<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://honeynet.org" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
 <title>Sysenter Chapter</title>
 <link>http://honeynet.org/chapters/sysenter</link>
 <description>Sysenter Chapter</description>
 <language>en</language>
<item>
 <title>Sysenter Chapter Status Report 2012</title>
 <link>http://honeynet.org/node/967</link>
 <description>&lt;p&gt;&lt;strong&gt;ORGANIZATION&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The Sysenter Chapter was founded in August 2010 and currently consists of the following people:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;em&gt;Angelo Dell&#039;Aera&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;&lt;em&gt;Charlie Hurel&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;&lt;em&gt;Gianluca Guida&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;&lt;em&gt;Guido Landi&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;&lt;em&gt;Patrik Lantz&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;&lt;em&gt;Pietro Delsante&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;&lt;em&gt;Roberto Tanara&lt;/em&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The Chapter members are interested in research projects covering the following topics:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Automated botnet tracking&lt;/li&gt;
&lt;li&gt;Low-interaction client honeypots&lt;/li&gt;
&lt;div class=&quot;og_rss_groups&quot;&gt;&lt;ul class=&quot;links&quot;&gt;&lt;li  class=&quot;first last og_links&quot;&gt;&lt;a href=&quot;/chapters/sysenter&quot; class=&quot;og_links&quot;&gt;Sysenter Chapter&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;&lt;p&gt;&lt;a href=&quot;http://honeynet.org/node/967&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <group domain="http://honeynet.org/chapters/sysenter" xmlns="http://drupal.org/project/og">Sysenter Chapter</group>
 <pubDate>Tue, 30 Oct 2012 10:06:08 -0500</pubDate>
 <dc:creator>angelo.dellaera</dc:creator>
 <guid isPermaLink="false">967 at http://honeynet.org</guid>
</item>
<item>
 <title>Sysenter Chapter - Status Report 2011</title>
 <link>http://honeynet.org/node/685</link>
 <description>&lt;p&gt;&lt;strong&gt;ORGANIZATION&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The Sysenter Chapter was founded in August 2010 and currently consists of the following people:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;em&gt;Angelo Dell&#039;Aera&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;&lt;em&gt;Guido Landi&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;&lt;em&gt;Patrik Lantz&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;&lt;em&gt;Roberto Tanara&lt;/em&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The Chapter members are interested in research projects covering the following topics:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Automated botnet tracking&lt;/li&gt;
&lt;li&gt;Low-interaction client honeypots&lt;/li&gt;
&lt;li&gt;Automated malware collection and analysis systems&lt;/li&gt;
&lt;li&gt;Distributed honeynet deployment, operation and data analysis&lt;/li&gt;
&lt;div class=&quot;og_rss_groups&quot;&gt;&lt;ul class=&quot;links&quot;&gt;&lt;li  class=&quot;first last og_links&quot;&gt;&lt;a href=&quot;/chapters/sysenter&quot; class=&quot;og_links&quot;&gt;Sysenter Chapter&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;&lt;p&gt;&lt;a href=&quot;http://honeynet.org/node/685&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <group domain="http://honeynet.org/chapters/sysenter" xmlns="http://drupal.org/project/og">Sysenter Chapter</group>
 <pubDate>Fri, 10 Jun 2011 08:52:27 -0500</pubDate>
 <dc:creator>angelo.dellaera</dc:creator>
 <guid isPermaLink="false">685 at http://honeynet.org</guid>
</item>
<item>
 <title>Murofet, Zeus++ or just Zeus 2.1?</title>
 <link>http://honeynet.org/node/579</link>
 <description>&lt;p&gt;The first one writing about this new threat was &lt;a href=&quot;http://www.prevx.com/blog/159/WinMurofetor-just-ZeuS.html&quot; target=&quot;_blank&quot;&gt;Marco Giuliani&lt;/a&gt;. So, Murofet or Zeus++? &lt;/p&gt;
&lt;p&gt;Taking a look at a couple of samples we were able to identify:&lt;br /&gt;
- Same API hooks&lt;br /&gt;
- Same encryption routine for configuration file (RC4)&lt;br /&gt;
- Pretty much the same configuration file format&lt;/p&gt;
&lt;div class=&quot;og_rss_groups&quot;&gt;&lt;ul class=&quot;links&quot;&gt;&lt;li  class=&quot;first last og_links&quot;&gt;&lt;a href=&quot;/chapters/sysenter&quot; class=&quot;og_links&quot;&gt;Sysenter Chapter&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;&lt;p&gt;&lt;a href=&quot;http://honeynet.org/node/579&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <group domain="http://honeynet.org/chapters/sysenter" xmlns="http://drupal.org/project/og">Sysenter Chapter</group>
 <category domain="http://honeynet.org/taxonomy/term/152">murofet</category>
 <category domain="http://honeynet.org/taxonomy/term/151">zeus</category>
 <pubDate>Fri, 15 Oct 2010 06:09:44 -0500</pubDate>
 <dc:creator>guido.landi</dc:creator>
 <guid isPermaLink="false">579 at http://honeynet.org</guid>
</item>
<item>
 <title>Trojan Carberp</title>
 <link>http://honeynet.org/node/578</link>
 <description>&lt;p&gt;I&#039;m interested in infostealers and specifically in banking-trojans so I didn&#039;t want to miss &lt;a href=&quot;http://www.trustdefender.com/blog/2010/10/06/carberp-%E2%80%93-a-new-trojan-in-the-making/&quot;&gt;this one&lt;/a&gt;. Samples of Carberp are floating around at least since last spring but in late September we saw such numbers increasing.&lt;/p&gt;
&lt;p&gt;Taking a look at how Carberp hooks API it looks like yet another Zeus &quot;clone&quot;. What I found interesting is how it hooks system calls. This is how a normal syscall looks like&lt;/p&gt;
&lt;div class=&quot;geshifilter&quot;&gt;
&lt;div class=&quot;text geshifilter-text&quot; style=&quot;font-family:monospace;&quot;&gt;MOV EAX,0xce &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; // ZwResumeThread syscall id&lt;/div&gt;
&lt;/div&gt;
&lt;div class=&quot;og_rss_groups&quot;&gt;&lt;ul class=&quot;links&quot;&gt;&lt;li  class=&quot;first last og_links&quot;&gt;&lt;a href=&quot;/chapters/sysenter&quot; class=&quot;og_links&quot;&gt;Sysenter Chapter&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;&lt;p&gt;&lt;a href=&quot;http://honeynet.org/node/578&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <group domain="http://honeynet.org/chapters/sysenter" xmlns="http://drupal.org/project/og">Sysenter Chapter</group>
 <category domain="http://honeynet.org/taxonomy/term/150">carberp</category>
 <category domain="http://honeynet.org/taxonomy/term/149">trojan</category>
 <category domain="http://honeynet.org/taxonomy/term/151">zeus</category>
 <pubDate>Mon, 11 Oct 2010 07:16:11 -0500</pubDate>
 <dc:creator>guido.landi</dc:creator>
 <guid isPermaLink="false">578 at http://honeynet.org</guid>
</item>
<item>
 <title>Is that PDF so scary?</title>
 <link>http://honeynet.org/node/576</link>
 <description>&lt;p&gt;- &quot;it bypasses DEP and ASLR using impressive tricks and unusual methods&quot; - &lt;a href=&quot;http://www.vupen.com/blog/&quot;&gt;Vupen&lt;/a&gt;&lt;/p&gt;
&lt;p&gt; - &quot;it uses a previously unpublished technique to bypass ASLR&quot; - &lt;a href=&quot;http://blog.metasploit.com/2010/09/return-of-unpublished-adobe.html&quot;&gt;Metasploit Blog&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;- &quot;exploit uses the ROP technique to bypass the ASLR and DEP&quot; - &lt;a href=&quot;http://www.zdnet.com/blog/security/adobe-pdf-exploits-using-signed-certificates-bypasses-aslrdep/7303&quot;&gt;ZDnet/Kasperky&lt;/a&gt;&lt;/p&gt;
&lt;div class=&quot;og_rss_groups&quot;&gt;&lt;ul class=&quot;links&quot;&gt;&lt;li  class=&quot;first last og_links&quot;&gt;&lt;a href=&quot;/chapters/sysenter&quot; class=&quot;og_links&quot;&gt;Sysenter Chapter&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;&lt;p&gt;&lt;a href=&quot;http://honeynet.org/node/576&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <group domain="http://honeynet.org/chapters/sysenter" xmlns="http://drupal.org/project/og">Sysenter Chapter</group>
 <category domain="http://honeynet.org/taxonomy/term/146">ASLR</category>
 <category domain="http://honeynet.org/taxonomy/term/145">DEP</category>
 <category domain="http://honeynet.org/taxonomy/term/139">exploit</category>
 <category domain="http://honeynet.org/taxonomy/term/147">pdf</category>
 <category domain="http://honeynet.org/taxonomy/term/148">ROP</category>
 <pubDate>Fri, 10 Sep 2010 04:56:10 -0500</pubDate>
 <dc:creator>guido.landi</dc:creator>
 <guid isPermaLink="false">576 at http://honeynet.org</guid>
</item>
<item>
 <title>Export Address Table Filtering (EMET v2)</title>
 <link>http://honeynet.org/node/571</link>
 <description>&lt;p&gt;I&#039;ll tell you the truth: Export Address Table Filtering, the feature of the &lt;a href=&quot;http://blogs.technet.com/b/srd/archive/2010/07/28/announcing-the-upcoming-release-of-emet-v2.aspx&quot;&gt;upcoming release of EMET&lt;/a&gt;, &quot;designed to break nearly all shell code in use today&quot;, intrigued me a bit.&lt;/p&gt;
&lt;div class=&quot;og_rss_groups&quot;&gt;&lt;ul class=&quot;links&quot;&gt;&lt;li  class=&quot;first last og_links&quot;&gt;&lt;a href=&quot;/chapters/sysenter&quot; class=&quot;og_links&quot;&gt;Sysenter Chapter&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;&lt;p&gt;&lt;a href=&quot;http://honeynet.org/node/571&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <group domain="http://honeynet.org/chapters/sysenter" xmlns="http://drupal.org/project/og">Sysenter Chapter</group>
 <category domain="http://honeynet.org/taxonomy/term/144">EAT filtering</category>
 <category domain="http://honeynet.org/taxonomy/term/143">emet</category>
 <category domain="http://honeynet.org/taxonomy/term/19">shellcode</category>
 <pubDate>Tue, 31 Aug 2010 04:40:36 -0500</pubDate>
 <dc:creator>guido.landi</dc:creator>
 <guid isPermaLink="false">571 at http://honeynet.org</guid>
</item>
<item>
 <title>PHoneyC DOM Emulation – Browser Personality</title>
 <link>http://honeynet.org/node/570</link>
 <description>&lt;p&gt;A new improvement in PHoneyC DOM emulation code was committed in SVN &lt;a href=&quot;http://code.google.com/p/phoneyc/source/detail?r=1624&quot;&gt;r1624&lt;/a&gt;. The idea is to better emulate the DOM behaviour depending on the selected browser personality. Let&#039;s take a look at the code starting from the personalities definition in &lt;em&gt;config.py&lt;/em&gt;.&lt;/p&gt;
&lt;div class=&quot;geshifilter&quot;&gt;
&lt;div class=&quot;text geshifilter-text&quot; style=&quot;font-family:monospace;&quot;&gt;39 UserAgents = [&lt;br /&gt;
40 &amp;nbsp; &amp;nbsp; (1,&lt;br /&gt;
41 &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;quot;Internet Explorer 6.0 (Windows 2000)&amp;quot;,&lt;br /&gt;
42 &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;quot;Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727)&amp;quot;,&lt;br /&gt;
43 &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;quot;Mozilla&amp;quot;,&lt;br /&gt;
44 &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;quot;Microsoft Internet Explorer&amp;quot;,&lt;/div&gt;
&lt;/div&gt;
&lt;div class=&quot;og_rss_groups&quot;&gt;&lt;ul class=&quot;links&quot;&gt;&lt;li  class=&quot;first last og_links&quot;&gt;&lt;a href=&quot;/chapters/sysenter&quot; class=&quot;og_links&quot;&gt;Sysenter Chapter&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;&lt;p&gt;&lt;a href=&quot;http://honeynet.org/node/570&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <group domain="http://honeynet.org/chapters/sysenter" xmlns="http://drupal.org/project/og">Sysenter Chapter</group>
 <category domain="http://honeynet.org/taxonomy/term/57">phoneyc</category>
 <pubDate>Sun, 22 Aug 2010 10:03:29 -0500</pubDate>
 <dc:creator>angelo.dellaera</dc:creator>
 <guid isPermaLink="false">570 at http://honeynet.org</guid>
</item>
<item>
 <title>Another great step forward</title>
 <link>http://honeynet.org/node/567</link>
 <description>&lt;p&gt;&lt;em&gt;“Dionaea is meant to be a Nepenthes successor, embedding Python as scripting language, using libemu to detect shellcodes, supporting IPv6 and TLS”&lt;/em&gt; (taken from &lt;a href=&quot;http://dionaea.carnivore.it/&quot;&gt;Dionaea homepage&lt;/a&gt;). Besides being the most interesting project for trapping malware exploiting vulnerabilities, Dionaea supports a really cool feature which allows it to log to XMPP services as described &lt;a href=&quot;http://dionaea.carnivore.it/#logxmpp&quot;&gt;here&lt;/a&gt;. TIP now exploits this feature receiving and storing such logs (really thanks to Markus Koetter for his help and support).&lt;/p&gt;
&lt;div class=&quot;og_rss_groups&quot;&gt;&lt;ul class=&quot;links&quot;&gt;&lt;li  class=&quot;first last og_links&quot;&gt;&lt;a href=&quot;/chapters/sysenter&quot; class=&quot;og_links&quot;&gt;Sysenter Chapter&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;&lt;p&gt;&lt;a href=&quot;http://honeynet.org/node/567&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <group domain="http://honeynet.org/chapters/sysenter" xmlns="http://drupal.org/project/og">Sysenter Chapter</group>
 <pubDate>Wed, 11 Aug 2010 09:00:18 -0500</pubDate>
 <dc:creator>angelo.dellaera</dc:creator>
 <guid isPermaLink="false">567 at http://honeynet.org</guid>
</item>
<item>
 <title>PHoneyC DOM Emulation - Window</title>
 <link>http://honeynet.org/node/566</link>
 <description>&lt;p&gt;A few weeks ago I started reviewing the PHoneyC DOM emulation code and realized it was turning to be hard to maintain and debug due to a huge amount of undocumented (and sometimes awful) hacks. For this reason I decided it was time to patch (and sometimes rewrite from scratch) such code. These posts will describe how the new DOM emulation code will work. The patch is not available right now since I&#039;m testing the code but plans exists to commit it in the &lt;a href=&quot;http://code.google.com/p/phoneyc/&quot;&gt;PHoneyC SVN&lt;/a&gt; in the next days.&lt;/p&gt;
&lt;div class=&quot;og_rss_groups&quot;&gt;&lt;ul class=&quot;links&quot;&gt;&lt;li  class=&quot;first last og_links&quot;&gt;&lt;a href=&quot;/chapters/sysenter&quot; class=&quot;og_links&quot;&gt;Sysenter Chapter&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;&lt;p&gt;&lt;a href=&quot;http://honeynet.org/node/566&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <group domain="http://honeynet.org/chapters/sysenter" xmlns="http://drupal.org/project/og">Sysenter Chapter</group>
 <category domain="http://honeynet.org/taxonomy/term/57">phoneyc</category>
 <pubDate>Tue, 10 Aug 2010 08:14:10 -0500</pubDate>
 <dc:creator>angelo.dellaera</dc:creator>
 <guid isPermaLink="false">566 at http://honeynet.org</guid>
</item>
</channel>
</rss>
