[00:01.750 --> 00:04.090] For this stupid freaking computer to boot up. [00:08.110 --> 00:10.190] As we're waiting, let's ask a couple questions here. [00:10.470 --> 00:13.430] Is there anyone in the audience here who has actually written a computer virus? [00:13.530 --> 00:13.910] Raise your hand. [00:16.190 --> 00:16.670] Okay. [00:17.230 --> 00:22.250] Now, how many federal officers in the audience are now looking at the person who wrote the computer virus? [00:23.090 --> 00:23.570] Okay. [00:24.470 --> 00:27.890] We will later. [00:28.650 --> 00:31.870] Now, how many hackers are actually looking at the federal officers and making a note? [00:36.030 --> 00:37.050] I'm just messing with you, guy. [00:40.760 --> 00:41.880] I did that at DEFCON. [00:42.180 --> 00:43.140] That was really interesting. [00:45.200 --> 00:48.100] DEFCON, it's kind of cool because they have the... How many people have gone to DEFCON? [00:48.240 --> 00:48.780] Raise your hand real quick. [00:49.680 --> 00:50.440] Yeah, rock on. [00:51.080 --> 00:53.660] DEFCON, they have a thing called Spot the Fed, which is really kind of neat. [00:54.660 --> 01:02.860] And I don't play it anymore because usually, like, the night before the conference, the Fed are all buying us alcohol in the bars. [01:03.180 --> 01:04.540] So it's kind of not really fair. [01:04.740 --> 01:05.920] It's like, you know, he's a Fed. [01:06.300 --> 01:11.320] Because he was buying us drinks all night last night and asking us for our opinions and showing us his badge. [01:14.880 --> 01:15.300] Duh. [01:17.580 --> 01:19.100] Besides, look at his freaking shoes. [01:21.260 --> 01:22.960] I have way too much shit on this. [01:25.200 --> 01:26.720] Get rid of half of this crap here. [01:30.440 --> 01:34.820] I know this is like a shoot me in the foot question, but how many people out there use Windows? [01:35.480 --> 01:36.400] And don't be embarrassed. [01:36.880 --> 01:37.620] Raise your hand. [01:38.500 --> 01:41.040] Okay, let me ask this question real quick here. [01:42.640 --> 01:43.100] Yeah. [01:49.560 --> 01:50.920] Yeah, maybe that right now. [01:51.820 --> 01:52.920] Oops, that's not what I wanted. [02:00.310 --> 02:01.030] Momentary pot. [02:04.640 --> 02:05.560] Yay, we're live. [02:06.840 --> 02:12.560] Okay, is there anyone in the audience who's never, ever used Windows in their life or a Macintosh? [02:12.680 --> 02:13.220] Raise your hand. [02:16.560 --> 02:20.020] All right, someone who's never used, used Windows, but may have used a Macintosh. [02:21.240 --> 02:22.800] Okay, I like this one person. [02:23.000 --> 02:24.920] So you used a Mac, but never used a Windows machine? [02:25.200 --> 02:26.640] No, no, no, no, no, I used both. [02:27.060 --> 02:27.660] Okay, you used both. [02:27.940 --> 02:28.460] Okay, that's right. [02:28.700 --> 02:29.460] Then why did you raise your hand? [02:29.820 --> 02:30.280] I don't know. [02:32.480 --> 02:35.140] The only thing I can say is, you know, less crap, more fruits and vegetables. [02:38.260 --> 02:44.500] One of the big problems here, just kind of do a brief intro here before we get into the slide presentation and the actual talk here. [02:46.080 --> 02:50.860] First of all, my name is Robert Lupo, known by a lot of you as Virus. [02:51.880 --> 02:52.580] This is Marty. [02:52.680 --> 02:53.940] Marty's going to be interjecting here. [02:54.500 --> 02:58.440] He was nice enough to work with me on doing some rewrites on the slides. [02:58.720 --> 03:01.240] He's a buddy of mine, helped me out at H2K. [03:02.320 --> 03:04.000] Who here was at H2K? [03:05.160 --> 03:07.480] All right, have you guys, how many of you guys saw my talk? [03:08.440 --> 03:09.740] Okay, we added a few things. [03:09.760 --> 03:11.780] So it's not going to be the exact same freaking talk. [03:12.300 --> 03:16.820] I'll also like to point out that this will be the last year that I will be giving this lecture. [03:18.420 --> 03:23.480] The next lecture that's currently being written right now is an advanced computer virus course. [03:24.460 --> 03:32.360] It's about an hour-long class I'll be giving at the conferences with actual code examples and explanation of what the code is actually doing. [03:33.800 --> 03:34.980] So this is it. [03:35.100 --> 03:36.820] You're the last people in New York to see this. [03:38.580 --> 03:40.700] Where was I before I completely lost my mind? [03:40.960 --> 03:41.840] I don't remember. [03:42.420 --> 03:42.900] That's okay. [03:45.360 --> 03:51.400] One of the things I want to talk to you guys about is, most of the computer virus lecture is based on Windows. [03:52.640 --> 03:59.540] And I know in the hacker community and especially in the network security community, we all like to sit there and say, you know, Windows blows. [03:59.920 --> 04:00.560] It sucks. [04:01.220 --> 04:03.800] Well, face the facts, Windows is pretty much here to stay. [04:03.940 --> 04:06.280] It's the most prevalent operating system in the world. [04:06.600 --> 04:08.680] And it's something we all have to face and use. [04:09.480 --> 04:12.400] Which is why there's so many freaking viruses written for it. [04:12.400 --> 04:15.480] Well, there's actually other reasons why there's so many freaking viruses written for it. [04:15.560 --> 04:17.820] But we won't get into that can of worms. [04:19.180 --> 04:27.300] When things start to become a little bit more prevalent, you know, in the operating system worlds, more viruses are going to be written for them. [04:28.520 --> 04:30.280] A couple years back, I made the prediction. [04:30.440 --> 04:35.820] I said, you know, as people will start using more and more Linux operating systems, viruses will start coming out for them. [04:37.060 --> 04:38.720] Can someone tell me true or false? [04:38.920 --> 04:40.340] There's viruses out there now for Linux. [04:40.900 --> 04:41.380] True. [04:44.430 --> 04:44.910] Why? [04:46.570 --> 04:47.430] Can I... [04:47.430 --> 04:48.050] What? [04:49.550 --> 04:53.650] Because it's becoming a more prevalent operating system where there's more people using it. [04:53.930 --> 04:56.530] The whole purpose of a virus is to be able to replicate itself. [04:56.670 --> 05:00.150] A virus is completely and utterly useless if it cannot replicate from one system to another. [05:00.770 --> 05:04.390] Which is why you don't see a whole lot of, like, Macintosh viruses that much. [05:06.450 --> 05:08.890] You know, I used to have a t-shirt that I wore a long time ago. [05:09.070 --> 05:10.530] It said, friends don't let friends buy Mac. [05:14.120 --> 05:17.200] And when they went to OS X, which is based on a free BSD OS. [05:19.440 --> 05:25.340] All right, now, if I'm going to admit it, I'll buy a Mac based on the fact that I now have command line. [05:26.600 --> 05:28.000] It's all about command line. [05:28.500 --> 05:29.860] All right, we're going to kick on here. [05:30.620 --> 05:32.380] You see that logo there is NextGen. [05:32.520 --> 05:33.920] It's NextGen Professional Services. [05:34.840 --> 05:36.620] It's a consulting group out of California. [05:37.060 --> 05:38.200] I'm a partner in the group. [05:38.460 --> 05:39.120] Great group. [05:39.300 --> 05:42.420] They do IT solutions, network security audits, all kinds of cool stuff. [05:42.580 --> 05:43.700] So that's my plug. [05:44.000 --> 05:44.080] Yay. [05:45.180 --> 05:57.160] That's my website there, v1ru5.org, and personal email is v1ru5 at disk.org, and business email is robert.lupo at nextgenps.com. [05:58.000 --> 05:59.920] Yeah, and I can see you all writing that down. [06:01.880 --> 06:03.460] All right, what's going to be covered in this talk? [06:03.560 --> 06:04.460] What is malicious code? [06:05.160 --> 06:14.380] Boot sectors, multipartite, violent vectors, macro, Trojan Horse, fakes, VBS, Visual Basic Scripts, also code, and computer viruses in the future? [06:15.640 --> 06:20.080] Now, each year I kind of discuss what I feel is going to happen in the future dealing with computer viruses. [06:20.460 --> 06:24.340] And it's kind of scary when some of my predictions actually start coming true. [06:25.260 --> 06:26.340] That's kind of disturbing. [06:26.820 --> 06:31.280] I talk to a lot of different people who have been, like, who are ex-virus writers. [06:31.620 --> 06:33.400] Some of them are current virus writers. [06:35.060 --> 06:37.380] I don't condone virus writing. [06:37.640 --> 06:38.500] I really don't. [06:39.560 --> 06:45.660] I'm a firm believer that no one has a right to actually put out some hostile code that can maliciously destroy other people's lives. [06:46.600 --> 06:59.580] People don't take into consideration that when a virus hits a company, like a startup, and people are invested their whole life savings into a company, and it completely and utterly trashed their systems, and they lose everything, and they go under, and they're living on the street, [06:59.740 --> 07:01.180] and they thought it was a joke. [07:02.060 --> 07:03.300] You're ruining people's lives. [07:04.720 --> 07:05.720] It's not very cool. [07:06.900 --> 07:15.940] If you want to write stuff and do experimentations on your own systems, you want to check out, you know, artificial intelligence with viruses, cool, rock on. [07:17.800 --> 07:21.600] Doing harmful payloads doesn't make you elite, doesn't make you cool. [07:22.240 --> 07:25.100] You know, the only ones who are going to think you're cool is your script kiddie buddies. [07:26.340 --> 07:27.160] It's just not cool. [07:28.060 --> 07:28.760] All right, enough preaching. [07:30.320 --> 07:31.940] Definition of malicious code malware. [07:32.640 --> 07:37.760] Any program or script written specifically to execute on behalf of the user without the user's permission or knowledge. [07:38.360 --> 07:39.340] God, that sounds like Windows. [07:39.700 --> 07:41.820] I mean, bi-ray, worms, and... [07:41.820 --> 07:42.480] I didn't say that. [07:43.000 --> 07:44.940] Horses are all examples of malicious code. [07:45.740 --> 07:46.920] Well, it does, doesn't it? [07:47.160 --> 07:47.800] Doesn't it sound like... [07:47.800 --> 07:48.660] Okay, I'm sorry. [07:49.620 --> 07:51.500] Gee, I wonder if we can actually do a class action suit. [07:51.980 --> 07:52.260] Never mind. [07:52.360 --> 07:52.960] We'll go there later. [07:57.060 --> 07:57.540] That's Windows. [07:59.300 --> 08:01.940] I knock it, but you know, I make my living protecting Windows. [08:02.200 --> 08:03.520] And I tell you, that's not an easy job. [08:04.420 --> 08:05.200] What is a virus? [08:05.760 --> 08:06.760] I know, I'm just... [08:07.220 --> 08:07.860] I'm on a roll. [08:08.120 --> 08:09.100] That's why there's butter on my pants. [08:09.100 --> 08:10.380] All right, what is a virus? [08:11.180 --> 08:14.260] Parasitic self-replicating code that attaches itself to a host. [08:14.620 --> 08:20.080] Host can be floppy boot records, master boot records, partition boot records, DOS boot records, binary files, and data files. [08:20.380 --> 08:23.680] Docs, excels, PTs, et cetera, yadda, yadda, yadda. [08:25.060 --> 08:27.000] Viruses are getting even more relevant. [08:27.340 --> 08:31.760] Who heard about the virus that actually infects JPEG files? [08:35.240 --> 08:40.540] How many people know that there was actually a virus about four years ago that did the same thing? [08:42.160 --> 08:43.760] Yeah, they didn't get any press. [08:44.560 --> 08:45.800] Because it wasn't replicating. [08:46.200 --> 08:53.700] It was something that would actually infect the JPEG and it would work fine if it was on your system, but it had no way of replicating off the system. [08:54.360 --> 08:56.820] And it was spread mostly by people exchanging the file. [08:56.820 --> 09:03.540] So, in other words, if you got a JPEG that was infected with that original virus, it would actually infect all your JPEGs and make them so you couldn't see them anymore. [09:04.300 --> 09:08.640] And then, you know, as long as you switch that JPEG to another person, then they can get infected. [09:08.640 --> 09:09.720] But it wouldn't replicate itself. [09:09.760 --> 09:11.940] So, it pretty much died really quick. [09:12.440 --> 09:13.600] It was an interesting concept. [09:14.120 --> 09:18.640] I used to work for an antivirus company several years back as a virus researcher. [09:18.860 --> 09:21.260] And we won't mention the name of the antivirus company. [09:27.280 --> 09:30.440] And it was actually kind of a cool place to work. [09:30.580 --> 09:31.440] I really enjoyed it. [09:31.520 --> 09:36.580] They had a special section for the virus researchers that were actually walled off. [09:36.680 --> 09:44.660] And there was a sign there that says warning anyone entering this area can actually may view things that are unacceptable on computer screens. [09:45.880 --> 09:48.380] And, you know, beware that you're entering in this area on your wrist. [09:48.380 --> 09:52.220] And it was done specifically for the sexual harassment issues. [09:52.840 --> 09:58.740] Because some of the viruses would actually throw up naked pictures of people's ex-girlfriends with, like, really bad slander things. [09:58.960 --> 10:01.840] You know, here's this bitch that, you know, cheated on me. [10:01.900 --> 10:03.480] And here's her phone number type things, you know. [10:03.700 --> 10:05.900] So, you know, you start to, you know, decoding these viruses. [10:06.140 --> 10:07.580] All of a sudden, there's this picture of this lady there. [10:07.680 --> 10:08.320] And you're like, okay. [10:08.560 --> 10:12.540] And, you know, some of the gals that worked in the office were kind of offended by that. [10:12.620 --> 10:15.260] So, they had to put a sign up there going, if you walk in here and you see something, that's offensive. [10:15.700 --> 10:21.760] Because a lot of the old time viruses, like the food sector viruses, you know, it was like, you know, you freaking suck, man. [10:22.560 --> 10:27.300] And they would yell out about, you know, how much people, like, blue chunks and all that stuff. [10:27.780 --> 10:29.100] And some people are very offended. [10:29.220 --> 10:31.140] It's like, oh my god, I saw the word fuck on the screen. [10:31.300 --> 10:32.580] I just, I just feel so offended. [10:33.120 --> 10:33.940] Ten million dollars. [10:34.580 --> 10:37.230] Ten million dollars. [10:37.810 --> 10:39.190] You know, you just want to look at it going, fuck. [10:39.670 --> 10:39.950] Twenty. [10:42.630 --> 10:43.270] What's a worm? [10:43.410 --> 10:47.350] Self-replicating, self-contained program or code that is not parasitic. [10:47.550 --> 10:51.390] Worms do not infect master food records, food suckers, binary files, and macros. [10:52.130 --> 10:55.190] This is almost pretty much verbatim right off the RFCs. [10:55.590 --> 10:59.030] Anyone there actually read the RFCs dealing with viruses and stuff? [10:59.390 --> 10:59.770] Yay, nay? [11:00.390 --> 11:01.870] Does anybody know what an RFC is? [11:02.730 --> 11:03.490] Okay, yeah. [11:03.630 --> 11:06.250] Raise your hand if you know what an RFC is so I don't feel like I'm talking to the wall. [11:06.410 --> 11:07.070] Yay, okay. [11:07.550 --> 11:10.310] Yeah, it's funny because people are going, didn't you read that RFC? [11:10.390 --> 11:13.330] I said, yeah, there's only what, 50,000 freaking RFCs out there? [11:13.430 --> 11:14.270] Yeah, I read all of them. [11:14.450 --> 11:15.850] I have no social life, you know? [11:16.770 --> 11:18.070] So that's what a girl looks like. [11:18.210 --> 11:18.350] Okay. [11:19.930 --> 11:21.630] I've read about those on the RFCs. [11:25.010 --> 11:28.630] Boot sector viruses, how they work, what to look for, ways to remove them. [11:29.470 --> 11:35.750] Now, this is kind of one of the reasons why I'm kind of retiring this talk because boot sector viruses are kind of going wayside. [11:35.850 --> 11:38.230] There's not a lot of boot sector virus infections out there anymore. [11:38.230 --> 11:43.270] A lot of people are using like Windows 2000, XP, and other Unix operating systems. [11:44.610 --> 11:47.970] Here's a really quick true or false question here. [11:48.350 --> 11:49.570] True or false? [11:49.730 --> 11:55.910] It is impossible to infect an NTFS partitioned drive with a boot sector virus. [11:56.950 --> 11:58.330] How many think it's true? [11:58.590 --> 11:59.170] Raise your hand. [12:00.530 --> 12:01.650] How many think it's false? [12:01.850 --> 12:02.450] Raise your hand. [12:03.370 --> 12:04.010] All right. [12:04.550 --> 12:05.930] I need a volunteer to tell me why it's false. [12:07.570 --> 12:08.430] Why is it false? [12:08.990 --> 12:09.650] NTFS file. [12:10.530 --> 12:10.890] Wrong. [12:12.910 --> 12:13.690] But you're close. [12:14.670 --> 12:14.830] Okay. [12:15.770 --> 12:22.150] Realistically, under normal circumstances, it is impossible to infect an NTFS drive with a boot sector virus. [12:22.150 --> 12:26.710] Because if you put a floppy disk in that has a boot sector virus, it does not see a drive. [12:26.870 --> 12:27.610] It does not see a drive. [12:27.710 --> 12:28.510] It can't infect the drive. [12:29.170 --> 12:30.970] So under normal circumstances, yes. [12:31.150 --> 12:32.170] It would be a true situation. [12:32.790 --> 12:35.350] I actually got a job because a guy challenged me on that. [12:35.350 --> 12:36.850] And he goes, is it true or false? [12:36.910 --> 12:38.310] I said, you can do it. [12:38.390 --> 12:39.150] He goes, no, you can't. [12:39.210 --> 12:39.950] I said, yeah, you can. [12:40.030 --> 12:41.410] He goes, if you can do it, I'll give you the job. [12:41.810 --> 12:42.830] I said, okay. [12:43.230 --> 12:43.930] Give me 24 hours. [12:44.430 --> 12:57.990] And what we ended up doing was I built an NT boot disk using FAT32, using all the NTFS files that are required to actually see the drive. [12:58.430 --> 13:03.150] Well, being that it's a FAT diskette, I was able to infect it with the New York boot virus. [13:03.290 --> 13:03.770] New York boot? [13:03.890 --> 13:04.530] Hey, how appropriate. [13:07.050 --> 13:11.030] And put the disk in, I was able to see the drive, and it completely blew out NT. [13:11.650 --> 13:13.290] I mean, completely blew out NT. [13:13.570 --> 13:14.550] There was no recovery. [13:15.290 --> 13:16.250] And I got the job. [13:19.490 --> 13:20.970] And then I had to fix his computer. [13:24.050 --> 13:26.050] And the person, he goes, now you have to fix my system. [13:26.110 --> 13:27.090] I said, this is your personal system? [13:27.210 --> 13:27.990] I said, and he goes, yeah. [13:28.110 --> 13:30.730] And I said, why did you let me do this to your personal system? [13:31.010 --> 13:32.170] He goes, well, I didn't think you could do it. [13:32.170 --> 13:35.590] And I said, if I came here telling you I was going to be able to do it, why did you let me do this? [13:35.590 --> 13:36.690] He goes, I said, all right, great. [13:36.890 --> 13:37.710] Give me your backup tapes. [13:37.890 --> 13:39.290] And he kind of... [13:40.050 --> 13:42.790] The deer in the headlights thing was like, I don't have your backup tapes. [13:42.850 --> 13:43.850] I said, do you have something there you needed? [13:44.010 --> 13:44.570] I said, yeah. [13:44.670 --> 13:45.170] He goes, not anymore. [13:47.650 --> 13:48.610] Do I still get to keep the job? [13:50.710 --> 13:52.070] All right, here's how... [13:52.070 --> 13:54.830] I want you to understand how a boot sector virus works. [13:55.010 --> 13:55.750] And everybody... [13:55.750 --> 13:59.390] How many people here really don't understand exactly what the boot sector, how it works? [13:59.470 --> 13:59.790] It's cool. [13:59.890 --> 14:00.290] Raise your hand. [14:00.370 --> 14:01.410] This is all about education, guys. [14:01.650 --> 14:02.210] All right, raise your hand. [14:02.370 --> 14:02.630] Hi. [14:03.130 --> 14:05.350] Yeah, raise the redhead's hand a little bit higher. [14:05.350 --> 14:06.570] Yeah, you with the Mohawk. [14:06.690 --> 14:07.330] Raise your hand higher. [14:07.790 --> 14:08.150] Okay. [14:08.530 --> 14:09.130] It's cool. [14:09.310 --> 14:10.410] This is all about education, guys. [14:11.630 --> 14:13.550] The boot sector is divided up into three sections. [14:13.750 --> 14:19.230] We have the code section, which is basically the instructions that actually tell the system how to boot up. [14:19.370 --> 14:22.350] You know, remember the old DAW states when you get like syntax error? [14:22.850 --> 14:27.570] Remember those when you fucked up and you got this like little syntax error or these little messages popped up? [14:27.690 --> 14:28.990] That was all in the code there. [14:29.070 --> 14:31.030] These were all the things, the instruction codes. [14:31.390 --> 14:34.410] The fat partition information has all your directory structure in there. [14:34.410 --> 14:39.790] You know, it tells the computer, you know, where to find all your files and where to find... [14:39.790 --> 14:41.270] It's like the mini map of your drive. [14:41.510 --> 14:43.230] You know, this is where all the directory structures are. [14:43.330 --> 14:44.910] This is where all the files are and yada, yada, yada, yada. [14:45.710 --> 14:47.870] The marker code is 55AA. [14:48.970 --> 14:51.290] That's what tells the computer, start here. [14:53.510 --> 14:54.690] Here, you get to press the button. [14:57.310 --> 14:58.490] Yeah, good job. [14:59.410 --> 15:00.330] That's the one I wanted. [15:00.610 --> 15:06.150] Alright, the virus first copies the boot code on the drive to a different sector on the media. [15:06.150 --> 15:11.470] So all the primary boot code that's used for actually booting up the system is actually copied over to a different sector. [15:11.710 --> 15:14.270] It then copies its code over the boot code. [15:14.750 --> 15:17.170] The end of the virus code then points to the new sector. [15:20.270 --> 15:25.810] The FAT partition info on the NBR holds the data in the partition info of the disk. [15:26.050 --> 15:31.450] Some viruses encrypt this info, making it impossible to retrieve your data if the virus is removed incorrectly. [15:31.870 --> 15:34.670] One of my absolute favorite viruses in the whole world is the monkey bee. [15:35.090 --> 15:39.830] I mean, people actually know the monkey bee or played with it or been hit by it. [15:40.730 --> 15:41.930] More hands are coming up. [15:41.930 --> 15:44.530] Alright, the monkey bee is so freaking cool. [15:44.670 --> 15:45.510] Here's what the monkey bee did. [15:46.090 --> 15:47.490] I'm a very active person. [15:47.590 --> 15:49.470] I've got to keep walking or I'll lose my mind here. [15:49.970 --> 15:50.990] The monkey bee was so cool. [15:51.030 --> 15:51.530] Ooh, that's bright. [15:51.710 --> 15:53.350] It's like, yeah, we'll walk over here a little bit more. [15:55.290 --> 15:57.330] That deer in the headlights stuff is kicking in right now. [15:57.710 --> 16:00.710] Alright, what the monkey bee did is it would do this. [16:00.810 --> 16:02.450] It would copy its code over. [16:02.550 --> 16:07.290] It would move it over to like sector 7, 8, or sector 9, 7, 9, or 12, or whatever. [16:07.530 --> 16:16.630] And the reason why it would do multiple sectors is that if it actually discovered a piece of code over in one sector, it would immediately go to the next sector in line until it found an open sector. [16:16.890 --> 16:18.870] That way it can multi-infect a system. [16:19.110 --> 16:24.010] So if you're already infected with like New York food on sector 7, and monkey kept on and said, oh, I'll just go to 9. [16:24.110 --> 16:28.930] So basically, if you try to remove one, then you had to go back and remove the other one, and then you had to go back and remove the other one. [16:29.110 --> 16:30.530] It made it really, really interesting. [16:30.870 --> 16:34.030] And then what monkey did, it says, just the fuck with you. [16:35.250 --> 16:37.350] I'm going to encrypt the fat and partition information. [16:39.350 --> 16:41.470] Yeah, I hear this like, oh, yeah. [16:41.590 --> 16:42.330] That's what made it so cool. [16:44.930 --> 16:51.250] Now, so monkey would actually load into memory and then unencrypt your partition information, go over there and let the system boot immediately. [16:51.530 --> 16:52.610] This is all seamless to you. [16:52.750 --> 16:53.370] It's just instantaneous. [16:55.290 --> 16:58.010] The marker, 5, 5, 8, 8, that's the part of the boot sector. [16:58.410 --> 16:59.130] Jumping way ahead. [17:01.370 --> 17:01.730] Again? [17:01.730 --> 17:02.130] Yeah. [17:09.640 --> 17:11.500] We're going to continue on with the monkey and then I'll hit this real quick. [17:12.380 --> 17:15.380] So in the next slide, I'll actually tell you how to do removals. [17:15.400 --> 17:22.340] But if you remove monkey incorrectly and you actually get rid of the code, what you end up having is, okay, great. [17:22.480 --> 17:26.440] You don't have the boot sector virus anymore that you can no longer see your data. [17:29.160 --> 17:29.800] It's gone. [17:29.800 --> 17:31.540] It's like, there's no trajectory. [17:31.800 --> 17:32.660] I don't know what you're talking about. [17:32.740 --> 17:33.220] You're smoking crap. [17:33.380 --> 17:33.480] Stop. [17:35.800 --> 17:42.740] So one of the ways to look for viruses is, you know, look for the, if you use a disk editor, like, Norton disk editor was awesome. [17:42.960 --> 17:44.640] You know, I used to use Norton disk editor all the time. [17:44.780 --> 17:47.900] And I would just periodically go to a system and I would just go through all the different sectors. [17:47.960 --> 17:49.180] If I saw no code, we're good. [17:49.420 --> 17:50.160] No boot sectors. [17:50.640 --> 17:55.020] If I was ever seeing duplicates of code at different sectors, then it was like, whoops. [17:56.260 --> 17:58.560] Look for strange changes in memory usage. [17:58.560 --> 18:05.020] If you start noticing that, especially under the DOS sequences, that, you know, memory usage was a little bit higher than normal. [18:06.040 --> 18:07.780] We have some TSRs going on here. [18:07.820 --> 18:08.940] Look for strange behavior in the OS. [18:09.300 --> 18:10.000] I know, no jokes. [18:10.080 --> 18:10.680] We're dealing with Windows. [18:10.860 --> 18:12.560] So how do you really define strange behavior? [18:13.020 --> 18:14.520] But, you know, you know what I mean. [18:14.760 --> 18:18.320] If you're getting GPS every three seconds instead of five, you may have a problem. [18:18.820 --> 18:18.900] Okay? [18:20.680 --> 18:23.540] God, I'm crashing like five times more than I normally do. [18:23.900 --> 18:24.740] Okay, next. [18:27.000 --> 18:33.580] One way is to remove just basic boot sector viruses is to use the FDISK slash MBR. [18:34.820 --> 18:37.380] Grab a boot disk or whatever. [18:38.060 --> 18:39.880] Now, this is a really, really cool way of doing it. [18:40.140 --> 18:40.880] And it's instantaneous. [18:41.120 --> 18:42.300] What FDISK slash... [18:42.300 --> 18:43.820] Who's used FDISK slash MBR? [18:44.680 --> 18:46.040] Oh, you guys so freaking rock. [18:46.040 --> 18:46.700] All right. [18:46.960 --> 18:47.060] Here. [18:48.240 --> 18:48.680] All right. [18:49.240 --> 18:52.480] For those of you who doesn't know what it is, so I can at least talk to like one person. [18:53.320 --> 18:53.660] Okay, great. [18:54.920 --> 18:56.640] What FDISK slash MBR says, you know what? [18:56.960 --> 18:59.260] You have a problem on the master boot record. [18:59.440 --> 19:01.040] I don't care what code is there. [19:01.500 --> 19:02.180] Just rewrite it. [19:02.580 --> 19:03.800] Whatever is there, forget about it. [19:03.960 --> 19:05.740] We're just going to put a brand new block of code over it. [19:05.740 --> 19:11.800] So for most boot sector viruses, it's great because it just like says, it's gone. [19:12.460 --> 19:15.360] You know, and yeah, you have a copy of the same boot sector or someplace else, but it doesn't matter right now. [19:15.420 --> 19:16.680] The virus is instantaneously gone. [19:19.500 --> 19:24.340] Another way to do it is just to find the old code on another sector and just copy it and paste it over. [19:24.560 --> 19:25.420] That works the same way. [19:25.800 --> 19:27.060] Yeah, disk editors let you do that. [19:27.160 --> 19:27.780] It's like you go to seven. [19:28.100 --> 19:28.980] It's like, well, there's the real code. [19:29.120 --> 19:29.240] Boom. [19:29.900 --> 19:30.220] Boom. [19:30.680 --> 19:31.180] Game over. [19:31.300 --> 19:31.700] Thanks for playing. [19:33.080 --> 19:33.780] Antivirus software. [19:34.080 --> 19:34.700] Gee, la da. [19:35.020 --> 19:35.160] Hi. [19:36.040 --> 19:38.640] Who can tell me the one of the biggest problems with antivirus products? [19:38.800 --> 19:39.200] Raise your hand. [19:40.560 --> 19:42.180] What is the biggest problem with antivirus products? [19:44.620 --> 19:44.980] No. [19:47.240 --> 19:47.600] Yes. [19:48.820 --> 19:51.460] Actually, the biggest problem with antivirus products is you. [19:52.300 --> 19:54.020] You are the biggest problem with antivirus products. [19:54.300 --> 19:57.000] I have done dozens and dozens of security audits. [19:57.100 --> 19:59.020] And one of the first things I do is I look at their DAT files. [19:59.280 --> 20:01.380] Wow, these have been updated, what, two years ago. [20:04.180 --> 20:06.300] Rule number seven of network security. [20:06.980 --> 20:13.180] An outdated DAT file in an antivirus product is only marginally better than no antivirus product at all. [20:15.000 --> 20:17.500] Note the first two will not work with some viruses. [20:17.680 --> 20:19.440] In fact, may foobar your whole system. [20:22.460 --> 20:23.480] Monkey was one of them. [20:25.440 --> 20:30.200] Now, if you use FDISK, like I said, FDISK slash MBR with the monkey virus, that's it. [20:30.280 --> 20:30.560] Game over. [20:30.680 --> 20:31.180] Thanks for playing. [20:31.540 --> 20:32.440] Hope you have backup tapes. [20:33.700 --> 20:38.820] One of... McAfee actually had to come out with a special monkey bee remover. [20:39.200 --> 20:44.520] And what monkey bee remover would actually do is it would sit there and simulate like it was going to replicate itself. [20:45.140 --> 20:49.180] So it would go, okay, hey, we're going to infect a floppy disk. [20:49.240 --> 20:51.740] And monkey would go, oh, great, let me unencrypt myself here. [20:51.740 --> 20:53.520] And we're going to start going over there and look for the code key. [20:53.640 --> 20:54.380] And it said, stop. [20:54.920 --> 20:57.500] I know what the encryption code key for unencrypting is. [20:57.660 --> 20:57.800] Boom. [20:57.920 --> 21:01.400] We'll kill the virus and we'll encrypt the partition drive and have a nice day. [21:01.800 --> 21:02.900] And it worked great. [21:03.280 --> 21:04.200] It worked really great. [21:04.280 --> 21:05.980] So you have to give them kudos for that. [21:06.440 --> 21:07.860] You know, at one time they were good. [21:08.900 --> 21:09.360] All right. [21:09.860 --> 21:10.480] Did I say that? [21:10.700 --> 21:11.220] No, I didn't say that. [21:11.640 --> 21:12.800] Types of boot sector viruses. [21:13.000 --> 21:15.740] You have stealth, polymorphic, encrypting, and any combination of these. [21:16.140 --> 21:20.300] You also have metamorphic and other ones, but those are more advanced talks. [21:21.260 --> 21:22.740] Stealth boot sector virus. [21:23.540 --> 21:26.820] Viruses hide in upper memory and help hide the virus from virus detectors. [21:27.200 --> 21:32.300] The problem is why it is important to boot a system with a clean boot disk before running a detector. [21:33.280 --> 21:36.620] What it will do sometimes is hide itself from the antivirus product. [21:36.620 --> 21:44.820] So if you sit there and you're actually infected with a stealth virus, running the antivirus product will actually tell you in many cases, there's nothing here. [21:44.960 --> 21:49.800] Where in reality, the virus is like, yeah, I got you so nailed. [21:49.900 --> 21:50.580] Who's your daddy? [21:56.280 --> 21:59.100] You know, if my wife ever sees this video tape, I'm in so much trouble. [22:00.140 --> 22:01.320] Polymorphic boot sector viruses. [22:01.500 --> 22:03.100] The polymorphic viruses are very tricky. [22:03.320 --> 22:05.040] They change the code every time they replicate. [22:05.400 --> 22:09.100] By changing their encryption code, they make it very difficult for removers to get rid of it. [22:09.680 --> 22:14.780] Antivirus software programs use a simulator to identify the code key and then use the key to remove the virus. [22:14.780 --> 22:16.380] It's very, very similar. [22:16.540 --> 22:22.320] It makes it very difficult for an antivirus product to actually identify it because it's not the same signature each time. [22:22.740 --> 22:24.240] You know, it changes its encryption code. [22:24.360 --> 22:28.440] So you can't use the same encryption code you used prior to remove the same virus. [22:28.820 --> 22:32.720] So once again, it goes into the little simulator situation and says, hey, we're going to replicate ourselves. [22:32.840 --> 22:33.600] It's like, okay, go ahead. [22:33.680 --> 22:34.860] Let me go through the encryption process. [22:34.960 --> 22:36.260] And once again, they're going to stop. [22:36.440 --> 22:37.420] I have the encryption key. [22:37.500 --> 22:39.680] I can use the encryption key to unencrypt you and destroy you. [22:40.620 --> 22:41.620] It's very, very cool. [22:41.820 --> 22:50.020] Yeah, I mean, when you see the antivirus writers, like at 3 o'clock in the morning, sitting there with like, you know, code red, typing away. [22:50.440 --> 22:51.900] Then everyone's going, I got it. [22:51.980 --> 22:52.540] I got it. [22:52.740 --> 22:53.940] I can go home and sleep. [22:55.940 --> 22:56.760] That's not a joke. [22:56.900 --> 22:57.480] I'm dead serious. [22:57.640 --> 23:02.580] I mean, when you hear sleep, I've got sleep coming, you know that someone's actually solved an issue. [23:03.200 --> 23:11.480] One of the coolest things I saw is we had, there was a virus writer who sent a virus to the company and sat there and says, I'll bet you you can't figure this one out. [23:12.380 --> 23:14.400] And everybody stayed there all night. [23:14.740 --> 23:20.200] And at 3 o'clock in the morning, the next day, there was a new data file out there for a fix for the virus. [23:20.540 --> 23:26.700] And it was like, everybody had this like, you know, wild hair up their ass like, we're not letting him get the litter of us, son of a bitch. [23:28.060 --> 23:31.120] And we're like, you know, I don't mind staying, but you're buying the pizza and beer. [23:31.240 --> 23:32.340] That's just how it's working. [23:33.220 --> 23:33.460] Next. [23:34.240 --> 23:35.480] Encrypting boot sector viruses. [23:36.040 --> 23:39.980] Encrypting viruses will encrypt data or themselves, making it more difficult to remove. [23:40.180 --> 23:43.040] They may also make it impossible to recover data without the virus to decrypt it. [23:43.440 --> 23:44.460] The monkey was one of those. [23:46.020 --> 23:47.680] Let's move on to file infectors. [23:49.040 --> 23:50.340] File infectors are kind of cool. [23:50.460 --> 23:52.000] I only talk about one file infector here. [23:52.100 --> 23:53.400] There's actually different types of file infectors. [23:53.480 --> 23:54.320] This is a prominent one. [23:54.840 --> 23:57.120] The beginning of the virus code will point to the end of the file. [23:57.120 --> 24:00.860] And the beginning of the real virus is putting this code into memory. [24:01.040 --> 24:05.280] So what happens is this first section here is the intro of the virus. [24:06.060 --> 24:07.200] And then the actual... [24:07.200 --> 24:11.260] And then what we'll do is it'll actually point itself over here to continue on. [24:11.420 --> 24:14.500] So it allows the file to run normally, but it actually... [24:15.600 --> 24:17.560] It fools it and says, I need to load it into memory. [24:17.780 --> 24:18.820] Go ahead and kick on. [24:19.060 --> 24:19.760] It's kind of neat. [24:20.520 --> 24:23.960] The end of the virus code then points to the beginning of the real virus file. [24:23.960 --> 24:27.880] The easiest way to detect these is larger size files. [24:28.240 --> 24:31.760] Who can tell me right now what's the largest size a com file can be? [24:33.120 --> 24:34.220] Oh, don't let me down. [24:34.400 --> 24:34.840] Raise your hand. [24:36.120 --> 24:36.520] 64k. [24:36.940 --> 24:39.180] So what happens if you have a 1 meg com file? [24:40.400 --> 24:41.020] Problem, right? [24:41.980 --> 24:42.380] Yeah. [24:42.920 --> 24:50.320] So a lot of the file infectors, what they would do is every time the file was run, it actually adds a little bit of size to the file. [24:50.520 --> 24:52.700] And every time it was run, it would add a little bit of size. [24:52.700 --> 24:57.580] So your command dot com file would actually start getting bigger and bigger. [24:57.780 --> 24:59.560] You'd have like a 10 gig drive or something like that. [24:59.680 --> 25:00.400] This was way back then, right? [25:00.820 --> 25:01.460] 10 gig drive. [25:01.960 --> 25:05.420] 10 gig drive is like a huge drive now. [25:06.180 --> 25:08.940] And the next thing you know is like, I'm running on disk space. [25:09.040 --> 25:09.940] I haven't installed anything. [25:09.940 --> 25:10.560] What's going on here? [25:10.600 --> 25:12.360] And you look at your com file and it's like... [25:12.360 --> 25:14.400] It's taken up like, shit, that's half my drive. [25:15.220 --> 25:16.920] I think something's wrong. [25:19.400 --> 25:23.060] The multi-partite virus will infect both the boot sector and files. [25:23.480 --> 25:29.260] The problem increases the spreading capacity of the virus by disk, email, or any other way to move the file. [25:29.260 --> 25:34.140] This is a really great way the virus writers found to actually just really replicate things. [25:34.300 --> 25:35.940] So the disk get, the files, whatever. [25:36.300 --> 25:38.740] So anytime you ran a file, they tried to replicate itself. [25:38.880 --> 25:49.400] Anytime you transferred a floppy disk, a lot of people don't realize that all you had to do is put a disk get into a drive and just hit a colon and you would infect the drive. [25:49.840 --> 25:51.160] Infect the disk instantaneously. [25:51.160 --> 25:53.420] Or do a directory and immediately infect the disk. [25:54.700 --> 25:55.700] And then they would, you know... [25:55.700 --> 25:56.880] Who remembers Sneakernet? [25:58.620 --> 25:59.980] Yeah, all the guys with gray hair. [26:00.380 --> 26:00.960] Right on. [26:02.080 --> 26:02.400] Hey! [26:02.640 --> 26:02.860] Hello! [26:03.100 --> 26:03.880] You think this is natural? [26:04.260 --> 26:05.340] It's all from a bottle, baby. [26:08.500 --> 26:09.280] I'm not ashamed. [26:09.420 --> 26:10.220] My wife ties my hair. [26:10.880 --> 26:11.900] Just like, you're looking old. [26:12.080 --> 26:12.460] Thank you, baby. [26:12.560 --> 26:12.840] I love you, too. [26:13.740 --> 26:16.720] You know, seriously, you know, back in the days we all had Sneakernet. [26:16.900 --> 26:20.120] Sneakernet, for those of you young kids out here, was like... [26:20.120 --> 26:21.440] Okay, I need to transfer a file. [26:21.560 --> 26:22.340] Pop out the disk. [26:32.200 --> 26:32.800] Hey, George. [26:35.640 --> 26:36.040] Shit. [26:38.700 --> 26:39.680] That was Sneakernet. [26:41.080 --> 26:44.300] What amazes me is sometimes Sneakernet was faster than using Windows networking. [26:44.500 --> 26:45.360] I didn't say that. [26:45.540 --> 26:46.100] I didn't say that. [26:46.320 --> 26:47.240] I just said... [26:47.240 --> 26:49.220] Why can't I connect to the frickin' computer? [26:49.760 --> 26:50.160] Goddammit. [26:50.540 --> 26:50.760] Fuck it. [26:54.080 --> 26:54.800] Oh, come on. [26:54.900 --> 26:55.840] You know it's true, right? [26:56.800 --> 26:57.700] Yeah, all right. [26:59.020 --> 26:59.340] Macroviruses. [26:59.820 --> 27:01.860] Anybody here who actually got hit by a macrovirus? [27:01.960 --> 27:02.280] Raise your hand. [27:04.440 --> 27:04.540] Okay? [27:05.600 --> 27:09.860] Anybody here think they never got hit by a macrovirus but suspected it? [27:11.100 --> 27:11.420] Okay. [27:13.560 --> 27:16.820] Macroviruses, they were kind of cool a little bit when they first came out. [27:16.960 --> 27:19.500] You know, people were like, oh, there's another way a virus is getting hit. [27:19.540 --> 27:20.740] And I was like, hello? [27:21.840 --> 27:22.460] Get over it. [27:22.680 --> 27:26.760] The macrovirus writers use basic computer languages included with a word in Excel to create the virus. [27:26.760 --> 27:32.400] Now, I don't know what Brainiac said, hey, let's give them coding capabilities in our application. [27:34.720 --> 27:36.100] We'll make their lives easier. [27:37.160 --> 27:37.560] Yeah. [27:38.520 --> 27:40.240] Once again, less crack, more fruits and vegetables. [27:40.420 --> 27:40.940] I wasn't done. [27:41.080 --> 27:41.340] Go back. [27:41.440 --> 27:41.840] What's wrong with you? [27:42.480 --> 27:42.760] Yeah. [27:43.600 --> 27:45.980] Several of the macroviruses used the normal dot file. [27:46.280 --> 27:48.520] Now, you can actually edit this file and view it. [27:48.840 --> 27:57.240] So, if you get suspected that you're actually infected by a macrovirus, you can actually view the normal dot file and see if there's additions to it. [27:57.240 --> 28:00.680] One of the, they had the rainbow virus. [28:01.060 --> 28:04.480] Does anyone remember the rainbow virus, which was a macrovirus? [28:05.360 --> 28:06.280] Anybody remember that? [28:07.520 --> 28:10.380] There was a version of it that used to change the colors on Windows. [28:11.720 --> 28:17.520] So, you know, you would sit there and, you know, you'd be using a file and all of a sudden it's like, I didn't choose puke green as my background. [28:17.820 --> 28:18.420] What the fucks up with that? [28:18.540 --> 28:19.600] You know, and then all your things were going there. [28:19.820 --> 28:24.420] And this was kind of entertaining for a while until everything went, we're just going to make all the colors black. [28:28.140 --> 28:29.480] Or we'll make all the colors white. [28:29.660 --> 28:32.040] And you're like, okay, now I'm annoyed, you know. [28:34.220 --> 28:38.040] But, the easiest way to do that is to keep it back up in your normal dot file. [28:38.480 --> 28:41.200] And then you can just replace it or just edit it and remove it out. [28:41.380 --> 28:44.280] So, the normal dot is used for all the new applications. [28:44.460 --> 28:47.040] It grabs all the previous information off of that and puts it in the application. [28:47.240 --> 28:48.600] So, it made replication really easy. [28:50.960 --> 28:51.980] What is a Trojan horse? [28:53.240 --> 28:55.340] Well, to small script kiddies, it's a condom. [28:57.480 --> 28:58.660] Used only for water balloons. [29:02.880 --> 29:03.660] Work with me, guys. [29:04.560 --> 29:05.800] It's a three hour time difference here. [29:05.880 --> 29:08.280] I'm just getting rolling back in Las Vegas here. [29:08.560 --> 29:10.360] Actually, I just moved to Las Vegas three months ago. [29:11.740 --> 29:13.040] Defcon is not going to be a problem this year. [29:14.740 --> 29:16.640] And no, I no longer have any crash space. [29:16.860 --> 29:17.440] I'm sorry. [29:17.900 --> 29:20.080] As soon as I moved to Las Vegas, I didn't crash with you, right dude? [29:20.080 --> 29:20.920] It's like, oh shit. [29:21.100 --> 29:22.820] It's like, I got 80 people going, right? [29:22.980 --> 29:23.460] I'm there, right? [29:23.660 --> 29:24.400] Yeah, okay, right? [29:24.720 --> 29:24.840] Okay. [29:25.860 --> 29:27.300] It's like, alright, five bucks, please. [29:27.580 --> 29:28.700] Yeah, I'm making money, baby. [29:29.160 --> 29:29.360] Alright. [29:29.780 --> 29:34.580] A program or piece of code that appears to be legitimate, but actually has a hidden or often time malicious purpose. [29:34.780 --> 29:37.200] The Trojans do not replicate, but can be parasitic. [29:40.520 --> 29:45.460] These are programs that are put onto your system by someone, or you are tricked into activating them yourself. [29:46.140 --> 29:48.900] A good example was Whack-A-Mole. [29:49.660 --> 29:50.540] You guys remember that? [29:51.660 --> 29:56.460] Hey dude, my boss at one company goes, you've got to check this out. [29:56.520 --> 29:58.260] This is the funnest freaking game I've ever played. [29:58.320 --> 29:59.100] It's called Whack-A-Mole. [29:59.640 --> 30:07.940] And he sat there, and I was like, he's like, going, who did you give this to? [30:08.500 --> 30:08.900] Everybody! [30:17.420 --> 30:20.960] And I'm like, did you read the acceptable use policy? [30:21.860 --> 30:26.220] Did you read the part where it says, do not transfer items without approval from IT? [30:26.400 --> 30:27.300] Well, I'm the head of IT. [30:27.640 --> 30:29.540] Once again, did you read... [30:30.140 --> 30:32.600] No, you just sit there and say, you're not doing your job right. [30:32.900 --> 30:33.300] You know, you... [30:35.100 --> 30:36.000] See, I'm a firm believer. [30:36.260 --> 30:43.220] If you're an IT manager or an IT director, you should have a freaking clue about what happens in your damn department and at least know how to operate a machine. [30:43.440 --> 30:44.040] That's just me. [30:44.220 --> 30:44.700] That's just me. [30:49.060 --> 30:51.300] I'm so tired of ending it with these IT managers. [30:51.500 --> 30:52.680] I'm like, I'm the manager of this department. [30:52.860 --> 30:53.080] Great. [30:54.540 --> 30:56.200] How do you operate a window system? [30:56.240 --> 30:56.640] I don't know. [30:56.960 --> 30:57.500] I don't know. [30:57.660 --> 30:57.960] I don't know. [30:58.880 --> 31:00.120] Hey, we need some help over here. [31:00.260 --> 31:00.700] I don't know what to do. [31:02.440 --> 31:05.640] Hey, can you help us do the mass installation of the antivirus project? [31:05.960 --> 31:06.160] The what? [31:08.880 --> 31:09.560] It's like... [31:09.560 --> 31:09.600] Yes. [31:11.340 --> 31:12.040] Don't get me started. [31:13.700 --> 31:17.320] Most often, these are backdoor programs like BO, BO2K, NetBus, etc. [31:17.880 --> 31:18.920] A lot of the backdoor programs. [31:18.920 --> 31:27.740] Now, like, things like IRC and IM, these are great ways that people have been spreading, like, you know, Trojan horse systems. [31:28.720 --> 31:30.800] I go on IRC every so often. [31:30.940 --> 31:33.920] I usually avoid IRC, honestly, because, you know what? [31:34.020 --> 31:35.640] I got enough drama in my frickin' life. [31:35.780 --> 31:37.520] Last thing I need is more online. [31:38.100 --> 31:39.400] It's like, it shouldn't be IRC. [31:39.480 --> 31:41.740] It should be drama or us, you know? [31:41.740 --> 31:46.320] But, people sit there, and you get these newbies on there, and these guys are like, Oh, dude, I want to do this. [31:46.440 --> 31:47.400] You know, I want to learn about hacking. [31:47.640 --> 31:47.720] Yeah. [31:48.280 --> 31:48.440] Whatever. [31:48.920 --> 31:51.400] And, you know, it's like, hey, dude, I got the perfect program from you. [31:51.720 --> 31:54.460] Run this, and you'll be able to, like, totally elite hacksore somebody's box. [31:56.060 --> 31:57.120] Dude, I ran the program. [31:57.280 --> 31:58.260] I can't see anything's happening. [31:58.460 --> 31:58.680] Yeah. [31:58.880 --> 31:59.860] I know you ran the program. [32:06.960 --> 32:07.660] So, what's wrong? [32:07.860 --> 32:08.300] I don't know. [32:08.600 --> 32:09.700] Here, try running this program. [32:09.940 --> 32:10.220] Okay. [32:13.740 --> 32:14.920] Oh, man, he's offline. [32:17.420 --> 32:17.940] For good. [32:22.140 --> 32:24.480] And, realistically, that's not really far from the truth. [32:24.860 --> 32:25.620] I mean, it's great. [32:25.900 --> 32:32.400] I mean, if you're a newbie in the industry, and you want to learn about, like, you know, network security and hacking and all that stuff, man, more power to you. [32:32.560 --> 32:34.200] I mean, realistically, you're the future. [32:35.200 --> 32:35.520] 100%. [32:35.520 --> 32:36.080] You know? [32:37.480 --> 32:39.020] But, know who you're talking to. [32:39.500 --> 32:39.740] You know? [32:39.900 --> 32:40.900] IRC is, like, the worst. [32:41.100 --> 32:42.620] Anybody can go on with anybody's nick. [32:42.980 --> 32:43.940] Hey, John, how's it going? [32:44.380 --> 32:45.360] Uh, fine. [32:46.560 --> 32:47.320] Yeah, how you doing? [32:47.440 --> 32:48.500] Did you get that program I sent you? [32:48.500 --> 32:48.860] No. [32:49.180 --> 32:49.480] Ah. [32:49.840 --> 32:50.640] Here it is. [32:52.720 --> 32:55.060] Did anyone ever see the little thing that was... [32:55.060 --> 32:56.800] I don't know if it was fake or not, but it looked really funny. [32:56.940 --> 33:01.660] It was on a couple websites about a B.O. [33:01.920 --> 33:06.520] It was a back orifice demonstration where the guy's sitting there and it's got a screenshot from his camera. [33:06.520 --> 33:07.380] And he's like... [33:07.380 --> 33:08.340] Look at the screen. [33:08.520 --> 33:16.660] And the actual picture of the screen was just like, you know, hey dude, what are you doing lamey here looking at this computer screen when you've got this beautiful girl sitting on your bed, you know? [33:16.740 --> 33:19.060] He goes, stop being such an idiot and put a shirt on, you know? [33:19.260 --> 33:20.740] And the guy's like... [33:21.640 --> 33:22.560] It was hilarious. [33:22.820 --> 33:23.320] It was great. [33:24.740 --> 33:29.040] By the way, I'm not knocking like the CDC here, right? [33:29.640 --> 33:31.260] I'm a huge supporter of the CDC. [33:31.580 --> 33:32.140] Great guys. [33:32.440 --> 33:33.620] Very, very intelligent people. [33:35.020 --> 33:41.220] The thing I believe that they actually do is they make people a little bit more aware of just how much they have to protect their systems. [33:42.000 --> 33:44.240] And they make Microsoft actually fix their shit. [33:47.820 --> 33:49.570] Example of hybrid virus. [33:50.640 --> 33:51.020] Nimda. [33:51.280 --> 33:52.050] Who got hit by Nimda? [33:53.040 --> 33:54.330] And he's like... [33:59.840 --> 34:00.850] I'm proud. [34:01.180 --> 34:01.620] I'm proud. [34:02.960 --> 34:07.180] The thing with Nimda, Nimda spread like a wildfire. [34:07.590 --> 34:09.800] It was pretty impressive. [34:09.800 --> 34:13.280] It did some massive amounts of damage and a massive amount of work. [34:14.400 --> 34:18.440] I'm going to let Marty expand upon this because this is kind of Marty's little baby here. [34:20.140 --> 34:20.520] Okay. [34:20.700 --> 34:25.040] Well, for those of you who know anything about Nimda, you know, you can just bear with me. [34:25.120 --> 34:27.860] But for those, this is going to be very lightweight. [34:28.050 --> 34:32.520] I don't want to get into the details of the exploits because that's beyond the scope of this. [34:32.720 --> 34:33.340] Nimda bad. [34:33.520 --> 34:33.800] Thank you. [34:34.070 --> 34:34.980] Yeah, Nimda bad. [34:35.880 --> 34:38.540] Nimda had four main propagation methods. [34:39.240 --> 34:45.840] The first, obviously, if you look at number one, is it's parasitic prepending file infector. [34:46.000 --> 34:47.570] So you would get infected files. [34:47.780 --> 34:52.640] Obviously, one of the files that arrived in the email was an infected executable. [34:53.800 --> 35:01.620] Email was the main method of propagation along with browsing for vulnerable web servers on the internet. [35:01.620 --> 35:20.040] And, of course, there was also a vulnerability in Internet Explorer 5.5 and earlier that allowed the infection, arbitrary code, to be run on the user's machine when they viewed an infected web server on the internet, which infected their machine internally, [35:20.360 --> 35:23.940] which then began to beacon and infect internal machines on the internet. [35:26.260 --> 35:32.360] So it was a beautiful piece of work, a very sophisticated worm. [35:32.580 --> 35:38.000] One of the neat things that I thought about Nimda was its Trojan capability. [35:38.000 --> 35:44.080] The way it propagated through network shares, it did a couple of different Trojan things. [35:44.240 --> 35:47.220] It copied itself as readme.eml. [35:47.220 --> 35:51.340] So people would see all these readme files and not know what they were. [35:51.520 --> 35:54.000] And, of course, double-click on the social engineering thing. [35:54.280 --> 36:01.700] But the other thing that was really slick was that it copied itself as a Trojan RichEd 20 DLL. [36:02.040 --> 36:13.100] Now, a lot of, well, Word and WordPad use RichEd 20 DLL for rich text, any rich text files of documents. [36:13.100 --> 36:18.780] So it looked for file shares that contained Word documents. [36:19.020 --> 36:24.760] And it would copy a Trojan RichEd 20 DLL there and make it a hidden file so you couldn't see it. [36:25.120 --> 36:37.760] When the user would double-click on the Word file, it would look at the local root first, at the local where it was launched, and launch, call the Trojan RichEd 20 DLL, infecting the host system. [36:37.940 --> 36:39.820] So it was really, really cool. [36:44.400 --> 36:50.100] We threw this up because this is like one of the new bridging, gapping type of viruses. [36:52.380 --> 36:58.720] If you ask some people a definition of a worm, a worm is something that really isn't parasitic. [36:58.820 --> 37:00.040] It won't actually infect the file. [37:00.160 --> 37:01.540] It just kind of goes from system to system. [37:01.820 --> 37:04.920] And this kind of bridges the gap because it actually hit the .exe files. [37:06.320 --> 37:10.300] A lot of things are really starting to change in the virus industry in the world. [37:11.060 --> 37:15.380] I hate to say this, but a lot of the crap that comes out is all script kitty shit. [37:16.020 --> 37:21.800] It's not like the old school virus writers who sat there and said, how much damage could I possibly do in as little code as possible? [37:22.240 --> 37:28.900] I mean, you're seeing things that would like nail you hard in like 4K of code, all machine language. [37:29.160 --> 37:33.860] And now it's some, you know, 12-year-old sitting down on a computer going, hey, I stole somebody else's script. [37:34.000 --> 37:38.880] Let's add some shit and make a whole brand new virus and get credit for it and say, yeah, look how awesome. [37:39.060 --> 37:42.360] Elite I am and have my other 12-year-olds chewing bubblegum saying, you're great. [37:44.140 --> 37:45.300] You're not great, you suck. [37:46.180 --> 37:46.320] All right. [37:49.680 --> 37:52.100] The new method of virus writings are emerging all the time. [37:52.260 --> 37:56.920] Some of the new forms of malicious code have the ability to change themselves to evade detection. [37:57.500 --> 38:00.240] 1981, the first known virus was a Mac OS virus. [38:01.020 --> 38:04.420] For those of you who thought you were completely safe on Macintosh, sorry. [38:06.720 --> 38:09.680] Realistically, the actual first virus ever written was MIT. [38:11.300 --> 38:12.440] Does anyone know that story? [38:13.660 --> 38:13.980] No? [38:14.220 --> 38:15.340] Raise your hand if you know the story. [38:16.060 --> 38:16.220] Okay. [38:16.720 --> 38:18.340] Basically, it was used as a competition. [38:18.680 --> 38:23.000] They would go on the mainframes and actually write codes that were designed to like take out other people's code. [38:23.140 --> 38:27.880] You know, the other code and actually, you know, try to use up as much space as possible and they would run for a period of time. [38:27.980 --> 38:28.660] It was a competition. [38:29.040 --> 38:32.720] And then one person, actually I can't remember his name, which is kind of stupid. [38:32.720 --> 38:38.280] But he wrote a piece of code and it just completely went rampant and started spreading to other systems. [38:39.720 --> 38:40.900] They were unamused. [38:42.400 --> 38:44.380] 1986, first known MS-DOS virus. [38:44.600 --> 38:46.060] 1988, encrypted viruses. [38:46.480 --> 38:49.180] 1997, agnomorphic viruses. [38:49.500 --> 38:51.320] 1998, polymorphic viruses. [38:51.660 --> 38:53.820] 2000, metamorphic viruses. [38:54.640 --> 38:57.560] Now, we don't really go into a lot of detail on metamorphic viruses. [38:57.680 --> 39:01.280] I told you what a polymorphic virus was, which is something that actually changes its encryption key. [39:01.280 --> 39:05.740] The metamorphic virus actually changes the code and the code size itself. [39:05.920 --> 39:07.560] So the signature is different. [39:07.820 --> 39:10.680] By adding like junk code, changing that structure a little bit. [39:11.740 --> 39:12.840] Everything is progressing. [39:13.260 --> 39:13.740] It's pretty bad. [39:13.940 --> 39:14.540] Keeping count. [39:14.680 --> 39:22.000] Antivirus software vendors identified a thousand new viruses last year, bringing the total to 71,000 known worldwide. [39:24.880 --> 39:28.320] Now, identified a thousand new viruses. [39:28.780 --> 39:30.500] Let me clarify on this, okay? [39:31.540 --> 39:34.040] One year, 1,000 brand new viruses. [39:34.320 --> 39:36.260] These are viruses in the wild. [39:36.680 --> 39:45.200] What you don't understand is the antivirus companies get on an average of 400 to 800 new, never-before-seen viruses each month. [39:48.680 --> 39:50.300] Most of these don't hit the wild. [39:50.520 --> 39:51.820] A lot of these are broken codes. [39:51.940 --> 39:52.560] A lot of these are crap. [39:53.580 --> 39:56.640] Or they don't replicate fast enough to actually be considered a threat. [39:57.440 --> 39:57.860] Yeah. [39:58.200 --> 39:59.140] They're just like there. [39:59.620 --> 40:02.280] A lot of new technology viruses sent to them. [40:02.680 --> 40:03.420] Think about that. [40:03.560 --> 40:07.180] Imagine getting 800 brand new, never-before-seen, each month. [40:07.180 --> 40:09.640] This is called job security for the antivirus. [40:11.160 --> 40:12.480] The data file providers. [40:12.900 --> 40:13.000] Okay. [40:13.200 --> 40:13.280] Cool. [40:13.400 --> 40:13.960] I'm never leaving. [40:15.220 --> 40:15.620] Yes. [40:16.500 --> 40:17.980] Let's talk about fakes and false alarms. [40:19.480 --> 40:21.700] Most of your fakes and false alarms come through email. [40:22.300 --> 40:24.920] Look for a lot of bangs on your thing. [40:25.020 --> 40:27.340] It's like, for God's sake, read this. [40:27.480 --> 40:37.080] And then it's like, you know, next line, next line, next line, next line, next line, next line. [40:40.080 --> 40:43.600] Another really good key is, send this to everyone you know. [40:44.520 --> 40:44.880] Alright. [40:45.140 --> 40:45.920] Who's gotten these? [40:47.980 --> 40:48.340] Okay. [40:48.500 --> 40:51.380] Who in IT wants to kill the sons of bitches who send them to them? [40:54.140 --> 40:58.560] How many times have you sent out to your users, hi, if you get one of these, please delete it and just inform us. [40:58.800 --> 40:59.640] Do not send it to us. [41:00.240 --> 41:02.420] And then a week later, you get like a dozen of them. [41:03.420 --> 41:04.500] Dude, there's a new virus. [41:04.500 --> 41:05.120] Yeah. [41:05.580 --> 41:05.680] Okay. [41:06.180 --> 41:06.500] Come here. [41:06.680 --> 41:07.320] Walk into this. [41:10.390 --> 41:11.430] Now run into this. [41:14.710 --> 41:15.070] Okay. [41:16.070 --> 41:20.010] This scary thing here, guys, is when you get these fakes and false alarms. [41:20.130 --> 41:21.210] Hey, there's a brand new virus here. [41:21.210 --> 41:32.630] It'll make your dog pregnant and change the color of your sister's hair and delete everything on your system directory and it'll wipe out all the text on your books. [41:34.670 --> 41:37.050] So, hey, this is new and I love it. [41:37.350 --> 41:38.910] Microsoft has sent out a warning. [41:40.390 --> 41:40.790] Okay. [41:41.170 --> 41:43.130] Microsoft does not send out virus warnings. [41:44.010 --> 41:44.110] Okay. [41:44.630 --> 41:47.110] And they'll drop things like, McAfee has said this is the worst thing. [41:47.230 --> 41:49.690] And then you go online going, gee, I don't see shit about this anywhere. [41:51.170 --> 41:55.590] So, if you're concerned, some of the false alarms actually look legitimate and you're like, well, maybe. [41:55.590 --> 42:08.470] The best thing they do is go onto the antivirus sites, you know, McAfee, Norton, F-Prod, whatever, and look under their fakes and false alarm sections here or, you know, or hoaxes and verify that way. [42:09.150 --> 42:14.490] But the point I want to make here is realistically, these themselves become viruses. [42:15.890 --> 42:16.810] Think about that. [42:17.650 --> 42:19.350] Because what's a virus supposed to do? [42:19.350 --> 42:24.810] It's supposed to chew up bandwidth, right, interfere with you and replicate. [42:25.490 --> 42:36.710] Well, when you have end users who barely know how to type and use a mouse as it is and they see these and they send them to everybody in their address book, you know, as Aunt Jenny in Kentucky. [42:37.850 --> 42:40.370] Everybody, all the relatives, all right, the whole state of Kentucky. [42:42.870 --> 42:48.090] You know, these replicate and they start chewing up bandwidth and they chew up your things and you end up getting a flood of these things. [42:48.090 --> 42:50.030] So realistically, these become a virus themselves. [42:50.290 --> 42:52.250] So it's really important to educate our end users. [42:52.450 --> 42:56.370] When you see something like this, don't send out the warnings to everybody you know. [42:57.410 --> 43:00.410] Contact me and I'll give you a yay or nay and tell you what's up. [43:00.550 --> 43:01.410] Go ahead and inform me. [43:01.610 --> 43:03.630] Don't forward me 20,000 copies of this. [43:06.090 --> 43:07.590] VBS Visual Basic Scripts. [43:07.710 --> 43:10.530] Every damn script kitty in the world can now write viruses. [43:12.750 --> 43:18.190] Now, the first time I gave this lecture, I had this little 12-year-old kid at Defcon stand up and go, excuse me. [43:18.310 --> 43:18.590] I said, yeah. [43:18.710 --> 43:20.150] And he goes, you spelled damn wrong. [43:21.510 --> 43:22.850] I said, I know. [43:23.430 --> 43:24.150] It's a joke. [43:25.470 --> 43:27.550] And I will never tell you what the actual joke is. [43:27.650 --> 43:28.950] I want you to get it for yourselves. [43:30.450 --> 43:32.090] So some people are like, oh, I get it. [43:32.150 --> 43:32.730] I'm saying, cool. [43:32.910 --> 43:33.890] Explain the joke. [43:34.170 --> 43:36.910] No, if you can't get it, it won't be funny for you. [43:37.910 --> 43:38.390] Okay. [43:38.790 --> 43:41.930] The I love you virus was a perfect example of this. [43:42.030 --> 43:45.770] The I love you virus, in my opinion, was nothing more than a script kitty stuff. [43:45.990 --> 43:46.110] You know. [43:47.690 --> 43:51.190] Your mom can write a virus using Visual Basic Scripting. [43:51.510 --> 43:51.990] Okay. [43:52.350 --> 43:54.690] It doesn't become elite status anymore. [43:55.070 --> 43:55.330] You know. [43:55.470 --> 43:57.370] These are not hard things to write. [43:57.590 --> 43:58.970] Anybody can write these. [43:59.570 --> 44:00.070] You know. [44:00.330 --> 44:02.330] Which makes them that much more annoying. [44:02.590 --> 44:03.730] And that much more pathetic. [44:04.130 --> 44:04.430] You know. [44:04.730 --> 44:09.270] So, when you see these new VBS script viruses coming out, the first thing you say is like... [44:09.790 --> 44:13.070] You know, there's some like, you know, eight-year-olds sitting there getting this jolly. [44:13.150 --> 44:14.610] He's like, dude, I am so elite. [44:14.870 --> 44:15.070] Yeah. [44:16.170 --> 44:18.050] And he's telling all his friends, like, huh, that was me. [44:18.830 --> 44:20.050] Wait, who's here to see me? [44:20.530 --> 44:21.150] With guns? [44:21.350 --> 44:21.470] What? [44:21.670 --> 44:21.870] Huh? [44:24.850 --> 44:25.290] You know. [44:25.430 --> 44:25.430] You know. [44:25.450 --> 44:26.150] And I hate to say that. [44:26.250 --> 44:27.450] Then they're crying like a little bitch. [44:27.530 --> 44:29.310] But they're like, you didn't mean to do nothing. [44:29.570 --> 44:30.730] It was like a mom. [44:35.310 --> 44:36.450] Put him in the cell with Bubba. [44:38.030 --> 44:38.390] Yeah. [44:38.510 --> 44:39.310] Let's see if he writes another script. [44:42.270 --> 44:42.990] Hostile code. [44:44.810 --> 44:47.390] Now, everything we talked about is considered hostile code. [44:47.530 --> 44:48.130] So, what's the deal? [44:50.230 --> 44:53.090] Realistically, when I talk about hostile code, I'm talking about things that... [44:53.550 --> 44:55.550] It's like brand new, undiscovered stuff. [44:55.950 --> 44:57.590] You know, new and undiscovered hitting the wild. [44:58.170 --> 44:59.290] Things that... [44:59.290 --> 45:01.130] There are no data files hitting for. [45:01.490 --> 45:03.150] The I Love You virus is a perfect example. [45:03.270 --> 45:07.410] When the I Love You virus hit, it replicated and spread across the nation, like... [45:07.990 --> 45:08.870] Almost instantaneously. [45:08.910 --> 45:09.810] It was so fast. [45:10.750 --> 45:12.190] So, I have to get credit on that. [45:12.430 --> 45:12.690] You know. [45:12.810 --> 45:15.810] Mostly because, you know, everybody's using stupid email servers. [45:16.510 --> 45:16.950] But... [45:17.670 --> 45:26.670] A good example was, when it hit the wild, the very first antivirus company out there, who had a fix for it, had a fix two hours after it hit the US. [45:27.030 --> 45:28.290] You know, it was F plot. [45:29.130 --> 45:29.610] You know, F secure. [45:31.030 --> 45:37.110] And two hours after it hit the US, they identified it, they had a fix for it, and they traced it back to country of origin. [45:37.670 --> 45:38.570] I was pretty impressed. [45:39.750 --> 45:44.050] But, we're also talking about things like Java, ActiveX, and other crap like that. [45:44.270 --> 45:44.450] You know. [45:44.670 --> 45:46.810] These can all be determined as hostile codes. [45:47.050 --> 45:52.270] Some of the Juarez sites you guys go to, you don't realize actually drop a Trojan into your system. [45:53.290 --> 45:54.170] Did you guys know that? [45:55.490 --> 45:56.450] Who didn't know that? [45:56.530 --> 45:57.550] Raise your hand. [45:57.710 --> 45:58.250] And don't be embarrassed. [45:59.190 --> 46:02.130] Who visited these sites and are going to go home and really check their system now? [46:04.170 --> 46:06.250] You know, people are like, oh, I'm just going to download some free shit. [46:06.410 --> 46:09.550] You know, and next thing you know, it's like, oh man, all these damn porn pages keep popping up. [46:09.590 --> 46:10.490] Not that I've ever done these. [46:10.930 --> 46:14.030] But I mean, it was like, you're like going, God, I just want to get that piece of software. [46:14.130 --> 46:14.590] Yeah, yeah, yeah. [46:15.310 --> 46:17.470] And it's like, you know, wait a minute. [46:17.590 --> 46:18.890] Why is my system acting funny? [46:20.290 --> 46:20.630] You know. [46:20.830 --> 46:21.630] And who are you going to tell? [46:21.790 --> 46:22.090] What were you doing? [46:22.410 --> 46:23.090] You know what? [46:23.130 --> 46:23.970] It sucked, man. [46:23.990 --> 46:26.890] I was sitting there trying to download to be legal software and I got hit with a Trojan. [46:26.890 --> 46:27.690] Can you do something about it? [46:27.770 --> 46:28.690] Wait, whoa, whoa, whoa, whoa. [46:30.910 --> 46:34.750] All right, so how the hell do you defend against, you know, a new hostile code? [46:35.290 --> 46:37.010] Well, kick over. [46:40.400 --> 46:42.220] Setting up proper security on your system. [46:42.360 --> 46:44.500] Yes, that means your Unix systems as well. [46:44.720 --> 46:46.840] You really need to set up proper security systems. [46:48.040 --> 46:54.140] Under Windows, you can actually set it so it doesn't allow ActiveX or Java applications to execute without your knowledge. [46:54.280 --> 46:55.740] This is a pretty important thing to do. [46:57.220 --> 47:02.140] On Unix systems, if you don't lock down your system, there's a lot of Trojans and back doors that can just walk right in. [47:02.380 --> 47:09.360] They look for normal vulnerabilities and if you're not patching correctly and you're not updating your systems normally, you're wide open. [47:09.780 --> 47:10.740] You know, people have this really... [47:13.240 --> 47:23.540] See, one of the things I hate about Unix, and that's usually not a word you would hear coming out of my mouth is hate and Unix together in the same sentence, is the same reason why I hate anti-virus products. [47:24.540 --> 47:26.740] Because it gives you that false sense of security. [47:27.480 --> 47:30.320] You think because you have an anti-virus product you're completely safe. [47:30.740 --> 47:31.260] Bullshit! [47:32.440 --> 47:33.080] You know? [47:33.340 --> 47:36.320] You were safe for two hours after you installed it and updated it. [47:36.880 --> 47:37.520] You know? [47:37.700 --> 47:39.780] My anti-virus product updates daily. [47:41.020 --> 47:41.540] Daily. [47:42.120 --> 47:46.180] And I still know that within that 24 hours I can still get infected with the virus. [47:47.100 --> 47:49.140] Because shit's coming out all the time. [47:49.920 --> 47:50.400] You know? [47:50.600 --> 47:54.660] And you are the worst enemy to yourself because you do not go out there and update your data files. [47:54.940 --> 47:55.160] Alright. [47:55.400 --> 47:57.140] I want an honest opinion here. [47:57.360 --> 48:00.740] Raise your hand if you have not updated your data file in a week. [48:01.040 --> 48:01.440] Raise your hand. [48:03.220 --> 48:05.160] Keep your hand up if you haven't done it in a month. [48:05.840 --> 48:07.380] Keep your hand up if you've never done it. [48:08.460 --> 48:08.860] Okay. [48:08.940 --> 48:09.480] There's a few of you. [48:09.500 --> 48:10.060] You're honest. [48:10.380 --> 48:10.760] Thank you. [48:11.900 --> 48:15.080] Trend Micro sent out four data files just this week. [48:15.140 --> 48:15.320] Yeah. [48:16.200 --> 48:17.020] If you didn't hear them. [48:17.140 --> 48:19.720] Trend Micro sent out four data files just this week. [48:21.340 --> 48:23.260] Fprod updates their data files daily. [48:24.400 --> 48:25.660] McAfee is like once a week. [48:27.320 --> 48:29.140] Trend, very, very cool product. [48:29.240 --> 48:34.320] One of the neat things I like about Trend Micro is you can go onto their website and actually have it scan your system from the internet. [48:34.500 --> 48:35.620] And it does a very, very good job. [48:35.780 --> 48:36.040] Yes, sir. [48:36.440 --> 48:37.100] I have a question. [48:37.600 --> 48:40.600] For a while I've had ActiveX disabled when I'm using Windows. [48:40.860 --> 48:41.040] Yeah. [48:41.220 --> 48:42.260] Because it really... [48:42.700 --> 48:44.500] And not just how I'm afraid of viruses. [48:44.660 --> 48:46.780] It's also really annoying some of the things that it does. [48:47.320 --> 48:51.940] But almost every site I go to that's a more mainstream site, like a news site, anything like that. [48:52.180 --> 48:54.120] And almost all of them use ActiveX. [48:54.280 --> 48:54.640] Exactly. [48:54.840 --> 48:56.600] Is there any way that you can... [48:56.600 --> 48:56.820] No. [48:56.860 --> 48:58.060] How many programs that... [48:58.060 --> 48:58.360] No. [48:59.500 --> 48:59.600] No. [49:01.640 --> 49:05.240] Basically, he is saying that, you know, he has ActiveX disabled. [49:06.320 --> 49:10.540] And when you go to like a lot of the news sites and all that stuff, they all want to use ActiveX. [49:10.680 --> 49:11.400] And it becomes really annoying. [49:11.460 --> 49:13.060] Because then, you know, he has problems. [49:13.240 --> 49:14.420] And is there a way to get around that? [49:14.640 --> 49:14.920] No. [49:14.980 --> 49:15.420] Not really. [49:22.680 --> 49:23.240] Not really. [49:23.940 --> 49:24.220] Because... [49:25.500 --> 49:25.960] You know what? [49:26.080 --> 49:26.920] There is a way to do it. [49:27.040 --> 49:28.080] And I'll tell you how to do it right now. [49:29.180 --> 49:30.020] Because we're getting right there. [49:31.100 --> 49:31.800] So, hey. [49:32.000 --> 49:32.480] Thanks for the segue. [49:34.320 --> 49:35.780] On Windows, stop laughing. [49:36.080 --> 49:39.340] There are products that you can... that can help out a lot. [49:39.880 --> 49:39.960] Right? [49:40.480 --> 49:43.760] Securing a Windows system has never ended any metal. [49:44.120 --> 49:47.040] I mean, you're going to hear me make craps about Microsoft Windows. [49:47.420 --> 49:50.620] And realistically, I do actually love the operating system. [49:52.200 --> 49:54.040] Because, you know, I'm a gamer at heart. [49:54.500 --> 49:55.560] Love playing computer games. [49:55.560 --> 49:58.060] And realistically, the kick-ass games are on Windows systems. [49:58.480 --> 49:58.580] Right? [49:59.380 --> 50:01.300] There's a lot of things you can do on a Windows system. [50:02.740 --> 50:05.960] You know, I've talked to hackers all over the nation. [50:06.080 --> 50:08.020] And someone says, I only use a Linux system. [50:08.100 --> 50:11.260] I only use a, you know, a Unix system or whatever. [50:11.480 --> 50:17.360] And I know people who sit there and say, dude, I can totally root your box with a Windows, you know, Windows 95 system just as easy. [50:17.540 --> 50:18.240] What's the big deal? [50:18.700 --> 50:20.100] You know, it's just all about skill. [50:21.420 --> 50:24.520] One of the ways you can actually defend yourself is with what they call sandbox technology. [50:25.100 --> 50:26.780] All right, so how does sandbox technology work? [50:26.900 --> 50:31.780] What it does is it actually, anything that you actually execute on your system gets put into a DMZ sandbox. [50:32.340 --> 50:35.080] And what it does is it puts it in an isolated sequence here. [50:35.200 --> 50:38.940] And when it executes the code, if it sees any hostile activity, it stops it in its tracks. [50:39.920 --> 50:41.060] And it says, you know what? [50:41.140 --> 50:43.480] This looks like it's trying to actually do something that's, you know, bad. [50:44.120 --> 50:45.700] Do you want me to do it or not? [50:46.140 --> 50:46.880] I've stopped it. [50:47.040 --> 50:47.780] It's not going to happen. [50:48.360 --> 50:49.500] This is really great stuff. [50:50.320 --> 50:51.540] What about DAT file updates? [50:51.720 --> 50:52.280] There are none. [50:53.200 --> 50:54.120] There are none. [50:54.320 --> 50:54.380] There are none. [50:54.380 --> 50:55.860] It's not looking for signatures. [50:56.100 --> 50:57.400] It's looking for hostile activity. [51:00.100 --> 51:00.580] Yeah? [51:01.560 --> 51:02.780] Speak, young man. [51:03.420 --> 51:06.480] I've heard of F-Pot. [51:06.840 --> 51:07.540] F-Pot? [51:07.700 --> 51:08.280] F-Secure. [51:08.360 --> 51:08.860] F-Secure. [51:08.980 --> 51:09.380] F-Secure. [51:09.380 --> 51:09.500] F-Secure. [51:09.700 --> 51:10.520] It's an anti-virus company. [51:11.420 --> 51:14.240] It sounds a lot like Blue Shot Plus. [51:17.360 --> 51:18.080] I'll get there. [51:18.240 --> 51:18.340] Trust me. [51:18.340 --> 51:22.480] Sandbox is a new type of approach. [51:23.080 --> 51:24.060] Relatively new. [51:24.820 --> 51:28.640] You have to remember that current anti-virus products are reactive. [51:29.280 --> 51:29.380] Right. [51:29.820 --> 51:38.940] And as complex hybrids become, you know, more complex, it takes virus, anti-virus companies longer to write the signatures for them. [51:38.940 --> 51:44.300] And that time period, with them spreading at near a speed of light, you know, that time is critical. [51:44.500 --> 51:55.880] So what they're doing is, some companies are going with Sandbox, some are actually integrating their personal firewall software into their anti-virus software, and it's based on behavior blocking. [51:56.120 --> 51:57.640] You block certain types of behaviors. [51:57.640 --> 52:04.620] I'm not going to allow them to infect my machine and then probe out, if I am infected, you know, probe out to the network. [52:04.780 --> 52:06.580] I'm going to restrict that behavior. [52:06.780 --> 52:06.880] Exactly. [52:07.000 --> 52:08.640] I'm also going to restrict... [52:10.760 --> 52:11.640] It is. [52:11.960 --> 52:16.880] And it has to be, and these type of technologies need to be... [52:16.880 --> 52:17.540] Fine-tuned. [52:17.780 --> 52:18.320] Fine-tuned. [52:18.460 --> 52:20.040] But once they're tuned, they're... [52:20.040 --> 52:20.700] They're rock solid. [52:20.860 --> 52:21.500] They're rock solid. [52:21.620 --> 52:22.600] Now, here's an example. [52:23.100 --> 52:25.780] A really great app to use is called Finch and Surf and Shield. [52:26.660 --> 52:28.580] No, I don't get kickbacks from the company. [52:28.900 --> 52:29.380] It's one of the... [52:29.380 --> 52:32.500] When I do security audits, it's one of the products I always recommend. [52:32.940 --> 52:36.360] It doesn't use data files, and it doesn't replace your anti-virus product. [52:36.520 --> 52:38.960] It works in conjunction with your anti-virus product. [52:39.060 --> 52:39.820] So what it does is... [52:39.820 --> 52:39.940] That's right. [52:40.000 --> 52:41.880] It helps protect your system from hostile code. [52:42.200 --> 52:52.840] A perfect example that they actually use on their web pages is companies that actually were using the Finch and Surf and Shield when the I Love You virus hit, those companies were completely protected. [52:52.840 --> 52:58.100] It stopped the I Love You virus in its tracks before it infected any systems because he detected it as hostile code. [52:58.340 --> 53:01.300] It's mostly used for things like ActiveX and Java problems. [53:01.420 --> 53:03.800] So for you back there, what you could actually have is... [53:03.800 --> 53:08.900] You could actually be running this in the background and actually have ActiveX and Java running on your system. [53:09.060 --> 53:16.520] And when you hit a web page, if it detected a hostile activity, it would actually stop it without actually interfering with you going to the news servers. [53:17.500 --> 53:18.700] Let's do the questions in a bit, okay? [53:19.080 --> 53:20.280] We're kind of running out of time right here. [53:21.040 --> 53:26.420] The website for Fingan is www.fingan.com, F-I-N-G-A-N. [53:26.760 --> 53:27.980] A great person to talk to. [53:28.100 --> 53:31.720] She's the rep I work with all the time for the company I'm presently working with. [53:32.060 --> 53:33.600] We're buying it for our company too. [53:34.260 --> 53:34.880] Denny Nelson. [53:35.100 --> 53:35.580] She's a sweetheart. [53:35.840 --> 53:36.260] Great lady. [53:37.460 --> 53:38.480] Tell her that I sent you. [53:39.100 --> 53:39.860] She'll treat you right. [53:40.000 --> 53:41.180] That's her desk number there. [53:43.620 --> 53:44.120] Thank you. [53:44.660 --> 53:45.480] That's our talk. [53:45.680 --> 53:47.780] I'd like to make a special thanks to Marty here. [53:47.920 --> 53:49.640] He gave me a lot of input and helped out. [53:50.840 --> 53:51.900] And the company I work for. [53:52.040 --> 53:52.900] One of the companies I work for. [54:00.970 --> 54:03.670] We have about four minutes for questions. [54:09.290 --> 54:09.910] You know what? [54:09.910 --> 54:12.150] It's very, very unique. [54:12.430 --> 54:13.570] The Sandbox technology. [54:13.830 --> 54:17.970] They have it for like servers, firewalls, workstations and so forth. [54:19.570 --> 54:21.790] It's very unique on how it works. [54:22.450 --> 54:24.650] Of all the different companies that are doing it. [54:24.770 --> 54:27.170] The only one I found that has been the most reliable has been Fingan. [54:27.350 --> 54:28.230] And I've tested all of them. [54:35.130 --> 54:41.530] There's a couple of multi-OS viruses that came out that affect both Windows and Linux. [54:41.750 --> 54:44.770] Linux is starting to develop a little bit more stronger following. [54:45.050 --> 54:46.990] And because so, there's a couple of things in the things. [54:46.990 --> 54:50.770] What a lot of the viruses are for Linux or in development are. [54:51.390 --> 54:53.950] Is they're looking for known vulnerabilities in Linux. [54:54.190 --> 54:55.590] For that people don't normally patch. [54:55.930 --> 54:58.170] And the virus looks for that to get root access and then spread itself. [55:02.770 --> 55:03.950] Hold on, let me get this guy right here. [55:19.770 --> 55:21.450] This actually tells you what it tried to do. [55:22.310 --> 55:23.630] Fingan actually tells you what it tried to do. [55:23.770 --> 55:25.310] It said, it tried to do this, this and this. [55:25.630 --> 55:27.490] Do you want to let it happen? [55:27.670 --> 55:29.650] And the thing is, is I'll download files from the internet. [55:29.870 --> 55:32.770] And it has this like little life preserver ring over the application. [55:32.910 --> 55:35.730] So when I double click on it, I know it's been put into its own little DMC Sandbox. [55:35.910 --> 55:39.150] And if it doesn't detect hostile activity, it lets it run perfectly. [55:39.170 --> 55:41.530] If it detects hostile activity, it comes in with it. [55:41.530 --> 55:43.610] It's trying to do this right now, yes or no. [55:43.610 --> 55:44.110] So... [55:49.170 --> 55:49.990] I think we're done. [55:50.310 --> 55:50.570] Thank you. [55:50.810 --> 55:51.270] Thank you.