<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The Italian Honey Project &#187; Media</title>
	<atom:link href="http://www.honeynet.it/category/media/feed" rel="self" type="application/rss+xml" />
	<link>http://www.honeynet.it</link>
	<description>The Italian chapter of the Honeynet Research Alliance</description>
	<lastBuildDate>Wed, 11 Jan 2012 11:44:56 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>First-ever Honeynet Project Public Conference–Paris 2011</title>
		<link>http://www.honeynet.it/media/first-ever-honeynet-project-public-conference%e2%80%93paris-2011</link>
		<comments>http://www.honeynet.it/media/first-ever-honeynet-project-public-conference%e2%80%93paris-2011#comments</comments>
		<pubDate>Mon, 21 Mar 2011 10:07:09 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Media]]></category>
		<category><![CDATA[Project News]]></category>
		<category><![CDATA[Conferences]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=406</guid>
		<description><![CDATA[
It is with great pleasure I announce the first-ever Honeynet Project Public Conference, held alongside with the traditional Honeynet Project Annual Workshop. The event will be held on March 21, 2011 in Paris. For those who just want to register now, go here. Date: 21 March 2011 (Monday) 8:30AM ~ 18:00PM (GMT+1) Location: ESIEA Paris, [...]
]]></description>
			<content:encoded><![CDATA[<blockquote><p>It is with great pleasure I announce the first-ever Honeynet Project Public Conference, held alongside with the traditional Honeynet Project Annual Workshop. The event will be held on March 21, 2011 in Paris. For those who just want to register now, go here.</p>
<p>Date:  21 March 2011 (Monday)</p>
<p>8:30AM ~ 18:00PM (GMT+1)</p>
<p>Location:</p>
<p>ESIEA Paris, 9 rue Vesale 75005 Paris</p>
<p>(Nearest subway station: Les Gobelins(line #7))</p>
<p>About the event:</p>
<p>The 2011 Project Honeynet Security Workshop brings together experts in the field of information security from around the world to share the latest advances and threats in information security research. Organized by the not-for-profit Honeynet Project and co-sponsored by the ESIEA Engineering School, this full day workshop creates opportunities for networking, collaboration and lessons-learned featuring a rare, outstanding line-up of international security professionals who will present on the latest research tools and findings in the field.</p>
<p>This year’s workshop will be held in Paris, France on 21 March 2011 and is the first time that the workshop has opened a day to the public. Starting at 9:00 GMT+1, the workshop program features a format that includes presentations in five sessions and two bonus hands-on activities. The bonus activities include a technically challenging capture-the-flag (CTF) session and a tough forensics challenge (FC) that will allow attendees to apply their expertise and compete for prizes. If you’re looking to attend a high quality and challenging security workshop, then we encourage you to take advantage of this rare opportunity.</p></blockquote>
<p>More info <a href="http://www.honeynet.org/node/602">here</a>.</p>
<p>Enjoy!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/media/first-ever-honeynet-project-public-conference%e2%80%93paris-2011/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The recent ZeuS and Koobface trends fluctuation</title>
		<link>http://www.honeynet.it/botnet/the-recent-zeus-and-koobface-trends-fluctation</link>
		<comments>http://www.honeynet.it/botnet/the-recent-zeus-and-koobface-trends-fluctation#comments</comments>
		<pubDate>Fri, 12 Mar 2010 09:45:04 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Media]]></category>
		<category><![CDATA[Financial Botnet]]></category>
		<category><![CDATA[koobface]]></category>
		<category><![CDATA[zeus]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=193</guid>
		<description><![CDATA[
Security experts are tracking a massive drop in the global number of control servers for various ZeuS botnets that are online, suggesting that a coordinated takedown effort may have been executed by law enforcement and/or volunteers from the security research community acting in tandem. [....] Update, 4:36 p.m. ET: Sadly, it appears that Troyak — [...]
]]></description>
			<content:encoded><![CDATA[<blockquote><p>Security experts are tracking a massive drop in the global number of control servers for various ZeuS botnets that are online, suggesting that a coordinated takedown effort may have been executed by law enforcement and/or volunteers from the security research community acting in tandem.</p>
<p>[....]</p>
<p><span style="text-decoration: underline;"><strong>Update, 4:36 p.m</strong>.</span> ET: Sadly, it appears that Troyak — the Internet provider that played host to all these ZeuS-infested networks that got knocked offline yesterday — has since found another upstream provider to once again connect it to the rest of the Internet.</p>
<p><strong><span style="text-decoration: underline;">Update, Mar. 11, 5:48 p.m</span></strong>. ET: Zeustracker recently posted this update to its site: Bad news:<span style="text-decoration: underline;"> <strong>Since Troyak started their peering with RTCOM-AS, the number of active ZeuS C&amp;C servers has increasted from 149 up to 191. For now, more than 40 ZeuS C&amp;C servers are back online!</strong></span> <span style="text-decoration: underline;">This means that the cybercriminals are now able to move the stolen data to a safe place or a backup server. </span>Additionally, the cybercriminals are able to update their config files served to the infected clients to set up a fallback server (if Troyak will disappear from the internet again).</p></blockquote>
<p>via <a href="http://www.krebsonsecurity.com/2010/03/dozens-of-zeus-botnets-knocked-offline/">Dozens of ZeuS Botnets Knocked Offline — Krebs on Security</a>.</p>
<p>An updated graph from zeustracker :</p>
<p style="text-align: center;"><a href="https://zeustracker.abuse.ch/statistic.php"><img class="aligncenter" src="http://www.honeynet.it/wp-content/uploads/zeus-trend1.jpg" alt="" width="637" height="223" /></a></p>
<p>The graph shows a sharp recover of   the Zeus activity during the last day. Online Zeus Configs had increased steeply for 149 to 223.</p>
<p>This information tell us  that the criminals are reacting to the Troyak-as take-off by updating their zombies to contact a new C&amp;C. Therefore, the Zeus activity will probably rally again in the next day.</p>
<p>In addition, <a href="http://threatpost.com/en_us/blogs/koobface-worm-doubles-cc-servers-48-hours-031110">Koobface worm doubles C&amp;C servers in 48 hours</a></p>
<p style="text-align: center;"><a href="http://www.krebsonsecurity.com/2010/03/dozens-of-zeus-botnets-knocked-offline/"><img src="http://www.honeynet.it/wp-content/uploads/evo_koobface_ccs.preview.png" alt="" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/botnet/the-recent-zeus-and-koobface-trends-fluctation/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Mariposa botnet. Another financial botnet that infected 12.7 computer (!?)</title>
		<link>http://www.honeynet.it/botnet/mariposa-botnet-another-financial-botnet-that-infected-12-7-computer</link>
		<comments>http://www.honeynet.it/botnet/mariposa-botnet-another-financial-botnet-that-infected-12-7-computer#comments</comments>
		<pubDate>Wed, 03 Mar 2010 08:44:57 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Media]]></category>
		<category><![CDATA[Press]]></category>
		<category><![CDATA[Financial Botnet]]></category>
		<category><![CDATA[Mariposa]]></category>
		<category><![CDATA[Spain]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=180</guid>
		<description><![CDATA[
SAN FRANCISCO (AP) &#8212; Authorities have smashed one of the world&#8217;s biggest networks of virus-infected computers, a data vacuum that stole credit cards and online banking credentials from as many as 12.7 million poisoned PCs. The &#8220;botnet&#8221; of infected computers included PCs inside more than half of the Fortune 1,000 companies and more than 40 [...]
]]></description>
			<content:encoded><![CDATA[<blockquote><p>SAN FRANCISCO (AP) &#8212; Authorities have smashed one of the world&#8217;s biggest networks of virus-infected computers, a data vacuum that stole credit cards and online banking credentials from as many as 12.7 million poisoned PCs.</p>
<p>The &#8220;botnet&#8221; of infected computers included PCs inside more than half of the Fortune 1,000 companies and more than 40 major banks, according to investigators.</p>
<p>Spanish investigators, working with private computer-security firms, have arrested the three alleged ringleaders of the so-called Mariposa botnet, which appeared in December 2008 and grew into one of the biggest weapons of cybercrime. More arrests are expected soon in other countries.</p>
<p>Spanish authorities have planned a news conference for Wednesday in Madrid.</p>
<p>[....]</p>
<p>Also, the suspects go against the stereotype of genius programmers often associated with cyber crime. The suspects weren&amp;apos;t brilliant hackers but had underworld contacts who helped them build and operate the botnet, Cesar Lorenza, a captain with Spain&amp;apos;s Guardia Civil, which is investigating the case, told The Associated Press.</p>
<p>Investigators were examining bank records and seized computers to determine how much money the criminals made.</p>
<p>[....]</p></blockquote>
<p>via <a href="http://hosted.ap.org/dynamic/stories/U/US_TEC_BOTNET_BUSTED?SITE=AP&amp;SECTION=HOME&amp;TEMPLATE=DEFAULT&amp;CTIME=2010-03-02-14-26-32">News from The Associated Press</a>.</p>
<p>An Analysis report by DefenceIntelligence  <a title="Analysis" href="http://defintel.com/docs/Mariposa_Analysis.pdf">here </a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/botnet/mariposa-botnet-another-financial-botnet-that-infected-12-7-computer/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cracking Down on Botnets &#8211;  Microsoft  against Waledac</title>
		<link>http://www.honeynet.it/botnet/the-official-microsoft-blog-%e2%80%93-news-and-perspectives-from-microsoft-cracking-down-on-botnets</link>
		<comments>http://www.honeynet.it/botnet/the-official-microsoft-blog-%e2%80%93-news-and-perspectives-from-microsoft-cracking-down-on-botnets#comments</comments>
		<pubDate>Thu, 25 Feb 2010 20:15:36 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Botnet 2.0]]></category>
		<category><![CDATA[Media]]></category>
		<category><![CDATA[Press]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[P2P]]></category>
		<category><![CDATA[waledac]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=176</guid>
		<description><![CDATA[
The takedown of the Waledac botnet that Microsoft executed this week – known internally as “Operation b49” – was the result of months of investigation and the innovative application of a tried and true legal strategy. [..] In a recent analysis, Microsoft found that between December 3-21, 2009, approximately 651 million spam emails attributable to [...]
]]></description>
			<content:encoded><![CDATA[<blockquote><p>The takedown of the Waledac botnet that Microsoft executed this week – known internally as “Operation b49” – was the result of months of investigation and the innovative application of a tried and true legal strategy.</p>
<p>[..]</p>
<p>In a recent analysis, Microsoft found that between December 3-21, 2009, approximately 651 million spam emails attributable to Waledac were directed to Hotmail accounts alone, including offers and scams related to online pharmacies, imitation goods, jobs, penny stocks and more.</p>
<p>[..]</p>
<p>This action has quickly and effectively cut off traffic to Waledac at the “.com” or domain registry level, severing the connection between the command and control centers of the botnet and most of its thousands of zombie computers around the world.</p></blockquote>
<p>via <a href="http://blogs.technet.com/microsoft_blog/archive/2010/02/25/cracking-down-on-botnets.aspx">The Official Microsoft Blog – Cracking Down on Botnets</a>.</p>
<p>Well done.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/botnet/the-official-microsoft-blog-%e2%80%93-news-and-perspectives-from-microsoft-cracking-down-on-botnets/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Zeus Steal $150,000 from insurance inc.</title>
		<link>http://www.honeynet.it/botnet/zeus-steal-150000-from-insurance-inc</link>
		<comments>http://www.honeynet.it/botnet/zeus-steal-150000-from-insurance-inc#comments</comments>
		<pubDate>Tue, 23 Feb 2010 08:57:15 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Media]]></category>
		<category><![CDATA[Press]]></category>
		<category><![CDATA[Financial Botnet]]></category>
		<category><![CDATA[zeus]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=174</guid>
		<description><![CDATA[
Port Austin, Mich. based United Shortline Insurance Service Inc., an insurance provider serving the railroad industry, discovered on Feb. 5 that the computer used by their firm’s controller was behaving oddly and would not respond. The company’s computer technician scoured the system with multiple security tools, and found it had been invaded by “ZeuS,” a [...]
]]></description>
			<content:encoded><![CDATA[<blockquote><p>Port Austin, Mich. based United Shortline Insurance Service Inc., an insurance provider serving the railroad industry, discovered on Feb. 5 that the computer used by their firm’s controller was behaving oddly and would not respond. The company’s computer technician scoured the system with multiple security tools, and found it had been invaded by “ZeuS,” a highly sophisticated banking Trojan that steals passwords and allows criminals to control infected hosts remotely</p>
<p>[...]</p>
<p>“The bank said whoever logged in to make these transfers successfully answered those questions,” he said. “They had some very detailed information. [The thieves] knew our patterns, they knew our passwords, my mother’s middle name, favorite sports team. And this is all information I don’t even have written down anywhere.”</p></blockquote>
<p>via <a href="http://www.krebsonsecurity.com/2010/02/hackers-steal-150000-from-mich-insurance-firm/">Hackers Steal $150,000 from Mich. Insurance Firm — Krebs on Security</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/botnet/zeus-steal-150000-from-insurance-inc/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Top 10 botnets and their impact</title>
		<link>http://www.honeynet.it/botnet/top-10-botnets-and-their-impact</link>
		<comments>http://www.honeynet.it/botnet/top-10-botnets-and-their-impact#comments</comments>
		<pubDate>Mon, 14 Dec 2009 13:16:45 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Media]]></category>
		<category><![CDATA[Report]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=157</guid>
		<description><![CDATA[
Message Labs&#38;apos; list of top 10 botnets in 2009 via Top 10 botnets and their impact.
]]></description>
			<content:encoded><![CDATA[<p>Message Labs&amp;apos; list of top 10 botnets in 2009</p>
<p>via <a href="http://www.net-security.org/secworld.php?id=8599">Top 10 botnets and their impact</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/botnet/top-10-botnets-and-their-impact/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Attending EC2ND</title>
		<link>http://www.honeynet.it/uncategorized/attending-ec2nd</link>
		<comments>http://www.honeynet.it/uncategorized/attending-ec2nd#comments</comments>
		<pubDate>Tue, 27 Oct 2009 16:14:22 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Media]]></category>
		<category><![CDATA[Paper]]></category>
		<category><![CDATA[The Dorothy Project]]></category>
		<category><![CDATA[The Italian Honeynet Project]]></category>
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=135</guid>
		<description><![CDATA[
I&#8217;m glad to inform that we will be attending the European Conference 2 Network Defence (EC2ND), scheduled on 9-10 November. This year the event is hosted by the Politecnico di Milano technical university in Milano, Italy. Me and marco will introduce the status of our  current activities. Hope to see you there!
]]></description>
			<content:encoded><![CDATA[<p>I&#8217;m glad to inform that we will be attending the European Conference 2 Network Defence (<a href="http://2009.ec2nd.org/" target="_blank">EC2ND</a>), scheduled on 9-10 November. This year the event is hosted by the <a href="http://www.polimi.it/">Politecnico di Milano</a> technical university in Milano, Italy.<br />
Me and marco will introduce the status of our  current activities.</p>
<p>Hope to see you there!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/uncategorized/attending-ec2nd/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>The botnet world is booming world &#124; The Industry Standard</title>
		<link>http://www.honeynet.it/media/the-botnet-world-is-booming-world-the-industry-standard</link>
		<comments>http://www.honeynet.it/media/the-botnet-world-is-booming-world-the-industry-standard#comments</comments>
		<pubDate>Fri, 10 Jul 2009 12:55:00 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Media]]></category>
		<category><![CDATA[Press]]></category>

		<guid isPermaLink="false">http://m4rc00.wordpress.com/2009/07/10/the-botnet-world-is-booming-world-the-industry-standard/</guid>
		<description><![CDATA[
The botnet world is booming world &#124; The Industry Standard Some press rumors.
]]></description>
			<content:encoded><![CDATA[<p><a href="http://m.thestandard.com/news/2009/07/09/botnet-world-booming-world">The botnet world is booming world | The Industry Standard</a> Some press rumors.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/media/the-botnet-world-is-booming-world-the-industry-standard/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

