<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Ruan Müller &#187; trojan</title>
	<atom:link href="http://ruanmuller.com/tag/trojan/feed/" rel="self" type="application/rss+xml" />
	<link>http://ruanmuller.com</link>
	<description>Willing and not afraid to challenge the status quo.</description>
	<lastBuildDate>Wed, 14 Dec 2011 19:57:11 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3</generator>
		<item>
		<title>Canada Post warns of fraudulent email</title>
		<link>http://ruanmuller.com/2010/04/26/canada-post-warns-of-fraudulent-email/</link>
		<comments>http://ruanmuller.com/2010/04/26/canada-post-warns-of-fraudulent-email/#comments</comments>
		<pubDate>Tue, 27 Apr 2010 03:18:27 +0000</pubDate>
		<dc:creator>Ruan</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[canada post]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[scam]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://ruanmuller.com/?p=363</guid>
		<description><![CDATA[Canada Post is warning its customers of a fraudulent email disguised as a delivery notification identifying itself as having been sent from Canada Post. The email states that Canada Post is trying to deliver a package and provides further directions for the recipient to open an email attachment in order to proceed with the package [...]]]></description>
			<content:encoded><![CDATA[<p>Canada Post is warning its customers of a fraudulent email disguised as a delivery notification identifying itself as having been sent from Canada Post. The email states that Canada Post is trying to deliver a package and provides further directions for the recipient to open an email attachment in order to proceed with the package delivery.</p>
<p>Canada Post says the email is  a fake and likely contains a virus or other malware. Recipients are being strongly cautioned against opening the attachment.</p>
<p>Additionally, Canada Post said that if a tracking number is provided in  the email, you can check separately at the agency&#8217;s website. If it comes  up as invalid, then the tracking number is a fake and the email should  be deleted.</p>
<p>Read more at <a href="http://www.news1130.com/news/local/article/48512--computer-virus-posing-as-canada-post-email" target="_blank">News1130</a></p>
<div class="social_bookmark"><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,border=0,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://ruanmuller.com/2010/04/26/canada-post-warns-of-fraudulent-email/&amp;title=Canada+Post+warns+of+fraudulent+email" title="Add 'Canada Post warns of fraudulent email' to digg"><img src="http://ruanmuller.com/wp-content/plugins/social-bookmarking-reloaded/digg.png" title="Add 'Canada Post warns of fraudulent email' to digg" alt="Add 'Canada Post warns of fraudulent email' to digg" border="0" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,border=0,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://slashdot.org/bookmark.pl?title=Canada+Post+warns+of+fraudulent+email&amp;url=http://ruanmuller.com/2010/04/26/canada-post-warns-of-fraudulent-email/" title="Add 'Canada Post warns of fraudulent email' to SlashDot"><img src="http://ruanmuller.com/wp-content/plugins/social-bookmarking-reloaded/slashdot.png" title="Add 'Canada Post warns of fraudulent email' to SlashDot" alt="Add 'Canada Post warns of fraudulent email' to SlashDot" border="0" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,border=0,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.facebook.com/share.php?u=http://ruanmuller.com/2010/04/26/canada-post-warns-of-fraudulent-email/&amp;t=Canada+Post+warns+of+fraudulent+email" title="Add 'Canada Post warns of fraudulent email' to FaceBook"><img src="http://ruanmuller.com/wp-content/plugins/social-bookmarking-reloaded/facebook.png" title="Add 'Canada Post warns of fraudulent email' to FaceBook" alt="Add 'Canada Post warns of fraudulent email' to FaceBook" border="0" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,border=0,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://twitter.com/home?status=http://ruanmuller.com/2010/04/26/canada-post-warns-of-fraudulent-email/" title="Add 'Canada Post warns of fraudulent email' to Twitter"><img src="http://ruanmuller.com/wp-content/plugins/social-bookmarking-reloaded/twitter.png" title="Add 'Canada Post warns of fraudulent email' to Twitter" alt="Add 'Canada Post warns of fraudulent email' to Twitter" border="0" /></a></div>
]]></content:encoded>
			<wfw:commentRss>http://ruanmuller.com/2010/04/26/canada-post-warns-of-fraudulent-email/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>First known Mac botnet distributed as Trojan</title>
		<link>http://ruanmuller.com/2009/04/20/first-known-mac-botnet-distributed-as-trojan/</link>
		<comments>http://ruanmuller.com/2009/04/20/first-known-mac-botnet-distributed-as-trojan/#comments</comments>
		<pubDate>Mon, 20 Apr 2009 23:35:50 +0000</pubDate>
		<dc:creator>Ruan</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[apple]]></category>
		<category><![CDATA[bit torrent]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[mac]]></category>
		<category><![CDATA[osx]]></category>
		<category><![CDATA[p2p]]></category>
		<category><![CDATA[peer]]></category>
		<category><![CDATA[trojan]]></category>

		<guid isPermaLink="false">http://ruanmuller.com/?p=265</guid>
		<description><![CDATA[A piece of malicious software unwittingly shared over a peer-to-peer network in January was the key tool in what security researchers are saying was the first known attempt to create a botnet of Mac computers. Researchers at Symantec say the Trojan, called OSX.Iservice, hid itself in pirated versions of the Apple application iWork &#8217;09 and [...]]]></description>
			<content:encoded><![CDATA[<blockquote><p>A piece of malicious software unwittingly shared over a peer-to-peer network in January was the key tool in what security researchers are saying was the first known attempt to create a botnet of Mac computers.</p>
<p>Researchers at Symantec say the Trojan, called OSX.Iservice, hid itself in pirated versions of the Apple application iWork &#8217;09 and the Mac version of Adobe Photoshop CS4 that were shared on a popular peer-to-peer bittorrent network.</p></blockquote>
<p><a href="http://www.securemac.com/" target="_blank">SecureMac</a> has released a tool to remove the Trojan, and can be downloaded from <a href="http://macscan.securemac.com/files/iServicesTrojanRemovalTool.dmg" target="_blank">here</a>.</p>
<p>Via: <a href="http://www.cbc.ca/consumer/story/2009/04/15/ibotnet-trojan.html" target="_blank">cbc.ca</a></p>
<div class="social_bookmark"><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,border=0,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://ruanmuller.com/2009/04/20/first-known-mac-botnet-distributed-as-trojan/&amp;title=First+known+Mac+botnet+distributed+as+Trojan" title="Add 'First known Mac botnet distributed as Trojan' to digg"><img src="http://ruanmuller.com/wp-content/plugins/social-bookmarking-reloaded/digg.png" title="Add 'First known Mac botnet distributed as Trojan' to digg" alt="Add 'First known Mac botnet distributed as Trojan' to digg" border="0" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,border=0,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://slashdot.org/bookmark.pl?title=First+known+Mac+botnet+distributed+as+Trojan&amp;url=http://ruanmuller.com/2009/04/20/first-known-mac-botnet-distributed-as-trojan/" title="Add 'First known Mac botnet distributed as Trojan' to SlashDot"><img src="http://ruanmuller.com/wp-content/plugins/social-bookmarking-reloaded/slashdot.png" title="Add 'First known Mac botnet distributed as Trojan' to SlashDot" alt="Add 'First known Mac botnet distributed as Trojan' to SlashDot" border="0" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,border=0,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.facebook.com/share.php?u=http://ruanmuller.com/2009/04/20/first-known-mac-botnet-distributed-as-trojan/&amp;t=First+known+Mac+botnet+distributed+as+Trojan" title="Add 'First known Mac botnet distributed as Trojan' to FaceBook"><img src="http://ruanmuller.com/wp-content/plugins/social-bookmarking-reloaded/facebook.png" title="Add 'First known Mac botnet distributed as Trojan' to FaceBook" alt="Add 'First known Mac botnet distributed as Trojan' to FaceBook" border="0" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,border=0,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://twitter.com/home?status=http://ruanmuller.com/2009/04/20/first-known-mac-botnet-distributed-as-trojan/" title="Add 'First known Mac botnet distributed as Trojan' to Twitter"><img src="http://ruanmuller.com/wp-content/plugins/social-bookmarking-reloaded/twitter.png" title="Add 'First known Mac botnet distributed as Trojan' to Twitter" alt="Add 'First known Mac botnet distributed as Trojan' to Twitter" border="0" /></a></div>
]]></content:encoded>
			<wfw:commentRss>http://ruanmuller.com/2009/04/20/first-known-mac-botnet-distributed-as-trojan/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New rogue DHCP server malware</title>
		<link>http://ruanmuller.com/2009/03/16/new-rogue-dhcp-server-malware/</link>
		<comments>http://ruanmuller.com/2009/03/16/new-rogue-dhcp-server-malware/#comments</comments>
		<pubDate>Tue, 17 Mar 2009 06:00:05 +0000</pubDate>
		<dc:creator>Ruan</dc:creator>
				<category><![CDATA[Data Centers]]></category>
		<category><![CDATA[Development]]></category>
		<category><![CDATA[Programming]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Telecommunications]]></category>
		<category><![CDATA[dns]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[SANS]]></category>
		<category><![CDATA[trojan]]></category>

		<guid isPermaLink="false">http://ruanmuller.com/?p=246</guid>
		<description><![CDATA[A bold new type of malware has been identified.  Its attack vector is based on hijacking the DNS settings for devices on a local area network. Any device regardless of operating system that depends on an internal or external name server can be affected. The trojan configures and runs a rogue DHCP daemon on the [...]]]></description>
			<content:encoded><![CDATA[<p>A bold new type of malware has been identified.  Its attack vector is based on hijacking the DNS settings for devices on a local area network. Any device regardless of operating system that depends on an internal or external name server can be affected.</p>
<p>The trojan configures and runs a rogue DHCP daemon on the infected host. Other devices on the same LAN are misled into using name servers settings provided by the trojan DHCP daemon for DNS lookups instead of using the origional configured name servers.</p>
<p>Devices on the network are then sent to fraudulent websites that can be more difficult to identify as imposters since the DNS lookups appear correct.</p>
<p>This is a more advanced attack of a well known vector of attacking a systems hosts file, but by being system agnostic and using the familiar DNS protocol, it is much more effective.</p>
<p>More details can be found at <a href="http://isc.sans.org/diary.html?storyid=6025" target="_blank">SANS</a></p>
<div class="social_bookmark"><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,border=0,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://ruanmuller.com/2009/03/16/new-rogue-dhcp-server-malware/&amp;title=New+rogue+DHCP+server+malware" title="Add 'New rogue DHCP server malware' to digg"><img src="http://ruanmuller.com/wp-content/plugins/social-bookmarking-reloaded/digg.png" title="Add 'New rogue DHCP server malware' to digg" alt="Add 'New rogue DHCP server malware' to digg" border="0" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,border=0,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://slashdot.org/bookmark.pl?title=New+rogue+DHCP+server+malware&amp;url=http://ruanmuller.com/2009/03/16/new-rogue-dhcp-server-malware/" title="Add 'New rogue DHCP server malware' to SlashDot"><img src="http://ruanmuller.com/wp-content/plugins/social-bookmarking-reloaded/slashdot.png" title="Add 'New rogue DHCP server malware' to SlashDot" alt="Add 'New rogue DHCP server malware' to SlashDot" border="0" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,border=0,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.facebook.com/share.php?u=http://ruanmuller.com/2009/03/16/new-rogue-dhcp-server-malware/&amp;t=New+rogue+DHCP+server+malware" title="Add 'New rogue DHCP server malware' to FaceBook"><img src="http://ruanmuller.com/wp-content/plugins/social-bookmarking-reloaded/facebook.png" title="Add 'New rogue DHCP server malware' to FaceBook" alt="Add 'New rogue DHCP server malware' to FaceBook" border="0" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,border=0,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://twitter.com/home?status=http://ruanmuller.com/2009/03/16/new-rogue-dhcp-server-malware/" title="Add 'New rogue DHCP server malware' to Twitter"><img src="http://ruanmuller.com/wp-content/plugins/social-bookmarking-reloaded/twitter.png" title="Add 'New rogue DHCP server malware' to Twitter" alt="Add 'New rogue DHCP server malware' to Twitter" border="0" /></a></div>
]]></content:encoded>
			<wfw:commentRss>http://ruanmuller.com/2009/03/16/new-rogue-dhcp-server-malware/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

