<?xml version="1.0" encoding="UTF-8" ?>
<rss version="2.0">
<channel>
	<title>Tuts 4 You : Forum</title>
	<description>http://forum.tuts4you.com/</description>
	<link>http://forum.tuts4you.com</link>
	<pubDate>Wed, 22 Feb 2012 18:26:45 +0000</pubDate>
	<ttl>0</ttl>
	<item>
		<title><![CDATA[[ Game Review ]  Darkness 2]]></title>
		<link>http://forum.tuts4you.com/topic/28468-game-review-darkness-2/</link>
		<description><![CDATA[<span rel='lightbox'><img src='http://cdn.themis-media.com/media/global/images/library/deriv/29/29306.png' alt='Posted Image' class='bbc_img' /></span><br />
This week, <em class='bbc'>Zero Punctuation</em> reviews <em class='bbc'>Darkness 2</em>.<br />
<br />
<a href='http://www.escapistmagazine.com/videos/view/zero-punctuation/5394-Darkness-2?utm_source=rss&utm_medium=rss&utm_campaign=videos' class='bbc_url' title='External link' rel='nofollow external'>View the full article</a>]]></description>
		<pubDate>Wed, 22 Feb 2012 18:26:45 +0000</pubDate>
		<guid>http://forum.tuts4you.com/topic/28468-game-review-darkness-2/</guid>
	</item>
	<item>
		<title>TED: Shilo Shiv Suleman: Using tech to enable dreaming - Shilo Shiv Su</title>
		<link>http://forum.tuts4you.com/topic/28469-ted-shilo-shiv-suleman-using-tech-to-enable-dreaming-shilo-shiv-suleman-2011/</link>
		<description><![CDATA[Has our technology -- our cell phones and iPods and cameras -- stopped us from dreaming? Young artist Shilo Shiv Suleman says no, as she demos "Khoya," her new storybook for iPad, which floats us through a magical world in 7 minutes of pure creativity.http://feeds.feedburner.com/~r/TEDTalks_video/~4/uFa8MUhKj4w<br />
<br />
<a href='http://feedproxy.google.com/~r/TEDTalks_video/~3/uFa8MUhKj4w/shilo_shiv_suleman_using_tech_to_enable_dreaming.html' class='bbc_url' title='External link' rel='nofollow external'>View the full article</a>]]></description>
		<pubDate>Wed, 22 Feb 2012 16:59:48 +0000</pubDate>
		<guid>http://forum.tuts4you.com/topic/28469-ted-shilo-shiv-suleman-using-tech-to-enable-dreaming-shilo-shiv-suleman-2011/</guid>
	</item>
	<item>
		<title><![CDATA[[ BBC Tech ]  EU court to rule on Acta legality]]></title>
		<link>http://forum.tuts4you.com/topic/28467-bbc-tech-eu-court-to-rule-on-acta-legality/</link>
		<description><![CDATA[A controversial anti-piracy agreement is to be referred to the EU's highest court due to concerns surrounding internet freedoms.<br />
<br />
<a href='http://www.bbc.co.uk/go/rss/int/news/-/news/technology-17125469' class='bbc_url' title='External link' rel='nofollow external'>View the full article</a>]]></description>
		<pubDate>Wed, 22 Feb 2012 13:03:23 +0000</pubDate>
		<guid>http://forum.tuts4you.com/topic/28467-bbc-tech-eu-court-to-rule-on-acta-legality/</guid>
	</item>
	<item>
		<title><![CDATA[[ Kasp. Lab ]  DDoS attacks in H2 2011]]></title>
		<link>http://forum.tuts4you.com/topic/28466-kasp-lab-ddos-attacks-in-h2-2011/</link>
		<description><![CDATA[All statistical data used in this report were obtained using Kaspersky Lab's botnet monitoring system and Kaspersky DDoS Prevention.<br />
<br />
<a href='http://www.securelist.com/en/analysis/204792221/DDoS_attacks_in_H2_2011' class='bbc_url' title='External link' rel='nofollow external'>View the full article</a>]]></description>
		<pubDate>Wed, 22 Feb 2012 11:11:07 +0000</pubDate>
		<guid>http://forum.tuts4you.com/topic/28466-kasp-lab-ddos-attacks-in-h2-2011/</guid>
	</item>
	<item>
		<title><![CDATA[DEFCON :  DEF CON 20 Contest &#38; Event RFI]]></title>
		<link>http://forum.tuts4you.com/topic/28465-defcon-def-con-20-contest-event-rfi/</link>
		<description><![CDATA[The DEF CON 20 Contest & Event Request for Information is live! If you already run or want to run a contest or event at DEF CON 20, it's where to find all of the info you need to get your contest or event on the map! Check it out at: &lt;a href="html/defcon-20/dc-20-contest-rfi.html"&gt;https://www.defcon.org/html/defcon-20/dc-20-contest-rfi.html<br />
<br />
<a href='https://www.defcon.org/html/defcon-20/dc-20-contest-rfi.html' class='bbc_url' title='External link' rel='nofollow external'>View the full article</a>]]></description>
		<pubDate>Wed, 22 Feb 2012 03:07:22 +0000</pubDate>
		<guid>http://forum.tuts4you.com/topic/28465-defcon-def-con-20-contest-event-rfi/</guid>
	</item>
	<item>
		<title><![CDATA[[ BBC Tech ]  Megaupload founder granted bail]]></title>
		<link>http://forum.tuts4you.com/topic/28464-bbc-tech-megaupload-founder-granted-bail/</link>
		<description><![CDATA[The founder of shut down file-sharing website Megaupload, Kim Dotcom, is granted bail by a New Zealand court.<br />
<br />
<a href='http://www.bbc.co.uk/go/rss/int/news/-/news/business-17122866' class='bbc_url' title='External link' rel='nofollow external'>View the full article</a>]]></description>
		<pubDate>Wed, 22 Feb 2012 01:24:12 +0000</pubDate>
		<guid>http://forum.tuts4you.com/topic/28464-bbc-tech-megaupload-founder-granted-bail/</guid>
	</item>
	<item>
		<title><![CDATA[[ HITB ]  Fake RIAA copyright violation notification serves malware]]></title>
		<link>http://forum.tuts4you.com/topic/28463-hitb-fake-riaa-copyright-violation-notification-serves-malware/</link>
		<description><![CDATA[<span rel='lightbox'><img src='http://news.hitb.org/sites/default/files/styles/medium/public/field/image/fake-riaa-notice.jpg' alt='Posted Image' class='bbc_img' /></span><br />
<br />
<br />
<br />
First spotted nearly a week ago, notifications of copyright violation supposedly sent by the Recording Industry Association of America are still hitting inboxes around the world.<br />
 The sender's email address is spoofed to make the message seem legitimate, and the email contains a warning and an attachment that the user is asked to open in order to see details of the violation. <br />
<br />
Tags: <br />
<br />
Industry News<br />
Viruses & Malware<br />
<br />
<a href='http://news.hitb.org/content/fake-riaa-copyright-violation-notification-serves-malware' class='bbc_url' title='External link' rel='nofollow external'>View the full article</a>]]></description>
		<pubDate>Wed, 22 Feb 2012 00:40:17 +0000</pubDate>
		<guid>http://forum.tuts4you.com/topic/28463-hitb-fake-riaa-copyright-violation-notification-serves-malware/</guid>
	</item>
	<item>
		<title><![CDATA[[ BBC Tech ]  Late Playbook OS upgrade released]]></title>
		<link>http://forum.tuts4you.com/topic/28462-bbc-tech-late-playbook-os-upgrade-released/</link>
		<description><![CDATA[Research in Motion releases an update to the Blackberry Playbook - almost a year later than first promised.<br />
<br />
<a href='http://www.bbc.co.uk/go/rss/int/news/-/news/technology-17118211' class='bbc_url' title='External link' rel='nofollow external'>View the full article</a>]]></description>
		<pubDate>Tue, 21 Feb 2012 20:11:06 +0000</pubDate>
		<guid>http://forum.tuts4you.com/topic/28462-bbc-tech-late-playbook-os-upgrade-released/</guid>
	</item>
	<item>
		<title>OllyDbg Fake ImageName Bug</title>
		<link>http://forum.tuts4you.com/topic/28459-ollydbg-fake-imagename-bug/</link>
		<description><![CDATA[I have recently found a weird behavior in OllyDbg, which can further be used as an anti-debugging / anti-attaching trick. The problem occurs when enumerating the running processes if the "Select a process to attach" dialog box is opened.<br />
<br />
The psapi "EnumProcesses" function is called to get the list of process identifiers (PIDs). For each PID, the psapi "EnumProcessModules" and "GetModuleFileNameExA" functions are called to extract the image base and full name of the main executable.<br />
<br />
As i have shown in previous posts, the values in  PEB.LoaderData can easily be manipulated. In this case i will manipulate only the full name of the main executable to be of an existing but malformed file. Surprisingly, OllyDbg trusts the new file name and starts to extract essential information from it. Information extracted includes MZ signature, optional header values, section table data, etc.<br />
<br />
The interesting thing about the forged executable is that it is rejected by the OS loader but still used by OllyDbg.<br />
<br />
To create a one-file demo for this bug, i had to embed the malformed executable into the original one as a binary resource.<br />
<span rel='lightbox'><img src='http://2.bp.blogspot.com/-HtYrmSWUGSk/T0MRt_jrc0I/AAAAAAAAAVk/Bt5mdFUsPJY/s1600/Untitled.png' alt='Posted Image' class='bbc_img' /></span><br />
As you can see in the image below, the number of sections is set to 0xFFFF (malformed executable).<br />
<span rel='lightbox'><img src='http://3.bp.blogspot.com/-knN1Lc88re4/T0MSuzBqW_I/AAAAAAAAAVs/qXaGghV_XmQ/s1600/Untitled_.png' alt='Posted Image' class='bbc_img' /></span><br />
The demo can be found here.<br />
<a href='http://ollytlscatch.googlecode.com/files/attach_to_me.exe' class='bbc_url' title='External link' rel='nofollow external'>http://ollytlscatch....ttach_to_me.exe</a><br />
The virustotal report can be found here.<br />
<a href='https://www.virustotal.com/file/2ffe26ebc652e4021d57c2656a848f83119a07669f8cc54e2849ca36cb3e0b93/analysis/1329795141/' class='bbc_url' title='External link' rel='nofollow external'>https://www.virustot...sis/1329795141/</a><br />
N.B. This has been tested on OllyDbg v1.10 only.<br />
<br />
Update:<br />
Another demo, that crashes OllyDbg upon debugging or attaching, has been created. You can find it here.<br />
<a href='http://ollytlscatch.googlecode.com/files/Debug_me.exe' class='bbc_url' title='External link' rel='nofollow external'>http://ollytlscatch....es/Debug_me.exe</a>]]></description>
		<pubDate>Tue, 21 Feb 2012 17:20:19 +0000</pubDate>
		<guid>http://forum.tuts4you.com/topic/28459-ollydbg-fake-imagename-bug/</guid>
	</item>
	<item>
		<title>TED: Chris Bliss: Comedy is translation - Chris Bliss (2011)</title>
		<link>http://forum.tuts4you.com/topic/28460-ted-chris-bliss-comedy-is-translation-chris-bliss-2011/</link>
		<description><![CDATA[Every act of communication is, in some way, an act of translation. Onstage at TEDxRainier, writer Chris Bliss thinks hard about the way that great comedy can translate deep truths for a mass audience.http://feeds.feedburner.com/~r/TEDTalks_video/~4/5YfmJWl_730<br />
<br />
<a href='http://feedproxy.google.com/~r/TEDTalks_video/~3/5YfmJWl_730/chris_bliss_comedy_is_translation.html' class='bbc_url' title='External link' rel='nofollow external'>View the full article</a>]]></description>
		<pubDate>Tue, 21 Feb 2012 16:54:58 +0000</pubDate>
		<guid>http://forum.tuts4you.com/topic/28460-ted-chris-bliss-comedy-is-translation-chris-bliss-2011/</guid>
	</item>
</channel>
</rss>
