 




<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>IT Trenches &#187; honeynet</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/it-trenches/tag/honeynet/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/it-trenches</link>
	<description></description>
	<lastBuildDate>Fri, 19 Nov 2010 14:37:59 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>Simple Conficker Scanner tool released &#8211; find the infected machines</title>
		<link>http://itknowledgeexchange.techtarget.com/it-trenches/simple-conficker-scanner-tool-released-find-the-infected-machines/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-trenches/simple-conficker-scanner-tool-released-find-the-infected-machines/#comments</comments>
		<pubDate>Tue, 31 Mar 2009 15:32:22 +0000</pubDate>
		<dc:creator>Troy Tate</dc:creator>
				<category><![CDATA[anti-virus]]></category>
		<category><![CDATA[antivirus]]></category>
		<category><![CDATA[Conficker]]></category>
		<category><![CDATA[detection]]></category>
		<category><![CDATA[diagnostic tools]]></category>
		<category><![CDATA[honeynet]]></category>
		<category><![CDATA[ms08-067]]></category>
		<category><![CDATA[patches]]></category>
		<category><![CDATA[scanning]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[vulnerability scanning]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-trenches/simple-conficker-scanner-tool-released-find-the-infected-machines/</guid>
		<description><![CDATA[A Simple Conficker Scanner (SCS) tool has been released by members of the Honeynet Project. This tool can be run under linux or Windows. It runs a specially crafted RPC query against a host or range of IP addresses. The tool will tell if systems are clean or potentially infected. I am running this tool [...]]]></description>
				<content:encoded><![CDATA[<p>A <a href="http://iv.cs.uni-bonn.de/wg/cs/applications/containing-conficker/" target="_blank">Simple Conficker Scanner (SCS)</a> tool has been released by members of the <a href="http://www.honeynet.org/" target="_blank">Honeynet Project</a>. This tool can be run under linux or Windows. It runs a specially crafted RPC query against a host or range of IP addresses. The tool will tell if systems are clean or potentially infected. I am running this tool against hosts on my network and I found a Windows 2000 server apparently infected by Conficker. I am in the process of clean-up on that host. It looks like a couple of things contributed to the infection on this computer:</p>
<p>1. Out of date anti-virus. The antivirus signatures had not been updated since January 2008.</p>
<p>2. Microsoft patches not applied.</p>
<p>Folks, the advice about maintaining up-to-date AV and applying patches is good advice. Heed the warnings and save yourself some troubles of clean-up. I will be having a discussion with my operations team about this situation and make it clear that we should have been prepared for this and this situation should not have arisen.</p>
<p>I am also following the advice from McAfee on <a href="http://download.nai.com/products/mcafee-avert/documents/combating_w32_conficker_worm.pdf" target="_blank">Combating the Conficker worm</a></p>
<p>For more details on how the Conficker worm actually works, follow the links in my blog</p>
<h2><a title="Permanent Link to The Conficker Analysis - are you ready for April 1?" rel="bookmark" href="../the-conficker-analysis-are-you-ready-for-april-1/">The Conficker Analysis &#8211; are you ready for April 1?</a></h2>
<p>Thanks for reading. Let&#8217;s continue to be good network citizens.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-trenches/simple-conficker-scanner-tool-released-find-the-infected-machines/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Browser warnings &#8211; Danger Will Robinson! &#8211; or did it just cry &#8220;Wolf!&#8221;?</title>
		<link>http://itknowledgeexchange.techtarget.com/it-trenches/browser-warnings-danger-will-robinson-or-did-it-just-cry-wolf/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-trenches/browser-warnings-danger-will-robinson-or-did-it-just-cry-wolf/#comments</comments>
		<pubDate>Tue, 08 Jul 2008 17:12:33 +0000</pubDate>
		<dc:creator>Troy Tate</dc:creator>
				<category><![CDATA[anti-virus]]></category>
		<category><![CDATA[antivirus]]></category>
		<category><![CDATA[awareness]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[Data security]]></category>
		<category><![CDATA[Development]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[forensics]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[honeynet]]></category>
		<category><![CDATA[honeypot]]></category>
		<category><![CDATA[IT education]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Metrics]]></category>
		<category><![CDATA[online identity]]></category>
		<category><![CDATA[Policy]]></category>
		<category><![CDATA[policy enforcement]]></category>
		<category><![CDATA[reporting]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[web]]></category>
		<category><![CDATA[website]]></category>
		<category><![CDATA[WWW]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-trenches/browser-warnings-danger-will-robinson-or-did-it-just-cry-wolf/</guid>
		<description><![CDATA[I sometimes browse the internet using Firefox. I say sometimes because Internet Explorer is the standard browser at my company and Firefox is not supported by IT. Well, since I work in IT, sometimes you have to test things on behalf of users and also to see how certain sites are different depending on the [...]]]></description>
				<content:encoded><![CDATA[<p>I sometimes browse the internet using Firefox. I say sometimes because Internet Explorer is the standard browser at my company and Firefox is not supported by IT. Well, since I work in IT, sometimes you have to test things on behalf of users and also to see how certain sites are different depending on the client browser.</p>
<p>Well, I recently upgraded Firefox to v3. It does seem much better than v2 although some of my useful addins are now broken (when will YSlow get fixed for v3?). One of the new features of Firefox v3 is the ability to report to the user if the visited website is a known potential malware site. This is a good feature! It provides the user with some useful information and education about the dangers on the internet. However, how accurate is this feature? What if you are visiting a trusted website that you frequently visit and now get this message?</p>
<p>For your information, this is the message that you will see when you attempt to visit a site deemed as risky.</p>
<p><strong>Reported Attack Site!</p>
<p>This web site at certification.xxxxxxx.org has been reported as an attack site and has been blocked based on your security preferences.</p>
<p>Attack sites try to install programs that steal private information, use your computer to attack others, or damage your system.</p>
<p>Some attack sites intentionally distribute harmful software, but many are compromised without the knowledge or permission of their owners.</strong></p>
<p>I blanked out the actual website address above. However, those of you with a bit of detective in you are likely going to figure it out.</p>
<p>What is interesting about this particular warning message is that it is referring to a website that has security as a guiding principle. When you see this message in Firefox, you have three options presented:</p>
<ul>
<li>Get me out of here!</li>
<li>Why was this site blocked?</li>
<li>Ignore this warning &#8211; in very tiny print at bottom of message.</li>
</ul>
<p>I was curious as to why this site would be considered as a danger. I clicked on the <em>Why was this site blocked?</em> option. The report I received was interesting and as I mentioned earlier, could this be an example of someone crying &#8220;Wolf!&#8221;?</p>
<p>The report was as follows:</p>
<p class="d"><strong>What is the current listing status for certification.xxxxxxx.org/?</strong></p>
<blockquote><p>Site is listed as suspicious &#8211; visiting this web site may harm your computer.</p>
<p>Part of this site was listed for suspicious activity 1 time(s) over the past 90 days.</p></blockquote>
<p class="d"><strong>What happened when Google visited this site?</strong></p>
<blockquote><p>Of the 6 pages we tested on the site over the past 90 days, 1 page(s) resulted in malicious software being downloaded and installed without user consent. The last time Google visited this site was on 07/06/2008, and the last time suspicious content was found on this site was on 07/06/2008.</p>
<p>Malicious software includes 1 scripting exploit(s). Successful infection resulted in an average of 3 new processes on the target machine.</p>
<p>Malicious software is hosted on 3 domain(s), including <a href="http://safebrowsing.clients.google.com/safebrowsing/diagnostic?client=Firefox&amp;hl=en-US&amp;site=lokriet.com">lokriet.com</a>, <a href="http://safebrowsing.clients.google.com/safebrowsing/diagnostic?client=Firefox&amp;hl=en-US&amp;site=clrbbd.com">clrbbd.com</a>, <a href="http://safebrowsing.clients.google.com/safebrowsing/diagnostic?client=Firefox&amp;hl=en-US&amp;site=catdbw.mobi">catdbw.mobi</a>.</p>
<p>1 domain(s) appear to be functioning as intermediaries for distributing malware to visitors of this site, including <a href="http://safebrowsing.clients.google.com/safebrowsing/diagnostic?client=Firefox&amp;hl=en-US&amp;site=catdbw.mobi">catdbw.mobi</a>.</p></blockquote>
<p class="d"><strong>Has this site acted as an intermediary resulting in further distribution of malware?</strong></p>
<blockquote><p>Over the past 90 days, certification.xxxxxxx.org/ did not appear to function as an intermediary for the infection of any sites.</p></blockquote>
<p class="d"><strong>Has this site hosted malware?</strong></p>
<blockquote><p>No, this site has not hosted malicious software over the past 90 days.</p></blockquote>
<p class="d"><strong>How did this happen?</strong></p>
<blockquote><p>In some cases, third parties can add malicious code to legitimate sites, which would cause us to show the warning message.</p></blockquote>
<p class="d"><strong>Next steps:</strong></p>
<ul>
<li><a href="http://safebrowsing.clients.google.com/safebrowsing/diagnostic?client=Firefox&amp;hl=en-US&amp;site=http://certification.comptia.org/#">Return to the previous page</a>.</li>
<li>If you are the owner of this web site, you can request a review of your site using Google <a href="http://www.google.com/webmasters/tools/">Webmaster Tools</a>. More information about the review process is available in Google&#8217;s <a href="http://www.google.com/support/webmasters/bin/answer.py?answer=45432">Webmaster Help Center</a>.</li>
</ul>
<p>This is great educational stuff, but did it really happen to this particular website? I don&#8217;t know, but apparently Google does. With the report of just one incident, does it make this site really worth the notification? How many incidents should it take before a site is considered malicious and who determines what malicious is?</p>
<p>Just something else to mull over in your copious time as you go perusing websites in Firefox.</p>
<p>Thanks for your time. Let’s be good network citizens together &amp; practice safe networking!</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-trenches/browser-warnings-danger-will-robinson-or-did-it-just-cry-wolf/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Did you see this? &#8211; Noticebored &#8211; Infosec Awareness Education</title>
		<link>http://itknowledgeexchange.techtarget.com/it-trenches/did-you-see-this-noticebored-infosec-awareness-education/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-trenches/did-you-see-this-noticebored-infosec-awareness-education/#comments</comments>
		<pubDate>Sat, 31 May 2008 02:28:22 +0000</pubDate>
		<dc:creator>Troy Tate</dc:creator>
				<category><![CDATA[anti-virus]]></category>
		<category><![CDATA[antivirus]]></category>
		<category><![CDATA[awareness]]></category>
		<category><![CDATA[blogging]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[Data security]]></category>
		<category><![CDATA[forensics]]></category>
		<category><![CDATA[honeynet]]></category>
		<category><![CDATA[honeypot]]></category>
		<category><![CDATA[humor]]></category>
		<category><![CDATA[IT education]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Metrics]]></category>
		<category><![CDATA[Monitoring]]></category>
		<category><![CDATA[online identity]]></category>
		<category><![CDATA[Policy]]></category>
		<category><![CDATA[policy enforcement]]></category>
		<category><![CDATA[research]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[wiki]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-trenches/did-you-see-this-noticebored-infosec-awareness-education/</guid>
		<description><![CDATA[Noticebored is a great resource for information security awareness. The blogs are timely and cover a great spectrum of topics with regards to this important topic. Thanks for your time. Let’s be good network citizens together &#38; practice safe networking!]]></description>
				<content:encoded><![CDATA[<p><a href="http://www.noticebored.com" target="_blank">Noticebored</a> is a great resource for information security awareness. The <a href="http://www.noticebored.com/blog/NBlog.html" target="_blank">blogs</a> are timely and cover a great spectrum of topics with regards to this important topic.</p>
<p>Thanks for your time. Let’s be good network citizens together &amp; practice safe networking!</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-trenches/did-you-see-this-noticebored-infosec-awareness-education/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Did you see this? &#8211; a live honeynet</title>
		<link>http://itknowledgeexchange.techtarget.com/it-trenches/did-you-see-this-a-live-honeynet/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-trenches/did-you-see-this-a-live-honeynet/#comments</comments>
		<pubDate>Fri, 09 May 2008 18:20:10 +0000</pubDate>
		<dc:creator>Troy Tate</dc:creator>
				<category><![CDATA[anti-virus]]></category>
		<category><![CDATA[antivirus]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[CIO]]></category>
		<category><![CDATA[Data security]]></category>
		<category><![CDATA[DataManagement]]></category>
		<category><![CDATA[forensics]]></category>
		<category><![CDATA[honeynet]]></category>
		<category><![CDATA[honeypot]]></category>
		<category><![CDATA[howto]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Monitoring]]></category>
		<category><![CDATA[research]]></category>
		<category><![CDATA[Sandbox]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[SQL Server]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-trenches/did-you-see-this-a-live-honeynet/</guid>
		<description><![CDATA[I just came across the Shadowserver Foundation. According to their mission: The Shadowserver Foundation is an all volunteer watchdog group of security professionals that gather, track, and report on malware, botnet activity, and electronic fraud. It is the mission of the Shadowserver Foundation to improve the security of the Internet by raising awareness of the [...]]]></description>
				<content:encoded><![CDATA[<p class="vspace">I just came across the <a href="http://www.shadowserver.org" target="_blank">Shadowserver Foundation</a>. According to their mission:</p>
<p class="vspace"><em>The Shadowserver Foundation is an all volunteer watchdog group  of security professionals that gather, track, and report on malware, botnet  activity, and electronic fraud. It is the mission of the Shadowserver Foundation  to improve the security of the Internet by raising awareness of the presence of  compromised servers, malicious attackers, and the spread of malware.</em></p>
<p class="vspace">This is a great resource to find out what&#8217;s happening &#8220;in the wild&#8221; and to help sell security protection to your organization. This is real stuff happening in the real world. For example, take a look at how detailed the <a href="http://www.shadowserver.org/wiki/pmwiki.php?n=Calendar.20080507">blog entry</a> is on the winzipices.cn SQL injection / malware attack. This gives you enough information to fight the threat and feel confident you understand it.  Well done to the Shadowserver Foundation!</p>
<p class="vspace">Thanks for your time. Let’s be good network citizens together &amp;<br />
practice safe networking!</p>
<p class="vspace">&nbsp;</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-trenches/did-you-see-this-a-live-honeynet/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
