<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments for Beng Hacks</title>
	<atom:link href="http://benghacks.wordpress.com/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://benghacks.wordpress.com</link>
	<description>enumerate, obfuscate, penetrate</description>
	<lastBuildDate>Wed, 11 Nov 2009 03:47:30 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>Comment on indonesiancoder.org by indonesiancoder.org &#171; SG Hackers</title>
		<link>http://benghacks.wordpress.com/2009/11/11/indonesiancoder-org/#comment-94</link>
		<dc:creator>indonesiancoder.org &#171; SG Hackers</dc:creator>
		<pubDate>Wed, 11 Nov 2009 03:47:30 +0000</pubDate>
		<guid isPermaLink="false">http://benghacks.wordpress.com/?p=129#comment-94</guid>
		<description>[...] Source     Share this post!  Twitter Digg Facebook Delicious StumbleUpon Google Bookmarks LinkedIn Technorati Favorites     This entry was posted on November 11, 2009 at 11:46 AM, and is filed under Quoted. Follow any responses to this post through RSS 2.0. You can leave a response or trackback from your own site. [...]</description>
		<content:encoded><![CDATA[<p>[...] Source     Share this post!  Twitter Digg Facebook Delicious StumbleUpon Google Bookmarks LinkedIn Technorati Favorites     This entry was posted on November 11, 2009 at 11:46 AM, and is filed under Quoted. Follow any responses to this post through RSS 2.0. You can leave a response or trackback from your own site. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on SG Hackers by Jun Hao</title>
		<link>http://benghacks.wordpress.com/2009/10/27/sg-hackers/#comment-93</link>
		<dc:creator>Jun Hao</dc:creator>
		<pubDate>Tue, 27 Oct 2009 15:30:45 +0000</pubDate>
		<guid isPermaLink="false">http://benghacks.wordpress.com/2009/10/27/sg-hackers/#comment-93</guid>
		<description>nice initiative =)</description>
		<content:encoded><![CDATA[<p>nice initiative =)</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Mobile Secrets by milo</title>
		<link>http://benghacks.wordpress.com/2009/09/29/mobile-secrets/#comment-92</link>
		<dc:creator>milo</dc:creator>
		<pubDate>Tue, 29 Sep 2009 15:13:29 +0000</pubDate>
		<guid isPermaLink="false">http://benghacks.wordpress.com/?p=116#comment-92</guid>
		<description>Interesting.. Hope to see an update on this (:</description>
		<content:encoded><![CDATA[<p>Interesting.. Hope to see an update on this (:</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Windows Vista Service Tweaks in Batch! by anon</title>
		<link>http://benghacks.wordpress.com/2009/04/14/windows-vista-service-tweaks-in-batch/#comment-91</link>
		<dc:creator>anon</dc:creator>
		<pubDate>Fri, 07 Aug 2009 20:36:24 +0000</pubDate>
		<guid isPermaLink="false">http://benghacks.wordpress.com/?p=92#comment-91</guid>
		<description>Thanks for taking the time to do this!</description>
		<content:encoded><![CDATA[<p>Thanks for taking the time to do this!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Is it really that easy to bypass firewall and antivirus? by benghacks</title>
		<link>http://benghacks.wordpress.com/2006/01/13/is-it-really-that-easy-to-bypass-firewall-and-antivirus/#comment-86</link>
		<dc:creator>benghacks</dc:creator>
		<pubDate>Mon, 22 Jun 2009 02:28:15 +0000</pubDate>
		<guid isPermaLink="false">http://benghacks.lah.cc/2006/01/13/is-it-really-that-easy-to-bypass-firewall-and-antivirus/#comment-86</guid>
		<description>To join a trojan to a word doc requires an exploit or a vbscript type dropper, but if macros are disabled then vbscript won&#039;t work.

Nigeria con I think best u just forget it and move on.</description>
		<content:encoded><![CDATA[<p>To join a trojan to a word doc requires an exploit or a vbscript type dropper, but if macros are disabled then vbscript won&#8217;t work.</p>
<p>Nigeria con I think best u just forget it and move on.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Is it really that easy to bypass firewall and antivirus? by Mike</title>
		<link>http://benghacks.wordpress.com/2006/01/13/is-it-really-that-easy-to-bypass-firewall-and-antivirus/#comment-85</link>
		<dc:creator>Mike</dc:creator>
		<pubDate>Wed, 10 Jun 2009 18:39:29 +0000</pubDate>
		<guid isPermaLink="false">http://benghacks.lah.cc/2006/01/13/is-it-really-that-easy-to-bypass-firewall-and-antivirus/#comment-85</guid>
		<description>Hi, I need someone who is able to get the password of a specific yahoo account (trojan horse?). This guy is located in Nigeria and did cheat me. He is still waiting for an e-mail from me (in fact he is expecting a word-file). If someone could help me (I would even pay to get this sucker), please send me an email to justanotheradress@gmail.com subject: nigeria
Thanks a lot! 

PS: I do have his IP address and I tried to get this bastard by myself, but I don&#039;t have the right tools...my trojans get detected and I&#039;m not able to join a working trojan or/and keylogger with a word document...please, help me to get this SOB.</description>
		<content:encoded><![CDATA[<p>Hi, I need someone who is able to get the password of a specific yahoo account (trojan horse?). This guy is located in Nigeria and did cheat me. He is still waiting for an e-mail from me (in fact he is expecting a word-file). If someone could help me (I would even pay to get this sucker), please send me an email to <a href="mailto:justanotheradress@gmail.com">justanotheradress@gmail.com</a> subject: nigeria<br />
Thanks a lot! </p>
<p>PS: I do have his IP address and I tried to get this bastard by myself, but I don&#8217;t have the right tools&#8230;my trojans get detected and I&#8217;m not able to join a working trojan or/and keylogger with a word document&#8230;please, help me to get this SOB.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Windows Vista Service Tweaks in Batch! by Sager NP8662: From the US to my room, a review! &#171; SlasherArcana&#8217;s blog</title>
		<link>http://benghacks.wordpress.com/2009/04/14/windows-vista-service-tweaks-in-batch/#comment-84</link>
		<dc:creator>Sager NP8662: From the US to my room, a review! &#171; SlasherArcana&#8217;s blog</dc:creator>
		<pubDate>Wed, 10 Jun 2009 02:55:49 +0000</pubDate>
		<guid isPermaLink="false">http://benghacks.wordpress.com/?p=92#comment-84</guid>
		<description>[...] system and the desktop had a few apps running including Spybot, FW, AV, IM, etc. Both also ran a Vista Service Tweak. The benchmark I decided to use was the X3:Terran Conflict Rolling Demo. In some circles it is [...]</description>
		<content:encoded><![CDATA[<p>[...] system and the desktop had a few apps running including Spybot, FW, AV, IM, etc. Both also ran a Vista Service Tweak. The benchmark I decided to use was the X3:Terran Conflict Rolling Demo. In some circles it is [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on ABS 2009 by Tim Meng</title>
		<link>http://benghacks.wordpress.com/2009/04/12/abs/#comment-81</link>
		<dc:creator>Tim Meng</dc:creator>
		<pubDate>Tue, 14 Apr 2009 05:07:36 +0000</pubDate>
		<guid isPermaLink="false">http://benghacks.wordpress.com/?p=95#comment-81</guid>
		<description>Hi, I am Tim Meng here. Please allow me to clarify some points you raised.

&lt;b&gt;But if you removed all the permissions how will u restore them?&lt;/b&gt; &lt;-- Once you uncheck the box to remove the permissions, you check it back to restore the permissions. If you read the checkbox, it says &quot;Inherit permissions ...&quot;.

&lt;b&gt;The malware you should be afraid of, do you think it will not account for Process Explorer?&lt;/b&gt; &lt;-- Very good point. Conficker does that. As such, there is a way to masquerade such that Conficker does not know Process Explorer runs.

&lt;b&gt;Problem is… the malware you’re not afraid of, antivirus will be able to detect anyway. The malware you should be afraid of, do you think it will not account for Process Explorer?&lt;/b&gt; &lt;-- Not true. Most of the time, I noticed the malware removed has not been detected by the antivirus. That is why I said, 25,000 virus everyday, AV software cannot keep up with the signatures.

&lt;b&gt;I once encountered a really naughty chinese malware, ... fix was to use a batch file to repeatedly kill both. In the race condition sooner or later the batch file will win.&lt;/b&gt; &lt;-- You are dealing with two exes, have you ever seen 5 exes protecting each other? :) Your method won&#039;t work.

&lt;b&gt;he said so far he never met anyone like that even tho there are script kiddies.&lt;/b&gt; &lt;-- Yes there are such people, but I can&#039;t say it out loud, and you know why.

I like your article on the analysis, basically covering what is on the mind of most people that I spoke to. I guess my 15th talk should address some FAQ on some of the points raised. Catch you again.


Regards,
Tim Meng</description>
		<content:encoded><![CDATA[<p>Hi, I am Tim Meng here. Please allow me to clarify some points you raised.</p>
<p><b>But if you removed all the permissions how will u restore them?</b> &lt;&#8211; Once you uncheck the box to remove the permissions, you check it back to restore the permissions. If you read the checkbox, it says &#8220;Inherit permissions &#8230;&#8221;.</p>
<p><b>The malware you should be afraid of, do you think it will not account for Process Explorer?</b> &lt;&#8211; Very good point. Conficker does that. As such, there is a way to masquerade such that Conficker does not know Process Explorer runs.</p>
<p><b>Problem is… the malware you’re not afraid of, antivirus will be able to detect anyway. The malware you should be afraid of, do you think it will not account for Process Explorer?</b> &lt;&#8211; Not true. Most of the time, I noticed the malware removed has not been detected by the antivirus. That is why I said, 25,000 virus everyday, AV software cannot keep up with the signatures.</p>
<p><b>I once encountered a really naughty chinese malware, &#8230; fix was to use a batch file to repeatedly kill both. In the race condition sooner or later the batch file will win.</b> &lt;&#8211; You are dealing with two exes, have you ever seen 5 exes protecting each other? <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  Your method won&#8217;t work.</p>
<p><b>he said so far he never met anyone like that even tho there are script kiddies.</b> &lt;&#8211; Yes there are such people, but I can&#8217;t say it out loud, and you know why.</p>
<p>I like your article on the analysis, basically covering what is on the mind of most people that I spoke to. I guess my 15th talk should address some FAQ on some of the points raised. Catch you again.</p>
<p>Regards,<br />
Tim Meng</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Process Hiding by ABS &#171; Beng Hacks</title>
		<link>http://benghacks.wordpress.com/2008/12/01/process-hiding/#comment-80</link>
		<dc:creator>ABS &#171; Beng Hacks</dc:creator>
		<pubDate>Tue, 14 Apr 2009 01:42:39 +0000</pubDate>
		<guid isPermaLink="false">http://benghacks.wordpress.com/?p=83#comment-80</guid>
		<description>[...] discussed this b4 in my Process Hiding article. The good news is that Process Explorer can view threads. Problem is you need to browse thru all [...]</description>
		<content:encoded><![CDATA[<p>[...] discussed this b4 in my Process Hiding article. The good news is that Process Explorer can view threads. Problem is you need to browse thru all [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on GovWare 2008 by RuFI0</title>
		<link>http://benghacks.wordpress.com/2008/10/09/govware-2008/#comment-79</link>
		<dc:creator>RuFI0</dc:creator>
		<pubDate>Sun, 12 Oct 2008 18:41:37 +0000</pubDate>
		<guid isPermaLink="false">http://benghacks.lah.cc/2008/10/09/govware-2008/#comment-79</guid>
		<description>Drop me an email regarding your HITB ticket</description>
		<content:encoded><![CDATA[<p>Drop me an email regarding your HITB ticket</p>
]]></content:encoded>
	</item>
</channel>
</rss>
