<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title></title>
	<atom:link href="http://somebastardstolemyname.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://somebastardstolemyname.wordpress.com</link>
	<description></description>
	<lastBuildDate>Wed, 14 Dec 2011 19:17:18 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='somebastardstolemyname.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title></title>
		<link>http://somebastardstolemyname.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://somebastardstolemyname.wordpress.com/osd.xml" title="" />
	<atom:link rel='hub' href='http://somebastardstolemyname.wordpress.com/?pushpress=hub'/>
		<item>
		<title>Lack of activity</title>
		<link>http://somebastardstolemyname.wordpress.com/2010/08/23/lack-of-activity/</link>
		<comments>http://somebastardstolemyname.wordpress.com/2010/08/23/lack-of-activity/#comments</comments>
		<pubDate>Mon, 23 Aug 2010 19:36:04 +0000</pubDate>
		<dc:creator>Rhys M.</dc:creator>
				<category><![CDATA[Random Crap]]></category>

		<guid isPermaLink="false">http://somebastardstolemyname.wordpress.com/?p=119</guid>
		<description><![CDATA[Well its been quite a while now since I&#8217;ve last updated my blog, yet its just passed 42,600 hits! Anyway, my time is now predominantly taken up by a new activity, with minimal time spent behind a computer, and even less time spent programming. I&#8217;ve taken up flying.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=somebastardstolemyname.wordpress.com&amp;blog=849487&amp;post=119&amp;subd=somebastardstolemyname&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Well its been quite a while now since I&#8217;ve last updated my blog, yet its just passed 42,600 hits! Anyway, my time is now predominantly taken up by a new activity, with minimal time spent behind a computer, and even less time spent programming. I&#8217;ve taken up flying.</p>
<p><img class="alignnone" title="flying1" src="http://img405.imageshack.us/img405/4567/photo0081mr.jpg" alt="" width="300" height="400" /><img class="alignnone" title="flying2" src="http://img827.imageshack.us/img827/1917/photo0119.jpg" alt="" width="300" height="400" /></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/somebastardstolemyname.wordpress.com/119/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/somebastardstolemyname.wordpress.com/119/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/somebastardstolemyname.wordpress.com/119/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/somebastardstolemyname.wordpress.com/119/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/somebastardstolemyname.wordpress.com/119/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/somebastardstolemyname.wordpress.com/119/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/somebastardstolemyname.wordpress.com/119/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/somebastardstolemyname.wordpress.com/119/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/somebastardstolemyname.wordpress.com/119/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/somebastardstolemyname.wordpress.com/119/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/somebastardstolemyname.wordpress.com/119/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/somebastardstolemyname.wordpress.com/119/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/somebastardstolemyname.wordpress.com/119/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/somebastardstolemyname.wordpress.com/119/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=somebastardstolemyname.wordpress.com&amp;blog=849487&amp;post=119&amp;subd=somebastardstolemyname&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://somebastardstolemyname.wordpress.com/2010/08/23/lack-of-activity/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">The_Undead</media:title>
		</media:content>

		<media:content url="http://img405.imageshack.us/img405/4567/photo0081mr.jpg" medium="image">
			<media:title type="html">flying1</media:title>
		</media:content>

		<media:content url="http://img827.imageshack.us/img827/1917/photo0119.jpg" medium="image">
			<media:title type="html">flying2</media:title>
		</media:content>
	</item>
		<item>
		<title>[ General Problem ] EPROCESS-ImageFileName + NtOpenProcessHook</title>
		<link>http://somebastardstolemyname.wordpress.com/2009/11/21/general-problem-eprocess-imagefilename-ntopenprocesshook/</link>
		<comments>http://somebastardstolemyname.wordpress.com/2009/11/21/general-problem-eprocess-imagefilename-ntopenprocesshook/#comments</comments>
		<pubDate>Sat, 21 Nov 2009 20:01:48 +0000</pubDate>
		<dc:creator>Rhys M.</dc:creator>
				<category><![CDATA[Programming]]></category>

		<guid isPermaLink="false">http://somebastardstolemyname.wordpress.com/?p=111</guid>
		<description><![CDATA[Ok well a few of my pieces of code here rely upon the ImageFileName element within the EPROCESS structure (which you can find in the ntifs_6001.h) header I&#8217;ve uploaded. Again, in 7600 it seems to be missing. Weird. Anyway, the problem was that ImageFileName was returning nothing. Blank. So evidently the offset has changed. I [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=somebastardstolemyname.wordpress.com&amp;blog=849487&amp;post=111&amp;subd=somebastardstolemyname&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Ok well a few of my pieces of code here rely upon the ImageFileName element within the EPROCESS structure (which you can find in the ntifs_6001.h) header I&#8217;ve uploaded. Again, in 7600 it seems to be missing. Weird.<br />
Anyway, the problem was that ImageFileName was returning nothing. Blank. So evidently the offset has changed. I wrote a peice of code to enumerate the base addresses of each EPROCESS structure and then looked at them in Win Dbg, have a look:<br />
<a href="http://img262.imageshack.us/img262/1724/kernelmemoryeprocess.jpg" target="_blank"><img src="http://img262.imageshack.us/img262/1724/kernelmemoryeprocess.jpg" alt="null" width="425" height="278" /></a></p>
<p>That image should pretty much give you an idea of what to do. Count the bytes. Find the new offset.<br />
Previously the offset for ImageFileName was +0&#215;154 now all of a sudden its +0&#215;174. To implement search for this offset programmatically, search the memory from each EPROCESS base for the string &#8220;system&#8221;. As it will ALWAYS be there, makes for an easy way to determine the correct offset.</p>
<p>I have attached an updated version of my <a href="http://somebastardstolemyname.wordpress.com/2008/10/04/c-ntopenprocess-hook/">NtOpenProcessHook</a> below with the fix.<br />
The hack (this is too crude to be a fix!) lies in the RetrievePID() function. So have a look there for comparison.</p>
<p><a href="http://somebastardstolemyname.wordpress.com/2008/10/04/c-ntopenprocess-hook/">[ Link ] My Old NtOpenProcessHook post</a><br />
<a href="http://theundead.atspace.com/Blog/FixedNtOpenProcessHookDriver.c.txt">[ C - Source ] New NtOpenProcessHook Driver</a><br />
<a href="http://theundead.atspace.com/Blog/CNtOpenProcessDrver.txt">[ C - Source ] Old NtOpenProcessHook Driver</a><br />
<a href="http://www.box.net/shared/lyd973fjv7">[ C - Header ] ntifs_6001.h</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/somebastardstolemyname.wordpress.com/111/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/somebastardstolemyname.wordpress.com/111/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/somebastardstolemyname.wordpress.com/111/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/somebastardstolemyname.wordpress.com/111/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/somebastardstolemyname.wordpress.com/111/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/somebastardstolemyname.wordpress.com/111/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/somebastardstolemyname.wordpress.com/111/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/somebastardstolemyname.wordpress.com/111/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/somebastardstolemyname.wordpress.com/111/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/somebastardstolemyname.wordpress.com/111/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/somebastardstolemyname.wordpress.com/111/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/somebastardstolemyname.wordpress.com/111/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/somebastardstolemyname.wordpress.com/111/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/somebastardstolemyname.wordpress.com/111/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=somebastardstolemyname.wordpress.com&amp;blog=849487&amp;post=111&amp;subd=somebastardstolemyname&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://somebastardstolemyname.wordpress.com/2009/11/21/general-problem-eprocess-imagefilename-ntopenprocesshook/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">The_Undead</media:title>
		</media:content>

		<media:content url="http://img262.imageshack.us/img262/1724/kernelmemoryeprocess.jpg" medium="image">
			<media:title type="html">null</media:title>
		</media:content>
	</item>
		<item>
		<title>[ C ] Entry Point Hook</title>
		<link>http://somebastardstolemyname.wordpress.com/2009/01/30/c-entry-point-hook/</link>
		<comments>http://somebastardstolemyname.wordpress.com/2009/01/30/c-entry-point-hook/#comments</comments>
		<pubDate>Fri, 30 Jan 2009 19:31:30 +0000</pubDate>
		<dc:creator>Rhys M.</dc:creator>
				<category><![CDATA[Programming]]></category>

		<guid isPermaLink="false">http://somebastardstolemyname.wordpress.com/?p=102</guid>
		<description><![CDATA[This was an idea that I used in the Rootkit idea below. Just a extract explained. [ .rar ] Project files [ C - Source ] PEInfect Unmodified program shown in PE Explorer. Unmodified programs entry point shown in ollydbg. Modified program shown in PE Explorer: Modified programs entry point shown in ollydbg:<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=somebastardstolemyname.wordpress.com&amp;blog=849487&amp;post=102&amp;subd=somebastardstolemyname&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>This was an idea that I used in the Rootkit idea below.<br />
Just a extract explained.<br />
<a href="http://www.box.net/shared/ur6kha36xu">[ .rar ] Project files</a><br />
<a href="http://theundead.atspace.com/Blog/PEInfect.cpp.txt">[ C - Source ] PEInfect</a></p>
<p><a href="http://img164.imageshack.us/img164/1999/beforepedn3.jpg">Unmodified program shown in PE Explorer.</a><br />
<a href="http://img291.imageshack.us/img291/5711/beforeollyjw8.jpg">Unmodified programs entry point shown in ollydbg.</a></p>
<p><strong>Modified program shown in PE Explorer:</strong><br />
<img src="http://img407.imageshack.us/img407/4362/afterperw8.jpg" /><br />
<strong>Modified programs entry point shown in ollydbg:</strong><br />
<img src="http://img132.imageshack.us/img132/5826/afterollysl5.jpg" /></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/somebastardstolemyname.wordpress.com/102/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/somebastardstolemyname.wordpress.com/102/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/somebastardstolemyname.wordpress.com/102/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/somebastardstolemyname.wordpress.com/102/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/somebastardstolemyname.wordpress.com/102/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/somebastardstolemyname.wordpress.com/102/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/somebastardstolemyname.wordpress.com/102/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/somebastardstolemyname.wordpress.com/102/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/somebastardstolemyname.wordpress.com/102/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/somebastardstolemyname.wordpress.com/102/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/somebastardstolemyname.wordpress.com/102/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/somebastardstolemyname.wordpress.com/102/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/somebastardstolemyname.wordpress.com/102/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/somebastardstolemyname.wordpress.com/102/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=somebastardstolemyname.wordpress.com&amp;blog=849487&amp;post=102&amp;subd=somebastardstolemyname&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://somebastardstolemyname.wordpress.com/2009/01/30/c-entry-point-hook/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">The_Undead</media:title>
		</media:content>

		<media:content url="http://img407.imageshack.us/img407/4362/afterperw8.jpg" medium="image" />

		<media:content url="http://img132.imageshack.us/img132/5826/afterollysl5.jpg" medium="image" />
	</item>
		<item>
		<title>[C - Unfinished] simple-rootkit-worm?</title>
		<link>http://somebastardstolemyname.wordpress.com/2009/01/27/c-very-unfinished-simple-rootkit-worm/</link>
		<comments>http://somebastardstolemyname.wordpress.com/2009/01/27/c-very-unfinished-simple-rootkit-worm/#comments</comments>
		<pubDate>Tue, 27 Jan 2009 18:47:01 +0000</pubDate>
		<dc:creator>Rhys M.</dc:creator>
				<category><![CDATA[Programming]]></category>

		<guid isPermaLink="false">http://somebastardstolemyname.wordpress.com/?p=83</guid>
		<description><![CDATA[This was the result of me messing around last November. Shows just how easy a rootkit with simple worm characteristics could be to write, but I got bored with it and it hasnt progressed for the past two months, but I may as well post it. What needs to be finished, as far as I [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=somebastardstolemyname.wordpress.com&amp;blog=849487&amp;post=83&amp;subd=somebastardstolemyname&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>This was the result of me messing around last November.<br />
Shows just how easy a rootkit with simple worm characteristics could be to write, but I got bored with it and it hasnt progressed for the past two months, but I may as well post it.<br />
What needs to be finished, as far as I can see is:<br />
<em>-prevent remodifying the target-files PE-Header.<br />
-the mailbox system. Makes sure only one copy of the file is run at a time to ensure agaisnt driver crashes.<br />
-all the strings need to be encrypted and then decrypted when used and erased.<br />
-all allocated memory needs to be deallocated.</em><br />
<strong>Rootkit:</strong><br />
<a href="http://www.box.net/shared/ceqkzup6di">[ .rar ]Project Files (Driver/Application)</a><br />
<a href="http://theundead.atspace.com/Blog/TurkDriver.c.txt">[ C - Source ]Driver</a><br />
<a href="http://theundead.atspace.com/Blog/turk.cpp.txt">[ C++ - Source ]Main program</a><br />
<a href="http://www.box.net/shared/lyd973fjv7">ntifs.h</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/somebastardstolemyname.wordpress.com/83/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/somebastardstolemyname.wordpress.com/83/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/somebastardstolemyname.wordpress.com/83/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/somebastardstolemyname.wordpress.com/83/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/somebastardstolemyname.wordpress.com/83/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/somebastardstolemyname.wordpress.com/83/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/somebastardstolemyname.wordpress.com/83/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/somebastardstolemyname.wordpress.com/83/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/somebastardstolemyname.wordpress.com/83/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/somebastardstolemyname.wordpress.com/83/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/somebastardstolemyname.wordpress.com/83/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/somebastardstolemyname.wordpress.com/83/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/somebastardstolemyname.wordpress.com/83/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/somebastardstolemyname.wordpress.com/83/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=somebastardstolemyname.wordpress.com&amp;blog=849487&amp;post=83&amp;subd=somebastardstolemyname&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://somebastardstolemyname.wordpress.com/2009/01/27/c-very-unfinished-simple-rootkit-worm/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">The_Undead</media:title>
		</media:content>
	</item>
		<item>
		<title>[C] A simple interpreted language</title>
		<link>http://somebastardstolemyname.wordpress.com/2009/01/03/c-a-simple-interpreted-language/</link>
		<comments>http://somebastardstolemyname.wordpress.com/2009/01/03/c-a-simple-interpreted-language/#comments</comments>
		<pubDate>Sat, 03 Jan 2009 10:46:00 +0000</pubDate>
		<dc:creator>Rhys M.</dc:creator>
				<category><![CDATA[Programming]]></category>

		<guid isPermaLink="false">http://somebastardstolemyname.wordpress.com/?p=80</guid>
		<description><![CDATA[Someone asked me the other-day about writing a simple scripting language, so I got around to playing around a bit, and ended up writing a simple interpreter. In appearance I guess it looks something like a cross between assembly (source, destination) and BASIC: It supports a simple form of loops, variable storage and retrieval, basic [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=somebastardstolemyname.wordpress.com&amp;blog=849487&amp;post=80&amp;subd=somebastardstolemyname&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Someone asked me the other-day about writing a simple scripting language, so I got around to playing around a bit, and ended up writing a simple interpreter. In appearance I guess it looks something like a cross between assembly (source, destination) and BASIC:<br />
<img class="alignnone" title="interpreterscript" src="http://img117.imageshack.us/img117/5237/interpreterscriptof1.jpg" alt="" width="308" height="273" /></p>
<p><img class="alignnone" title="InterpreterCConsole" src="http://img211.imageshack.us/img211/4646/interpreterrk7.jpg" alt="" width="365" height="153" /></p>
<p>It supports a simple form of loops, variable storage and retrieval, basic (limited functionality at this point) conditional statements, variable output.<br />
Download:<br />
<a href="http://theundead.atspace.com/Blog/CInterpreter.txt">-source code here.</a><br />
<a href="http://www.box.net/shared/6psxy2gh85">-Project Files here (contains script file)</a><br />
<a href="http://theundead.atspace.com/Blog/Script.tus.txt">-sample script file</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/somebastardstolemyname.wordpress.com/80/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/somebastardstolemyname.wordpress.com/80/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/somebastardstolemyname.wordpress.com/80/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/somebastardstolemyname.wordpress.com/80/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/somebastardstolemyname.wordpress.com/80/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/somebastardstolemyname.wordpress.com/80/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/somebastardstolemyname.wordpress.com/80/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/somebastardstolemyname.wordpress.com/80/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/somebastardstolemyname.wordpress.com/80/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/somebastardstolemyname.wordpress.com/80/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/somebastardstolemyname.wordpress.com/80/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/somebastardstolemyname.wordpress.com/80/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/somebastardstolemyname.wordpress.com/80/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/somebastardstolemyname.wordpress.com/80/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=somebastardstolemyname.wordpress.com&amp;blog=849487&amp;post=80&amp;subd=somebastardstolemyname&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://somebastardstolemyname.wordpress.com/2009/01/03/c-a-simple-interpreted-language/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">The_Undead</media:title>
		</media:content>

		<media:content url="http://img117.imageshack.us/img117/5237/interpreterscriptof1.jpg" medium="image">
			<media:title type="html">interpreterscript</media:title>
		</media:content>

		<media:content url="http://img211.imageshack.us/img211/4646/interpreterrk7.jpg" medium="image">
			<media:title type="html">InterpreterCConsole</media:title>
		</media:content>
	</item>
		<item>
		<title>[ C ] NtOpenProcess hook.</title>
		<link>http://somebastardstolemyname.wordpress.com/2008/10/04/c-ntopenprocess-hook/</link>
		<comments>http://somebastardstolemyname.wordpress.com/2008/10/04/c-ntopenprocess-hook/#comments</comments>
		<pubDate>Sat, 04 Oct 2008 00:03:21 +0000</pubDate>
		<dc:creator>Rhys M.</dc:creator>
				<category><![CDATA[Programming]]></category>

		<guid isPermaLink="false">http://somebastardstolemyname.wordpress.com/?p=44</guid>
		<description><![CDATA[A &#8216;Crude&#8217; method of preventing access to a program is by hooking NtOpenProcess and denying any request for a handle. Simple. The screenshot below shows what happens when I tried to terminate notepad, which at the time was &#8216;protected&#8217; by this hook. A detour hook would be preferable to an SSDT pointer change as it [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=somebastardstolemyname.wordpress.com&amp;blog=849487&amp;post=44&amp;subd=somebastardstolemyname&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>A &#8216;Crude&#8217; method of preventing access to a program is by hooking NtOpenProcess and denying any request for a handle. Simple. The screenshot below shows what happens when I tried to terminate notepad, which at the time was &#8216;protected&#8217; by this hook. A detour hook would be preferable to an SSDT pointer change as it is less detectable, but I&#8217;ll cover that some other time.</p>
<p><img src="http://img211.imageshack.us/img211/5259/ntopenprocesshook.jpg" alt="" /></p>
<p><a href="http://theundead.atspace.com/Blog/CNtOpenProcessDrver.txt" target="_blank">[ C - Source ] Driver.c</a><br />
<a href="http://theundead.atspace.com/Blog/CPPNtOpenProcessDriverControl.txt" target="_blank">[ C++ - Source ] DriverControll.cpp</a><br />
<a href="http://www.box.net/shared/s56adhg5k6" target="_blank">Download</a> the compiled executable.<br />
<a href="http://www.box.net/shared/lyd973fjv7">ntifs.h</a><br />
<a href="http://somebastardstolemyname.wordpress.com/2009/11/21/general-problem-eprocess-imagefilename-ntopenprocesshook" target="_blank">NEW post regarding NtOpenProcess hooks</a></p>
<p>Operation:  Once the executable has been run and you&#8217;ve entered your target process name (with the .exe!) and you are presented with an arrow (&#8211;&gt;), you have three commands. HOOK, UNHOOK, EXIT. They&#8217;re fairly explanatory. Unhook before you exit. Make sure you&#8217;ve spelt the process name correctly.</p>
<p>Ok, as with many previous things this is XP only. The call number would need to be changed for other OS&#8217;s or SP&#8217;s. Look <a href="http://www.metasploit.com/users/opcode/syscalls.html">here </a>for different call numbers.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/somebastardstolemyname.wordpress.com/44/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/somebastardstolemyname.wordpress.com/44/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/somebastardstolemyname.wordpress.com/44/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/somebastardstolemyname.wordpress.com/44/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/somebastardstolemyname.wordpress.com/44/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/somebastardstolemyname.wordpress.com/44/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/somebastardstolemyname.wordpress.com/44/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/somebastardstolemyname.wordpress.com/44/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/somebastardstolemyname.wordpress.com/44/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/somebastardstolemyname.wordpress.com/44/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/somebastardstolemyname.wordpress.com/44/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/somebastardstolemyname.wordpress.com/44/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/somebastardstolemyname.wordpress.com/44/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/somebastardstolemyname.wordpress.com/44/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=somebastardstolemyname.wordpress.com&amp;blog=849487&amp;post=44&amp;subd=somebastardstolemyname&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://somebastardstolemyname.wordpress.com/2008/10/04/c-ntopenprocess-hook/feed/</wfw:commentRss>
		<slash:comments>18</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">The_Undead</media:title>
		</media:content>

		<media:content url="http://img211.imageshack.us/img211/5259/ntopenprocesshook.jpg" medium="image" />
	</item>
		<item>
		<title>[Unfinished - C++]DirectX 2D Tile Engine</title>
		<link>http://somebastardstolemyname.wordpress.com/2008/08/31/unfinished-cdirectx-2d-tile-engine/</link>
		<comments>http://somebastardstolemyname.wordpress.com/2008/08/31/unfinished-cdirectx-2d-tile-engine/#comments</comments>
		<pubDate>Sun, 31 Aug 2008 21:39:06 +0000</pubDate>
		<dc:creator>Rhys M.</dc:creator>
				<category><![CDATA[Programming]]></category>

		<guid isPermaLink="false">http://somebastardstolemyname.wordpress.com/?p=36</guid>
		<description><![CDATA[So I decided to give DirectX a shot and try and create a Tile Engine (wikipedia link for those who dont know..) Without much reading or forethought I went ahead and started coding. Not really happy with the results, has a quite a few things which I would do different. A pixel based camera rather [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=somebastardstolemyname.wordpress.com&amp;blog=849487&amp;post=36&amp;subd=somebastardstolemyname&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>So I decided to give DirectX a shot and try and create a Tile Engine <a title="wikipedia" href="http://en.wikipedia.org/wiki/Tile_engine" target="_blank">(wikipedia link for those who dont know..) </a></p>
<p>Without much reading or forethought I went ahead and started coding. Not really happy with the results, has a quite a few things which I would do different. A pixel based camera rather than a tile based one, so I&#8217;m posting this here and leaving it as is. I&#8217;ll salvage bits from this code and recode it and see what I come up with.</p>
<p>Anyway, heres a picture of it:</p>
<p><img class="alignnone" src="http://img179.imageshack.us/img179/4504/tileenginewt5.jpg" alt="" width="412" height="412" /></p>
<p>The values in the map file are stored in little endian format, and the structure of the map file explained <a href="http://img174.imageshack.us/img174/8914/tileenginemapmn1.jpg" target="_blank">here in picture format.</a></p>
<p><a href="http://theundead.atspace.com/Blog/dxTileEngine.cpp" target="_blank">Source Code (.cpp)</a><br />
<a href="http://theundead.atspace.com/Blog/dxclass.h" target="_blank">Source Code (.h)</a><br />
<a title="TILE1" href="http://img297.imageshack.us/img297/9537/tile1gn6.png" target="_blank">PNG #1</a><br />
<a title="TILE2" href="http://img98.imageshack.us/img98/9751/tile2jl0.png" target="_blank">PNG #2</a></p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/somebastardstolemyname.wordpress.com/36/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/somebastardstolemyname.wordpress.com/36/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/somebastardstolemyname.wordpress.com/36/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/somebastardstolemyname.wordpress.com/36/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/somebastardstolemyname.wordpress.com/36/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/somebastardstolemyname.wordpress.com/36/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/somebastardstolemyname.wordpress.com/36/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/somebastardstolemyname.wordpress.com/36/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/somebastardstolemyname.wordpress.com/36/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/somebastardstolemyname.wordpress.com/36/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/somebastardstolemyname.wordpress.com/36/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/somebastardstolemyname.wordpress.com/36/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/somebastardstolemyname.wordpress.com/36/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/somebastardstolemyname.wordpress.com/36/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/somebastardstolemyname.wordpress.com/36/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/somebastardstolemyname.wordpress.com/36/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=somebastardstolemyname.wordpress.com&amp;blog=849487&amp;post=36&amp;subd=somebastardstolemyname&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://somebastardstolemyname.wordpress.com/2008/08/31/unfinished-cdirectx-2d-tile-engine/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">The_Undead</media:title>
		</media:content>

		<media:content url="http://img179.imageshack.us/img179/4504/tileenginewt5.jpg" medium="image" />
	</item>
		<item>
		<title>[C++] WINSOCK send hook.</title>
		<link>http://somebastardstolemyname.wordpress.com/2008/07/27/c-send-hook/</link>
		<comments>http://somebastardstolemyname.wordpress.com/2008/07/27/c-send-hook/#comments</comments>
		<pubDate>Sun, 27 Jul 2008 22:25:32 +0000</pubDate>
		<dc:creator>Rhys M.</dc:creator>
				<category><![CDATA[Programming]]></category>

		<guid isPermaLink="false">http://somebastardstolemyname.wordpress.com/?p=32</guid>
		<description><![CDATA[I see a few people looking for information on winsock and WINAPI hooks in general. Well, heres an easily modifiable inline hook. It works quite simply by replacing the 5 byte preamble at the start of the target function (NOTE: in pre win-xp sp2 systems this will be 3 bytes, and not five, so that [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=somebastardstolemyname.wordpress.com&amp;blog=849487&amp;post=32&amp;subd=somebastardstolemyname&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I see a few people looking for information on winsock and WINAPI hooks in general.<br />
Well, heres an easily modifiable inline hook.<br />
It works quite simply by replacing the 5 byte preamble at the start of the target function <em>(NOTE: in pre win-xp sp2 systems this will be 3 bytes, and not five, so that would need to be changed)</em> with a jump to our function, doing whatever we need to do then jump back to the original code.  However, because we&#8217;re replacing that preamble, for things to work we have to add those commands in our hook function.</p>
<div class="wp-caption alignnone" style="width: 382px"><img title="WIN32 send hook" src="http://img122.imageshack.us/img122/1691/winapihookdiagrampm3.jpg" alt="Hook diagram" width="372" height="283" /><p class="wp-caption-text">Hook diagram</p></div>
<p><a href="http://theundead.atspace.com/Blog/Cplusplusssendhook.txt" target="_blank">C/C++ &#8211; Source Code</a></p>
<p><a title="send" href="http://msdn.microsoft.com/en-us/library/ms740149(VS.85).aspx" target="_blank">MSDN &#8211; send</a></p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/somebastardstolemyname.wordpress.com/32/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/somebastardstolemyname.wordpress.com/32/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/somebastardstolemyname.wordpress.com/32/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/somebastardstolemyname.wordpress.com/32/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/somebastardstolemyname.wordpress.com/32/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/somebastardstolemyname.wordpress.com/32/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/somebastardstolemyname.wordpress.com/32/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/somebastardstolemyname.wordpress.com/32/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/somebastardstolemyname.wordpress.com/32/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/somebastardstolemyname.wordpress.com/32/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/somebastardstolemyname.wordpress.com/32/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/somebastardstolemyname.wordpress.com/32/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/somebastardstolemyname.wordpress.com/32/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/somebastardstolemyname.wordpress.com/32/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/somebastardstolemyname.wordpress.com/32/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/somebastardstolemyname.wordpress.com/32/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=somebastardstolemyname.wordpress.com&amp;blog=849487&amp;post=32&amp;subd=somebastardstolemyname&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://somebastardstolemyname.wordpress.com/2008/07/27/c-send-hook/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">The_Undead</media:title>
		</media:content>

		<media:content url="http://img122.imageshack.us/img122/1691/winapihookdiagrampm3.jpg" medium="image">
			<media:title type="html">WIN32 send hook</media:title>
		</media:content>
	</item>
		<item>
		<title>New Content</title>
		<link>http://somebastardstolemyname.wordpress.com/2008/05/28/new-content/</link>
		<comments>http://somebastardstolemyname.wordpress.com/2008/05/28/new-content/#comments</comments>
		<pubDate>Wed, 28 May 2008 14:41:29 +0000</pubDate>
		<dc:creator>Rhys M.</dc:creator>
				<category><![CDATA[Random Crap]]></category>

		<guid isPermaLink="false">http://somebastardstolemyname.wordpress.com/?p=27</guid>
		<description><![CDATA[So its been just over five months since my last post, which is pretty pathetic but I&#8217;m at a sheer loss of idea&#8217;s for content. If you wanna see something specific, write a comment with your thoughts and requests and I&#8217;ll see what I can do.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=somebastardstolemyname.wordpress.com&amp;blog=849487&amp;post=27&amp;subd=somebastardstolemyname&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>So its been just over five months since my last post, which is pretty pathetic but I&#8217;m at a sheer loss of idea&#8217;s for content.</p>
<p>If you wanna see something specific, write a comment with your thoughts and requests and I&#8217;ll see what I can do.</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/somebastardstolemyname.wordpress.com/27/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/somebastardstolemyname.wordpress.com/27/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/somebastardstolemyname.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/somebastardstolemyname.wordpress.com/27/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/somebastardstolemyname.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/somebastardstolemyname.wordpress.com/27/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/somebastardstolemyname.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/somebastardstolemyname.wordpress.com/27/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/somebastardstolemyname.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/somebastardstolemyname.wordpress.com/27/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/somebastardstolemyname.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/somebastardstolemyname.wordpress.com/27/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/somebastardstolemyname.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/somebastardstolemyname.wordpress.com/27/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/somebastardstolemyname.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/somebastardstolemyname.wordpress.com/27/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=somebastardstolemyname.wordpress.com&amp;blog=849487&amp;post=27&amp;subd=somebastardstolemyname&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://somebastardstolemyname.wordpress.com/2008/05/28/new-content/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">The_Undead</media:title>
		</media:content>
	</item>
		<item>
		<title>Rootkit Detector v2</title>
		<link>http://somebastardstolemyname.wordpress.com/2007/12/25/rootkit-detector-v2/</link>
		<comments>http://somebastardstolemyname.wordpress.com/2007/12/25/rootkit-detector-v2/#comments</comments>
		<pubDate>Tue, 25 Dec 2007 00:27:26 +0000</pubDate>
		<dc:creator>Rhys M.</dc:creator>
				<category><![CDATA[Programming]]></category>

		<guid isPermaLink="false">http://somebastardstolemyname.wordpress.com/2007/12/25/rootkit-detector-v2/</guid>
		<description><![CDATA[I recently decided to rework a piece of code I wrote earlier this year, and decided to expand upon it. My intent is to eventually have something resembling a fully fledged rootkit-detector, but I think thats still a while off. I did however add a few new functions to my previous version: amongst them the [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=somebastardstolemyname.wordpress.com&amp;blog=849487&amp;post=26&amp;subd=somebastardstolemyname&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I recently decided to rework a piece of code I wrote earlier this year, and decided to expand upon it.</p>
<p>My intent is to eventually have something resembling a fully fledged rootkit-detector, but I think thats still a while off. I did however add a few new functions to my previous version: amongst them the ability to detect both detour hooks and ssdt-table pointer hooks, that and the ability to detect hidden processes &#8211; the latter being something I still need to do a bit of work on, but I&#8217;ll include that in my next version.</p>
<p>I also had some fun and reworked the GUI and came up with a cool way of doing so. I thought it came out looking pretty stylish (as you can see in the screenshot below <img src='http://s2.wp.com/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' /> ).</p>
<p><img class="alignnone" title="Rootkit Detector V2" src="http://img508.imageshack.us/img508/7776/screenshotrootkitdethm5.jpg" alt="" width="500" height="241" /></p>
<p>You can download it here:<br />
<a title="Rootkit Detector Download" href="http://www.box.net/shared/oxspm67swg" target="_blank">EXE Download (.zip)</a><br />
Some screenshots:<br />
<a title="Rootkit Detector in action" href="http://i19.photobucket.com/albums/b171/somebastardstolemyname/rootkitdetectorv21.jpg" target="_blank">In action&#8230;</a><br />
<a title="Rootkit Detector gui" href="http://i19.photobucket.com/albums/b171/somebastardstolemyname/rootkitdetectorv2p2.jpg" target="_blank">The reworked GUI again</a></p>
<p><em><a href="http://somebastardstolemyname.wordpress.com/2007/10/16/ssdt-hookrootkit-detector/" target="_blank">And the original programs post</a></em></p>
<p><em>Note: wont work on pre XP-sp2 systems. Nor do I think it will work on Vista.<br />
</em></p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/somebastardstolemyname.wordpress.com/26/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/somebastardstolemyname.wordpress.com/26/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/somebastardstolemyname.wordpress.com/26/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/somebastardstolemyname.wordpress.com/26/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/somebastardstolemyname.wordpress.com/26/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/somebastardstolemyname.wordpress.com/26/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/somebastardstolemyname.wordpress.com/26/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/somebastardstolemyname.wordpress.com/26/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/somebastardstolemyname.wordpress.com/26/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/somebastardstolemyname.wordpress.com/26/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/somebastardstolemyname.wordpress.com/26/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/somebastardstolemyname.wordpress.com/26/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/somebastardstolemyname.wordpress.com/26/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/somebastardstolemyname.wordpress.com/26/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/somebastardstolemyname.wordpress.com/26/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/somebastardstolemyname.wordpress.com/26/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=somebastardstolemyname.wordpress.com&amp;blog=849487&amp;post=26&amp;subd=somebastardstolemyname&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://somebastardstolemyname.wordpress.com/2007/12/25/rootkit-detector-v2/feed/</wfw:commentRss>
		<slash:comments>16</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">The_Undead</media:title>
		</media:content>

		<media:content url="http://img508.imageshack.us/img508/7776/screenshotrootkitdethm5.jpg" medium="image">
			<media:title type="html">Rootkit Detector V2</media:title>
		</media:content>
	</item>
	</channel>
</rss>
