<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Kryptoblog &#187; Elak kod</title>
	<atom:link href="http://www.strombergson.com/kryptoblog/tag/elak-kod/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.strombergson.com/kryptoblog</link>
	<description>Kryptografi och IT-säkerhet på svenska</description>
	<lastBuildDate>Thu, 20 Jan 2011 21:25:55 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.4</generator>
<atom:link rel="hub" href="http://pubsubhubbub.appspot.com"/><atom:link rel="hub" href="http://superfeedr.com/hubbub"/>		<item>
		<title>En Duracellkanin? Nej, en Energizer-trojan</title>
		<link>http://www.strombergson.com/kryptoblog/2010/03/12/en-duracellkanin-nej-en-energizer-trojan/</link>
		<comments>http://www.strombergson.com/kryptoblog/2010/03/12/en-duracellkanin-nej-en-energizer-trojan/#comments</comments>
		<pubDate>Fri, 12 Mar 2010 13:21:28 +0000</pubDate>
		<dc:creator>Joachim Strömbergson</dc:creator>
				<category><![CDATA[Elak kod]]></category>
		<category><![CDATA[Hårdvara]]></category>
		<category><![CDATA[Inbyggda system]]></category>

		<guid isPermaLink="false">http://www.strombergson.com/kryptoblog/?p=1128</guid>
		<description><![CDATA[<p>Batterif&#246;retaget <a href="http://www.energizer.com/Pages/default.aspx">Energizer</a> sl&#228;ppte f&#246;r ett tag sedan en <span class="caps">USB</span>-kopplad batteriladdare kallad Energizer Duo.</p>

	<p><img src="http://www.imaging-resource.com/NPICS1/DUOCHARGER_1_S.JPG" alt="Energizer Duo" /></p>

	<p>F&#246;rutom att ladda via <span class="caps">USB</span> kunde produkten k&#246;ra en liten applikationen p&#229; datorn som visade laddstatus f&#228;&#246;r batterierna.</p>

	<p><img src="http://www.imaging-resource.com/NPICS1/DUOCHARGER_2_S.JPG" alt="Laptop med applikationen." /></p>

	<p>Men det var&#8230;</p>


No related posts.

Related posts brought to you by <a href='http://mitcho.com/code/yarpp/'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[	<p>Batterif&#246;retaget <a href="http://www.energizer.com/Pages/default.aspx">Energizer</a> sl&#228;ppte f&#246;r ett tag sedan en <span class="caps">USB</span>-kopplad batteriladdare kallad Energizer Duo.</p>

	<p><img src="http://www.imaging-resource.com/NPICS1/DUOCHARGER_1_S.JPG" alt="Energizer Duo" /></p>

	<p>F&#246;rutom att ladda via <span class="caps">USB</span> kunde produkten k&#246;ra en liten applikationen p&#229; datorn som visade laddstatus f&#228;&#246;r batterierna.</p>

	<p><img src="http://www.imaging-resource.com/NPICS1/DUOCHARGER_2_S.JPG" alt="Laptop med applikationen." /></p>

	<p>Men det var nu inte det enda som k&#246;rdes n&#228;r laddaren kopplades in. Enligt Symantec kom batteriladdaren med en elak liten trojan. <a href="http://www.symantec.com/connect/blogs/trojan-found-usb-battery-charger-software">Symantec har en l&#228;ngre beskrivning av Energizertrojanen</a> som bla beskriver vad den kunde g&#246;ra:</p>

	<p><blockquote><br />
&#8226;    Download a file<br />
&#8226;    Execute a file<br />
&#8226;    Send a directory listing to the remote attacker<br />
&#8226;    Send files to the remote attacker<br />
&#8226;    Modify the following registry entry:<br />
</blockquote></p>

	<p>Energizer har dragit tillbaka produkten. Det jag undrar &#246;ver &#228;r hur trojanen hittade in i koden till laddaren fr&#229;n f&#246;rsta b&#246;rjan. Hade det varit ett <span class="caps">USB</span>-minne hade det varit en sak, men nu &#228;r det inte det och d&#229; brukar m&#228;ngden minne som finns vara h&#246;gst begr&#228;nsat. M&#228;rkligt.</p>
 <div class="shr-publisher-1128"></div>

<p>No related posts.</p>
<p>Related posts brought to you by <a href='http://mitcho.com/code/yarpp/'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://www.strombergson.com/kryptoblog/2010/03/12/en-duracellkanin-nej-en-energizer-trojan/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Statistik över elak kod i olika typer av filer</title>
		<link>http://www.strombergson.com/kryptoblog/2010/03/09/statistik-over-elak-kod-i-olika-typer-av-filer/</link>
		<comments>http://www.strombergson.com/kryptoblog/2010/03/09/statistik-over-elak-kod-i-olika-typer-av-filer/#comments</comments>
		<pubDate>Tue, 09 Mar 2010 21:47:53 +0000</pubDate>
		<dc:creator>Joachim Strömbergson</dc:creator>
				<category><![CDATA[Elak kod]]></category>
		<category><![CDATA[Internet]]></category>

		<guid isPermaLink="false">http://www.strombergson.com/kryptoblog/?p=1138</guid>
		<description><![CDATA[<p>F-Secures log har en postning med statistik &#246;ver elak kod i olika typer av filformat. Att d&#246;ma av <span class="caps">PDF</span> den klart vanligaste filtypen d&#228;r elak kod f&#246;ljer med.</p>

	<p><img src="http://www.f-secure.com/weblog/archives/targeted_attacks_2008_2009_2010.png" alt="Statistik fr&#229;n F-secure." /></p>

	<p>Det hade naturligtvis varit intressant att se hur vanliga&#8230;</p>


No related posts.

Related posts brought to you by <a href='http://mitcho.com/code/yarpp/'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[	<p>F-Secures log har en postning med statistik &#246;ver elak kod i olika typer av filformat. Att d&#246;ma av <span class="caps">PDF</span> den klart vanligaste filtypen d&#228;r elak kod f&#246;ljer med.</p>

	<p><img src="http://www.f-secure.com/weblog/archives/targeted_attacks_2008_2009_2010.png" alt="Statistik fr&#229;n F-secure." /></p>

	<p>Det hade naturligtvis varit intressant att se hur vanliga resp format &#228;r p&#229; &#246;ver huvud taget. &#196;r det ex s&#229; att <span class="caps">PDF </span>&#228;r vanligaste filtypen d&#228;r elak kod f&#246;ljer med f&#246;r att den &#228;r l&#228;ttast att d&#246;lja kod, eller f&#246;r att det helt enkelt &#228;r den &#246;verl&#228;gset vanligaste filtypen av de j&#228;mf&#246;rda typerna. Oavsett hur det ligger till b&#246;r man nog inse att PDFer (och andra filer) som trillar ner fr&#229;n n&#228;tet kan inneh&#229;lla elakheter.</p>
 <div class="shr-publisher-1138"></div>

<p>No related posts.</p>
<p>Related posts brought to you by <a href='http://mitcho.com/code/yarpp/'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://www.strombergson.com/kryptoblog/2010/03/09/statistik-over-elak-kod-i-olika-typer-av-filer/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Danske Banks hemska webbapplikation</title>
		<link>http://www.strombergson.com/kryptoblog/2008/09/12/danske-banks-hemska-webbapplikation/</link>
		<comments>http://www.strombergson.com/kryptoblog/2008/09/12/danske-banks-hemska-webbapplikation/#comments</comments>
		<pubDate>Fri, 12 Sep 2008 17:18:23 +0000</pubDate>
		<dc:creator>Joachim Strömbergson</dc:creator>
				<category><![CDATA[Dumheter]]></category>
		<category><![CDATA[Elak kod]]></category>

		<guid isPermaLink="false">http://strombergson.com/kryptoblog/?p=558</guid>
		<description><![CDATA[<p>Kollegan Kalle tipsade f&#246;r ett tag sedan om en tr&#229;d p&#229; <a href="http://thedailywtf.com/">DailyWTF</a> om <a href="http://thedailywtf.com/Articles/Sampo-UhOh.aspx">den hemska webbapplikation som Danske Banke introducerade i Finland efter k&#246;pet av Sampo</a>. V&#228;rt att l&#228;sa om man vill se ett IT-projekt som uppenbarligen&#8230;</p>


No related posts.

Related posts brought to you by <a href='http://mitcho.com/code/yarpp/'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[	<p>Kollegan Kalle tipsade f&#246;r ett tag sedan om en tr&#229;d p&#229; <a href="http://thedailywtf.com/">DailyWTF</a> om <a href="http://thedailywtf.com/Articles/Sampo-UhOh.aspx">den hemska webbapplikation som Danske Banke introducerade i Finland efter k&#246;pet av Sampo</a>. V&#228;rt att l&#228;sa om man vill se ett IT-projekt som uppenbarligen gick snett fr&#229;n b&#246;rjan.</p>

	<p><img src="http://img.thedailywtf.com/images/200808/sampo.png" alt="SampoBank" /></p>

	<p>Det finns &#228;ven en Wiki som samlar information om alla hemskheter i <a href="http://kks.cabal.fi/SampoApplet">SampoApplet</a>. Bland detaljerna man kan hitta d&#228;r finns en lista p&#229; vad SampoApplet f&#246;rs&#246;ker samla information om i <span class="caps">GNU</span>/Linux:</p>

	<p><blockquote><br />
/proc/asound/cards<br />
/proc/cpuinfo<br />
/proc/ide0/hda<br />
/proc/ide1/hdc<br />
/proc/ide2/hdb<br />
/proc/ide3/hdd<br />
/proc/ide/hda<br />
/proc/ide/hdb<br />
/proc/ide/hdc<br />
/proc/ide/hdd<br />
/proc/meminfo<br />
/proc/partitions<br />
/proc/pci<br />
/proc/sys/kernel/hostname<br />
/proc/version<br />
</blockquote></p>

	<p>Vad skall banken med information om <span class="caps">CPU</span> och h&#229;rddisk-partitioner till? Motsvarande saker g&#228;ller i Windows och p&#229; Mac.</p>

 <div class="shr-publisher-558"></div>

<p>No related posts.</p>
<p>Related posts brought to you by <a href='http://mitcho.com/code/yarpp/'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://www.strombergson.com/kryptoblog/2008/09/12/danske-banks-hemska-webbapplikation/feed/</wfw:commentRss>
		<slash:comments>9</slash:comments>
		</item>
	</channel>
</rss>

