<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>msunified.net &#187; Windows Live Messenger</title>
	<atom:link href="http://msunified.net/tag/windows-live-messenger/feed/" rel="self" type="application/rss+xml" />
	<link>http://msunified.net</link>
	<description>Technical blog about Exchange and OCS by Ståle Hansen</description>
	<lastBuildDate>Mon, 09 Aug 2010 20:09:26 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='msunified.net' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://0.gravatar.com/blavatar/87139ddc4ba9c9960cf07f9364dfc9f4?s=96&#038;d=http://s2.wp.com/i/buttonw-com.png</url>
		<title>msunified.net &#187; Windows Live Messenger</title>
		<link>http://msunified.net</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://msunified.net/osd.xml" title="msunified.net" />
	<atom:link rel='hub' href='http://msunified.net/?pushpress=hub'/>
		<item>
		<title>New trojan on MSN March 2010</title>
		<link>http://msunified.net/2010/03/18/new-trojan-on-msn-march-2010/</link>
		<comments>http://msunified.net/2010/03/18/new-trojan-on-msn-march-2010/#comments</comments>
		<pubDate>Wed, 17 Mar 2010 23:03:31 +0000</pubDate>
		<dc:creator>Ståle Hansen</dc:creator>
				<category><![CDATA[UCC]]></category>
		<category><![CDATA[MSN]]></category>
		<category><![CDATA[OCS 2007 R2]]></category>
		<category><![CDATA[Telenor TSOC]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[Windows Live Messenger]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://msunified.net/?p=1293</guid>
		<description><![CDATA[March first 2010 Telenor TSOC discovered that a new worm was on the loose on Windows Live Messenger. This time it is in your native language and therefor the probability of users actually clicking on the link is much greater. The worm sends a link from one of your contacts in MSN and if you click it a trojan will [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=msunified.net&amp;blog=7420011&amp;post=1293&amp;subd=stalehansen&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><div class="tweetmeme-button" id="tweetmeme-button-post-1293" style='float: right; margin-left: 10px; margin-bottom: 5px; padding: 4px 0 2px 4px; background: #fff;'>
<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fmsunified.net%2F2010%2F03%2F18%2Fnew-trojan-on-msn-march-2010%2Ftweetmeme_alias%3Dhttp%3A%2F%2Fwp.me%2Fpv8hB-kR%26tweetmeme_source%3D%E2%80%9Dstalehansen%E2%80%9D"><img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fmsunified.net%2F2010%2F03%2F18%2Fnew-trojan-on-msn-march-2010%2F" height="61" width="51" /></a>
</div>  <a href="http://stalehansen.files.wordpress.com/2010/03/620x350_msn_trojaner_tcm48-74327.jpg"><img class="alignleft size-thumbnail wp-image-1297" style="border:0;" title="MSN Trojan" src="http://stalehansen.files.wordpress.com/2010/03/620x350_msn_trojaner_tcm48-74327.jpg?w=108&#038;h=60" alt="" width="108" height="60" /></a>March first 2010 <a href="http://telenorsoc.blogspot.com/" target="_blank">Telenor TSOC </a>discovered that a new worm was on the loose on Windows Live Messenger. This time it is in your native language and therefor the probability of users actually clicking on the link is much greater. The worm sends a link from one of your contacts in MSN and if you click it a trojan will be downloaded to your PC and install itself. This is a huge risk for businesses that allow users to use Windows Live Messenger in their company network. If one PC get compromised in the internal network the possibility for it infecting other PC&#8217;s is even greater. This is one of the main reasons to implement OCS 2007 R2 as the only business solution for chat. Some arguments are:</p>
<ul>
<li>Encrypted internal chat solution</li>
<li>All traffic stay inside you organization</li>
<li>Can federate and chat with other organizations in a secure manner</li>
<li>Can add global rules for blocking links, file transfers and unpatched clients</li>
<li>Can add MSN contacts and be sure that messages with links is blocked server-side</li>
</ul>
<p>In addition to secure chat OCS gives the businesses the ability to implement Unified Communications and is therefore way more than just a chat client.</p>
<h3>About this trojan</h3>
<p>First you get a message from one of you contacts saying, <strong>seen this?? :D</strong>  and it links to hxxp://www.facebook-c.com/image.php?Photo023girl.JPG. The trojan adapts to the language on the computer and will display the text in you native language. In norwegian it will be<strong> se på dette bildet :D</strong> with the link following. The link points to a site at Yahoo and so the links was live for a day or two. It still was a huge security risk. The trojan is written in Visual Basic and executes a C++ program. It installed itself as c:\windows\winmbu.exe and granted itself access through the local firewall. The program gave the owner of the trojan access to</p>
<ul>
<li>Communication with C&amp;C over the IRC protocol</li>
<li>Sending of messages over MSN and Yahoo messenger</li>
<li>Download and run files on the infected computer</li>
</ul>
<p>At release date only 13 of 41 antivirus products detected this file. So even with an updated antivirus on the local computer 69% of the antivirus solutions would not have detected it.</p>
<p>Link to official article in norwegian: <a href="http://telenorsoc.blogspot.com/2010/03/trojaner-spres-via-msn-messenger.html">http://telenorsoc.blogspot.com/2010/03/trojaner-spres-via-msn-messenger.html</a><br />
Link to the antivirus protection overview: <a href="http://www.virustotal.com/analisis/89c677bc0044864d80244aee8201661e79f431f33c3b164aa778f363fe1cf9da-1267474859">http://www.virustotal.com/analisis/89c677bc0044864d80244aee8201661e79f431f33c3b164aa778f363fe1cf9da-1267474859</a></p>
<br />Filed under: <a href='http://msunified.net/category/ucc/'>UCC</a> Tagged: <a href='http://msunified.net/tag/msn/'>MSN</a>, <a href='http://msunified.net/tag/ocs-2007-r2/'>OCS 2007 R2</a>, <a href='http://msunified.net/tag/telenor-tsoc/'>Telenor TSOC</a>, <a href='http://msunified.net/tag/trojan/'>trojan</a>, <a href='http://msunified.net/tag/windows-live-messenger/'>Windows Live Messenger</a>, <a href='http://msunified.net/tag/worm/'>worm</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/stalehansen.wordpress.com/1293/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/stalehansen.wordpress.com/1293/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/stalehansen.wordpress.com/1293/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/stalehansen.wordpress.com/1293/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/stalehansen.wordpress.com/1293/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/stalehansen.wordpress.com/1293/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/stalehansen.wordpress.com/1293/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/stalehansen.wordpress.com/1293/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/stalehansen.wordpress.com/1293/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/stalehansen.wordpress.com/1293/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/stalehansen.wordpress.com/1293/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/stalehansen.wordpress.com/1293/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/stalehansen.wordpress.com/1293/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/stalehansen.wordpress.com/1293/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=msunified.net&amp;blog=7420011&amp;post=1293&amp;subd=stalehansen&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://msunified.net/2010/03/18/new-trojan-on-msn-march-2010/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6afc0203b3f13256107aceceb663b891?s=96&#38;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif&#38;r=G" medium="image">
			<media:title type="html">Ståle Hansen</media:title>
		</media:content>

		<media:content url="http://stalehansen.files.wordpress.com/2010/03/620x350_msn_trojaner_tcm48-74327.jpg?w=150" medium="image">
			<media:title type="html">MSN Trojan</media:title>
		</media:content>
	</item>
		<item>
		<title>How Windows Live Messenger works</title>
		<link>http://msunified.net/2009/06/20/how-windows-live-messenger-works/</link>
		<comments>http://msunified.net/2009/06/20/how-windows-live-messenger-works/#comments</comments>
		<pubDate>Sat, 20 Jun 2009 10:56:02 +0000</pubDate>
		<dc:creator>Ståle Hansen</dc:creator>
				<category><![CDATA[OCS 2007]]></category>
		<category><![CDATA[Windows Live Messenger]]></category>

		<guid isPermaLink="false">http://msunified.net/?p=457</guid>
		<description><![CDATA[Any Post starting with this disclaimer means that this post was not written by me however I liked it and added to my blog. I will also include the link to the original or similar post to provide credit to the original author Read the entire post here: http://www.milkaddict.com/?p=21 How does Windows Live Messenger works? [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=msunified.net&amp;blog=7420011&amp;post=457&amp;subd=stalehansen&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Any Post starting with this disclaimer means that this post was not written by me however I liked it and added to my blog. I will also include the link to the original or similar post to provide credit to the original author</p>
<p>Read the entire post here: <a href="http://www.milkaddict.com/?p=21" target="_blank">http://www.milkaddict.com/?p=21</a></p>
<p>How does Windows Live Messenger works? there are millions of users typing messages everyday but maybe few of them ever asked themselves how the messenger really works! so here I wrote a little post about it. Windows Live Messenger it’s an hybrid Client-Server / Peer-to-Peer application. It basically started as a client-server application. Let’s say that the client A wants to contact the client B. The client A logs in a CS (Connection Server) through a persistent TCP connection (eventually using proxy,gateway..). Behind the CS there are the PS (Presence Server). Each person get always the same particular PS, which is where your personal status message, description of your user photo and similar things are stored.</p>
<p style="text-align:center;"><img class="size-full wp-image-496 aligncenter" style="border:#000000 0;" title="Msn1" src="http://stalehansen.files.wordpress.com/2009/06/msn1.png?w=450&#038;h=326" alt="Msn1" width="450" height="326" /></p>
<p>Another element of the architecture is the Address Book. The client A gets directly from the Address Book his list of contacts. Then the client A tells to his CS who his friends are, the CS subscribes to his friend’s PS to get the presence information that are sent up through the client server connection. If the client A change his status to OffLine for example, the change goes up to the CS of A, then to the PS of A, then down to the CS of B through the subscription and then down to the client B.</p>
<p><strong>CHAT</strong></p>
<p>If the client A wants to chat, tells to his CS that wants to contact somebody, and the CS tells A to contact a Mixer, which sends IM traffic to a destination, for example to B (passing through the CS of B). Then A and B and talk back and forth through the Mixer.</p>
<p style="text-align:center;"><img class="size-full wp-image-497 aligncenter" style="border:#000000 0;" title="Msn2" src="http://stalehansen.files.wordpress.com/2009/06/msn2.png?w=450&#038;h=302" alt="Msn2" width="450" height="302" /></p>
<p>You can watch also an original video where some of the developers and visionaries behind Windows Live Messenger explain how it works. <a href="http://channel9.msdn.com/posts/Charles/Windows-Live-Messenger-What-How-Why/" target="_blank">http://channel9.msdn.com/posts/Charles/Windows-Live-Messenger-What-How-Why/</a></p>
<br />Posted in OCS 2007 Tagged: Windows Live Messenger <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/stalehansen.wordpress.com/457/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/stalehansen.wordpress.com/457/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/stalehansen.wordpress.com/457/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/stalehansen.wordpress.com/457/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/stalehansen.wordpress.com/457/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/stalehansen.wordpress.com/457/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/stalehansen.wordpress.com/457/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/stalehansen.wordpress.com/457/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/stalehansen.wordpress.com/457/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/stalehansen.wordpress.com/457/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/stalehansen.wordpress.com/457/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/stalehansen.wordpress.com/457/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/stalehansen.wordpress.com/457/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/stalehansen.wordpress.com/457/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=msunified.net&amp;blog=7420011&amp;post=457&amp;subd=stalehansen&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://msunified.net/2009/06/20/how-windows-live-messenger-works/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6afc0203b3f13256107aceceb663b891?s=96&#38;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif&#38;r=G" medium="image">
			<media:title type="html">Ståle Hansen</media:title>
		</media:content>

		<media:content url="http://stalehansen.files.wordpress.com/2009/06/msn1.png" medium="image">
			<media:title type="html">Msn1</media:title>
		</media:content>

		<media:content url="http://stalehansen.files.wordpress.com/2009/06/msn2.png" medium="image">
			<media:title type="html">Msn2</media:title>
		</media:content>
	</item>
	</channel>
</rss>