons-of-Cyberwarfare-slides.pdf"&gt;slides&lt;/a&gt;; videos of our demos are &lt;a href="http://www.youtube.com/watch?v=tjqqk_FRfdg"&gt;here&lt;/a&gt; and &lt;a href="http://www.youtube.com/watch?v=QD3pItsYHnk"&gt;here&lt;/a&gt;). Through a two-step attack, it is possible to execute macros automatically without triggering any alert or confirmation (from the application and of course from the AV). The only condition is to first create a simple (malicious) registry key during the first step. This kind of attack is very interesting and may have a dramatic impact when considering environments where executing sophisticated binaries is impossible (see our Hack.lu paper).&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;Well this &lt;a href="http://isc.sans.edu/diary.html?storyid=9988"&gt;news &lt;/a&gt; (and also &lt;a href="http://nakedsecurity.sophos.com/2010/11/25/new-windows-zero-day-flaw-bypasses-uac/"&gt;this one&lt;/a&gt;) sheds a new, interesting light on our proof-of-concepts. This extract is quite explicit:&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;span style="font-family:monospace;"&gt;&lt;span style="font-size:120%;"&gt;"&lt;span style="font-style: italic;"&gt;What’s interesting is that the vulnerability exist in a function that queries the registry so in order to exploit this the attacker has to be able to create a special (malicious) registry key. Author of the PoC managed to find such a key that can be created by a normal user on Windows Vista and 7 (so, a user that does not even have any administrative privileges)&lt;/span&gt;.&lt;/span&gt;&lt;/span&gt;"&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;Do still have any doubt about the fact that Microsoft Windows is a wonderful world indeed? But for who?&lt;br /&gt;&lt;br /&gt;E.F.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6281858739286835733-8672399062588641948?l=cvo-lab.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://isc.sans.edu/diary.html?storyid=9988' title='What the interest to create a malicious registry key? A confirmation of our Hack.lu 2010 paper.'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/8672399062588641948'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/8672399062588641948'/><link rel='alternate' type='text/html' href='http://cvo-lab.blogspot.com/2010/11/what-interest-to-create-malicious.html' title='What the interest to create a malicious registry key? A confirmation of our Hack.lu 2010 paper.'/><author><name>Eric Filiol</name><uri>http://www.blogger.com/profile/04835548005201063894</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/-X0IVCfnSjNo/TrmrvRiBBaI/AAAAAAAAADY/5fPBjidBQfk/s220/shadow_runner.jpeg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6281858739286835733.post-5807641181653674367</id><published>2010-11-24T12:10:00.000-08:00</published><updated>2010-11-24T12:18:08.830-08:00</updated><title type='text'>New release of Megiddo Open source cryptographic library</title><content type='html'>Hi to all&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;I have just released the new version of Megiddo (0.4.0) on the relevant &lt;a href="http://code.google.com/p/mediggo/"&gt;code.google&lt;/a&gt; page. This release includes many new things:&lt;/div&gt;&lt;div&gt;&lt;ul&gt;&lt;li style="text-align: justify;"&gt;A new detection program for single encrypted file. Relatively often encryption is performed by using a short cyclic sequence (from a few bytes to a few kilobytes) and to combine it to the plaintext (file, binaries...). It is for instance the case with encrypted malware. The program detect_singlefile.c program enables to detect the length of that cyclic sequence. You have just then to split your encrypted file into chunks of that length and perform the cryptanalysis as explained in the library&lt;/li&gt;&lt;li style="text-align: justify;"&gt;New and very detailed slides explaining how to use the open source library and especially giving interesting examples (drawn from real cases) on how trapdoors can be hidden in encryption systems. The case of dynamic cryptographic trapdoors is also presented.&lt;/li&gt;&lt;/ul&gt;&lt;div style="text-align: justify;"&gt;Have a nice reading and fun by practicing with Megiddo-0.4.0&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;E.F.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6281858739286835733-5807641181653674367?l=cvo-lab.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://code.google.com/p/mediggo/' title='New release of Megiddo Open source cryptographic library'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/5807641181653674367'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/5807641181653674367'/><link rel='alternate' type='text/html' href='http://cvo-lab.blogspot.com/2010/11/new-release-of-megiddo-open-source.html' title='New release of Megiddo Open source cryptographic library'/><author><name>Eric Filiol</name><uri>http://www.blogger.com/profile/04835548005201063894</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/-X0IVCfnSjNo/TrmrvRiBBaI/AAAAAAAAADY/5fPBjidBQfk/s220/shadow_runner.jpeg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6281858739286835733.post-1417503344822356356</id><published>2010-11-24T05:38:00.001-08:00</published><updated>2010-11-24T06:40:44.843-08:00</updated><title type='text'>Welcome to the (C+V)O Lab</title><content type='html'>&lt;div style="text-align: justify; color: rgb(102, 102, 102);"&gt;&lt;span style="font-family:verdana;"&gt;Welcome to the Operational cryptology and computer virology lab blog. You can follow the different activities on this lab. Please feel free to contribute in any constructive way.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;Just a quick summary of the lab research activities: we work on computer, network and information security with the attackers' mind and point of view to provide better protection and defense. Our research topics covers&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;ul  style="text-align: justify; color: rgb(102, 102, 102);font-family:verdana;"&gt;&lt;li&gt;&lt;span lang="en-GB"&gt;&lt;b&gt;Symmetric  encryption&lt;/b&gt;&lt;/span&gt;&lt;span lang="en-GB"&gt;:&lt;/span&gt;&lt;span lang="en-GB"&gt; design  and evaluation of symmetric cryptosystems, &lt;/span&gt;&lt;span lang="en-GB"&gt;design  of cryptosystems with trapdoors (introduction of undetectable  mathematical weaknesses allowing a less complex cryptanalysis for  anyone who has knowledge of the trapdoor), c&lt;/span&gt;&lt;span lang="en-GB"&gt;ryptanalysis  of symmetric cryptosystem based on the combinatorial properties  (weaknesses) of those systems, r&lt;/span&gt;&lt;span lang="en-GB"&gt;econstruction  techniques of unknown algorithms (coding or encryption) using the  intercepted stuff only (encoded streams, encrypted messages)&lt;/span&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;div style="text-align: justify; color: rgb(102, 102, 102);"&gt;  &lt;/div&gt;&lt;div  style="color: rgb(102, 102, 102); text-align: justify;font-family:verdana;"&gt; &lt;ul&gt;&lt;li&gt;&lt;span lang="en-GB"&gt;&lt;b&gt;Analysis   and design of steganographic systems.&lt;/b&gt;&lt;/span&gt;&lt;span lang="en-GB"&gt;   Encrypted data (COMSEC aspect only) exhibit a (too) typical   statistical profile. Consequently any attacker can therefore easily   identify an exchange of encrypted data. It is therefore crucial in   some contexts to hide the very existence (storage, exchange) of   data. It is the role of steganography (hiding the channel by   considering the TRANSEC aspect). From a dual point of view, I am also interested in techniques for detecting   steganographic contents (steganalysis). &lt;/span&gt;&lt;/li&gt;&lt;li&gt; &lt;p style="margin-bottom: 0in;"&gt;&lt;span lang="en-GB"&gt;&lt;b&gt;Computer   virology:&lt;/b&gt;&lt;/span&gt;&lt;span lang="en-GB"&gt; formal    characterization of viral techniques (known and unknown    techniques),&lt;/span&gt;&lt;span lang="en-GB"&gt; study    and design of new malware technologies, formalization    and design of new antiviral techniques, &lt;/span&gt;&lt;span lang="en-GB"&gt;malicious     cryptography and steganography (potential use of encryption and/or  steganographic techniques by Malware and use of malicious codes    for applied cryptanalysis purposes), a&lt;/span&gt;&lt;span lang="en-GB"&gt;nalysis    and Evaluation (passive and active) of antivirus software.&lt;/span&gt;&lt;/p&gt; &lt;/li&gt;&lt;/ul&gt; &lt;/div&gt;&lt;div style="text-align: justify; color: rgb(102, 102, 102);"&gt; &lt;/div&gt;&lt;div  style="color: rgb(102, 102, 102); text-align: justify;font-family:verdana;"&gt; &lt;ul&gt;&lt;li&gt;&lt;b&gt;&lt;span lang="en-GB"&gt;Analysis   and technical studies of the concept of computer warfare&lt;/span&gt;&lt;/b&gt;&lt;/li&gt;&lt;/ul&gt; &lt;/div&gt;Once again, welcome to this blog&lt;br /&gt;&lt;br /&gt;E.F.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6281858739286835733-1417503344822356356?l=cvo-lab.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/1417503344822356356'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6281858739286835733/posts/default/1417503344822356356'/><link rel='alternate' type='text/html' href='http://cvo-lab.blogspot.com/2010/11/welcome-to-cvo-lab.html' title='Welcome to the (C+V)O Lab'/><author><name>Eric Filiol</name><uri>http://www.blogger.com/profile/04835548005201063894</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/-X0IVCfnSjNo/TrmrvRiBBaI/AAAAAAAAADY/5fPBjidBQfk/s220/shadow_runner.jpeg'/></author></entry></feed>
