Wednesday, 18 March 2015
Password recovery with Elcomsoft System Recovery
You've forgotten your Windows password. What now?
Password reset accessibility hack
You've forgotten your Windows password. What now?
Password Reset Disk
You've forgotten your Windows password. What now?
Three ways to recover from a forgotten Windows password
I’ll show you three different ways to get back into your system:
1. The ‘right’ way
2. A free but dirty hack
3. An elegant but $50 hack
Thursday, 22 March 2012
Art critic vs. security consultant
the news at the time."
Bratsa Bonifacho’s Horty MyParty is Weird and CoolNow is a red and blue montage of letters and punctuation marks.
The characters are disfigured, disoriented and generally jumbled, although they retain their rigid position in a grid.
I suppose we might imagine an image of a computer program suffering some corruption.
Ann Rosenberg, a Vancouver-based critic and curator, wrote an article about the piece but was unable to discover information on the viruses that the work refers to:
"I have not found any evidence of them. But Googling up Horty and his putative party has been a visual treat and a mental roller-coaster."However, Sophos' Graham Cluley has found the relevant details, stating that:
"it is apparently inspired by a number of viruses from yesteryear including VBS/Horty (which claimed to offer pornographic content of adult film star Jenna Jameson), 2002's MyParty email worm, and the CoolNow MSN Messenger worm."Cluley acknowledges that he has less of a clue about art than viruses, though, and takes what I interpret to be a mocking tone when he says:
"Golly. What a chance I missed entering the field of computer security rather than art criticism. A layman like me wouldn't have understood that Bonifacho "communicates and expresses essentially non-verbal thoughts and emotions abstractly, within the discipline of formalism - through colour and shape, gesture and surface.." unless I had visited his website."
Thursday, 12 January 2012
25 years of computer viruses in pictures
You can view the entire 'infographic' or download a high-resolution version from F-Secure's blog.
To summarise, quickly, the history starts with Brain; runs through the likes of Melissa, Code Red and Love Letter (aka ILoveYou); and concludes with Stuxnet and Conficker.
Interestingly the chart includes Sony's used of rootkit-like technology. This not a virus, but uses an approach also used by some malware. Additionally, many of the other threats are actually worms rather than viruses.
Friday, 25 November 2011
Stuxnet explained: video
It provides significant evidence that nation states are using computers to undermine each other.
The well-made video below explains what Stuxnet is (a weapon in code form), what it did and poses some questions about the future.
It suggests, incorrectly as far as I know, that the source code is available. Thus far it is not "open source", as claimed in the video.
This is one of many pieces of recent media that explores the concept of cyber war. It is a controversial area, largely because there is little proof. Stuxnet is tangible evidence, which is why security companies are so excited about it.
Cold war, cyber war or simply war?
Eugene Kaspersky has just written an interesting article that poses the view that this type of cyber war, in which malicious code is used as a form of weapon, is a series of acts of international aggression. He believes that it is tantamount to cyber terrorism.
Malicious code such as Stuxnet can do a few things but one of the most interesting characteristics is its capacity for sabotage. In the Cold War of the 1980s there were claims of sabotage, but rarely anything as direct as the tasks that Stuxnet is capable of carrying out.
One similar incident involved the Trans-Siberian pipeline back in 1982. The US is said to have planted a logic bomb that resulted in a massive explosion. Rather than introducing a virus from a network or USB key, the theory goes that US programmers planted the malicious code into a program that they knew would be stolen by the Russians.
Stuxnet: Anatomy of a Computer Virus from Patrick Clair on Vimeo.
Thursday, 10 November 2011
First malware was for the Mac
![]() |
| Elk Cloner was the first virus to affect desktop computers |
I've heard this claim from many Mac users as well as from the company itself. However, it just so happens that the very first known piece of malware was written for the Mac*.
The Elk Cloner program was written by Rich Skrenta in 1982 (a year before Fred Cohen demonstrated a virus proof of concept on
Skrenta has a website with a page dedicated to Elk Cloner. If you want to know what it looked like, see the image above.
Apple plays down the malware threat to Macs and makes interesting claims such as, "A Mac isn’t susceptible to the thousands of viruses plaguing Windows." This is, perhaps, rather obvious. In the same way, a Windows PC isn't susceptible to malware that affects Macs.
The same can't be said for Macs versus Linux computers, though. There is some compatibility, which means that Linux malware can sometimes run on Macs (perhaps with a little tweaking).
Mikko Hypponen from F-Secure has presented a short documentary about the Brain virus and even interviewed the original authors, who are legitimate businessmen working from the same address as they were in 1986. You can watch this below:
* It really depends on how you define virus, malware and so on but arguably the first virus was a worm called Pervade, which was unleashed onto UNIVAC systems in 1975 by John Walker. It wasn't an internet worm, though, because 'the internet' did not exist in the way that it does today.
** Thanks to Anonymous (below) for noting my stupid mistake :)
Tuesday, 8 November 2011
Computer worm simulation (Sasser)
The globe (left) represents the worm's progress across the world. The diagram (right) shows how it affects different types of network.
The Sasser worm starts off slow but kicks into action halfway through the second day.
Read about (and visualise) more viruses and other threats.
Monday, 7 November 2011
Computer worm simulation
The two circles represent two different companies. When the malware infects a system within these companies a coloured blog turns red.
Each company works in slightly different ways. The settings screen that appears at the beginning of the video shows how they differ. You can see how the differences affect the spread of the worm.
In this example I've set the simulator to show the effects the Melissa worm could have. You should notice that one company (Corporation 2) becomes completely infected much faster than the other.
Read about (and visualise) more viruses and other threats.
Wednesday, 2 December 2009
Rogues' Gallery: Fake AV Software
Monday, 19 October 2009
Rogue Anti-Virus Software
When Symantec announced that it has identified 250 different types we thought it might be useful to write a news story about it and to use video footage taken in my virus lab to illustrate what these fake anti-virus programs look like. As you'll see if you click through to the story (or the video below), they are pretty convincing!
Tuesday, 5 May 2009
The art of internet threats
Message Labs has produced another range of visualisations. This time is has updated its archive with representations of some more recent threats, as well as illustrating its email services.The new images are now available from the Message Labs site.
Monday, 22 December 2008
A network being disconnected (video)
The video below was generated by HostExploit.com, using software called BGPlay. BGPlay "is a Java application which displays animated graphs of the routing activity of a certain prefix within a specified time interval." In other words, it creates a visual representation of internet connections. The video below shows McColo struggling to reconnect to the internet during Saturday 15th and Sunday 16th November 2008.
Saturday, 10 May 2008
What does a botnet look like?
The idea that criminals have harnessed the power of hundreds of thousands of innocent computers, forming massive networks designed to perform evil deeds, is hard for the general public to swallow. It's also quite a tricky concept to visualise.
That has not stopped David Voreland and Scott Berinato from trying. They have created a map of interconnected botnet systems. It's interesting - is your system on it?
Monday, 10 March 2008
Background to computer crime
It just so happens that this article coincides with the unveiling of an art project by UK security firm MessageLabs. The company set out to create visual representations of virus code, spam and phishing emails with the help of Romanian visual artist Alex Dragulescu. The aim was to give a face to something that is rather hard to imagine as a physical object. It's actually pretty interesting to compare how the threats look to how they behave. MessageLabs' experts delivered an interesting talk about this, also explaining how bad guys make money by operating online threats.
I wrote a short note about this project a couple of months ago.
The Associated Press (AP) has created a short piece of video coverage for the exhibition and asked me to talk about some of the reasons why these threats exist. You can view the video by clicking below...
Note: Despite the caption, I am not 'Editor' of Computer Shopper. That honour belongs to David Ludlow.
Monday, 28 January 2008
Visualising viruses
What does a computer virus look like? Previously I've looked at a couple of interesting ways in which people have represented computer code visually. Today a colleague pointed me to Alex Dragulescu's website. This visual artist has used an analysis of "disassembled code, API calls, memory addresses and subroutines" to create 3D images.
The results are fascinating. MyDoom, for example, actually looks like a virus (or at least, it looks like something you might see down a microscope in a sci-fi movie). The Storm worm looks like it would be quite happy living at the bottom of the ocean.
Alex Dragulescu's representation of MyDoom
Friday, 6 July 2007
What does a computer virus look like?
In reality, and on the surface, a virus might appear in your email as an attachment, perhaps pretending to be an image or a security update from Microsoft. So that innocent-looking icon is one way that computer viruses can appear to the human eye.
But wouldn't it be more interesting to look beyond the image of an icon and see what it looks like under the hood?
Virus researchers use tools like Interactive Disassembler Pro (IDA) to reverse engineer malware. So you could argue that a virus looks like this program's output, as below:

This might be an accurate view, but it's not very exciting. I can't see this appearing in The Matrix IV. Anti-virus company F-Secure has developed a new tool that provides a pretty amazing, movie-style view of the effects a virus has on a computer system. The view below illustrates it. Add a pumping soundtrack and a 3D version of Bruce Willis and you've got Die Hard 5.1 (build 366478).
Read about (and visualise) more viruses and other threats.





