<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The Italian Honey Project &#187; Media</title>
	<atom:link href="http://www.honeynet.it/category/media/feed" rel="self" type="application/rss+xml" />
	<link>http://www.honeynet.it</link>
	<description>The Italian chapter of the Honeynet Research Alliance</description>
	<lastBuildDate>Tue, 10 Aug 2010 12:54:12 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>The Opt-in Botnet Generation</title>
		<link>http://www.honeynet.it/botnet/the-opt-in-botnet-generation</link>
		<comments>http://www.honeynet.it/botnet/the-opt-in-botnet-generation#comments</comments>
		<pubDate>Tue, 27 Apr 2010 18:41:53 +0000</pubDate>
		<dc:creator>claudio.guarnieri</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Media]]></category>
		<category><![CDATA[Report]]></category>
		<category><![CDATA[Opt-In]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=246</guid>
		<description><![CDATA[
Botnets have always been considered a severe threat that removes PCs and servers from IT control. However, botnet compromises have always come from the accidental and unknowing installation of bot malware. The purposeful and intentional acceptance of bot malware, however laudable the cause, presents a dangerous challenge to any organization concerned about maintaining control over [...]
]]></description>
			<content:encoded><![CDATA[<blockquote><p>Botnets have always been considered a severe threat that removes PCs and servers from IT control. However, botnet compromises have always come from the accidental and unknowing installation of bot malware. The purposeful and intentional acceptance of bot malware, however laudable the cause, presents a dangerous challenge to any organization concerned about maintaining control over network assets and demonstrating proper fiduciary responsibility.</p>
<p>In short, the introduction of social networking CnC and an increasingly diverse range of motivations and common-cause group memberships is opening the doors to new cyber-protesting possibilities – and to criminal misappropriation of hacktivist botnets. This whitepaper examines the evolutionary path of opt-in botnets, including how tactics have changed, why anyone would willingly choose to join a botnet, and what activist botnets mean to organizations that find themselves both victims and enablers of a botnet-driven attack.</p></blockquote>
<p>From: <a href="http://www.damballa.com/research/optinbotnet/index.php">Damballa.com</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/botnet/the-opt-in-botnet-generation/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The recent ZeuS and Koobface trends fluctuation</title>
		<link>http://www.honeynet.it/botnet/the-recent-zeus-and-koobface-trends-fluctation</link>
		<comments>http://www.honeynet.it/botnet/the-recent-zeus-and-koobface-trends-fluctation#comments</comments>
		<pubDate>Fri, 12 Mar 2010 09:45:04 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Media]]></category>
		<category><![CDATA[Financial Botnet]]></category>
		<category><![CDATA[koobface]]></category>
		<category><![CDATA[zeus]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=193</guid>
		<description><![CDATA[
Security experts are tracking a massive drop in the global number of control servers for various ZeuS botnets that are online, suggesting that a coordinated takedown effort may have been executed by law enforcement and/or volunteers from the security research community acting in tandem. [....] Update, 4:36 p.m. ET: Sadly, it appears that Troyak — [...]
]]></description>
			<content:encoded><![CDATA[<blockquote><p>Security experts are tracking a massive drop in the global number of control servers for various ZeuS botnets that are online, suggesting that a coordinated takedown effort may have been executed by law enforcement and/or volunteers from the security research community acting in tandem.</p>
<p>[....]</p>
<p><span style="text-decoration: underline;"><strong>Update, 4:36 p.m</strong>.</span> ET: Sadly, it appears that Troyak — the Internet provider that played host to all these ZeuS-infested networks that got knocked offline yesterday — has since found another upstream provider to once again connect it to the rest of the Internet.</p>
<p><strong><span style="text-decoration: underline;">Update, Mar. 11, 5:48 p.m</span></strong>. ET: Zeustracker recently posted this update to its site: Bad news:<span style="text-decoration: underline;"> <strong>Since Troyak started their peering with RTCOM-AS, the number of active ZeuS C&amp;C servers has increasted from 149 up to 191. For now, more than 40 ZeuS C&amp;C servers are back online!</strong></span> <span style="text-decoration: underline;">This means that the cybercriminals are now able to move the stolen data to a safe place or a backup server. </span>Additionally, the cybercriminals are able to update their config files served to the infected clients to set up a fallback server (if Troyak will disappear from the internet again).</p></blockquote>
<p>via <a href="http://www.krebsonsecurity.com/2010/03/dozens-of-zeus-botnets-knocked-offline/">Dozens of ZeuS Botnets Knocked Offline — Krebs on Security</a>.</p>
<p>An updated graph from zeustracker :</p>
<p style="text-align: center;"><a href="https://zeustracker.abuse.ch/statistic.php"><img class="aligncenter" src="http://www.honeynet.it/wp-content/uploads/zeus-trend1.jpg" alt="" width="637" height="223" /></a></p>
<p>The graph shows a sharp recover of   the Zeus activity during the last day. Online Zeus Configs had increased steeply for 149 to 223.</p>
<p>This information tell us  that the criminals are reacting to the Troyak-as take-off by updating their zombies to contact a new C&amp;C. Therefore, the Zeus activity will probably rally again in the next day.</p>
<p>In addition, <a href="http://threatpost.com/en_us/blogs/koobface-worm-doubles-cc-servers-48-hours-031110">Koobface worm doubles C&amp;C servers in 48 hours</a></p>
<p style="text-align: center;"><a href="http://www.krebsonsecurity.com/2010/03/dozens-of-zeus-botnets-knocked-offline/"><img src="http://www.honeynet.it/wp-content/uploads/evo_koobface_ccs.preview.png" alt="" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/botnet/the-recent-zeus-and-koobface-trends-fluctation/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Mariposa botnet. Another financial botnet that infected 12.7 computer (!?)</title>
		<link>http://www.honeynet.it/botnet/mariposa-botnet-another-financial-botnet-that-infected-12-7-computer</link>
		<comments>http://www.honeynet.it/botnet/mariposa-botnet-another-financial-botnet-that-infected-12-7-computer#comments</comments>
		<pubDate>Wed, 03 Mar 2010 08:44:57 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Media]]></category>
		<category><![CDATA[Press]]></category>
		<category><![CDATA[Financial Botnet]]></category>
		<category><![CDATA[Mariposa]]></category>
		<category><![CDATA[Spain]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=180</guid>
		<description><![CDATA[
SAN FRANCISCO (AP) &#8212; Authorities have smashed one of the world&#8217;s biggest networks of virus-infected computers, a data vacuum that stole credit cards and online banking credentials from as many as 12.7 million poisoned PCs. The &#8220;botnet&#8221; of infected computers included PCs inside more than half of the Fortune 1,000 companies and more than 40 [...]
]]></description>
			<content:encoded><![CDATA[<blockquote><p>SAN FRANCISCO (AP) &#8212; Authorities have smashed one of the world&#8217;s biggest networks of virus-infected computers, a data vacuum that stole credit cards and online banking credentials from as many as 12.7 million poisoned PCs.</p>
<p>The &#8220;botnet&#8221; of infected computers included PCs inside more than half of the Fortune 1,000 companies and more than 40 major banks, according to investigators.</p>
<p>Spanish investigators, working with private computer-security firms, have arrested the three alleged ringleaders of the so-called Mariposa botnet, which appeared in December 2008 and grew into one of the biggest weapons of cybercrime. More arrests are expected soon in other countries.</p>
<p>Spanish authorities have planned a news conference for Wednesday in Madrid.</p>
<p>[....]</p>
<p>Also, the suspects go against the stereotype of genius programmers often associated with cyber crime. The suspects weren&amp;apos;t brilliant hackers but had underworld contacts who helped them build and operate the botnet, Cesar Lorenza, a captain with Spain&amp;apos;s Guardia Civil, which is investigating the case, told The Associated Press.</p>
<p>Investigators were examining bank records and seized computers to determine how much money the criminals made.</p>
<p>[....]</p></blockquote>
<p>via <a href="http://hosted.ap.org/dynamic/stories/U/US_TEC_BOTNET_BUSTED?SITE=AP&amp;SECTION=HOME&amp;TEMPLATE=DEFAULT&amp;CTIME=2010-03-02-14-26-32">News from The Associated Press</a>.</p>
<p>An Analysis report by DefenceIntelligence  <a title="Analysis" href="http://defintel.com/docs/Mariposa_Analysis.pdf">here </a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/botnet/mariposa-botnet-another-financial-botnet-that-infected-12-7-computer/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cracking Down on Botnets &#8211;  Microsoft  against Waledac</title>
		<link>http://www.honeynet.it/botnet/the-official-microsoft-blog-%e2%80%93-news-and-perspectives-from-microsoft-cracking-down-on-botnets</link>
		<comments>http://www.honeynet.it/botnet/the-official-microsoft-blog-%e2%80%93-news-and-perspectives-from-microsoft-cracking-down-on-botnets#comments</comments>
		<pubDate>Thu, 25 Feb 2010 20:15:36 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Botnet 2.0]]></category>
		<category><![CDATA[Media]]></category>
		<category><![CDATA[Press]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[P2P]]></category>
		<category><![CDATA[waledac]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=176</guid>
		<description><![CDATA[
The takedown of the Waledac botnet that Microsoft executed this week – known internally as “Operation b49” – was the result of months of investigation and the innovative application of a tried and true legal strategy. [..] In a recent analysis, Microsoft found that between December 3-21, 2009, approximately 651 million spam emails attributable to [...]
]]></description>
			<content:encoded><![CDATA[<blockquote><p>The takedown of the Waledac botnet that Microsoft executed this week – known internally as “Operation b49” – was the result of months of investigation and the innovative application of a tried and true legal strategy.</p>
<p>[..]</p>
<p>In a recent analysis, Microsoft found that between December 3-21, 2009, approximately 651 million spam emails attributable to Waledac were directed to Hotmail accounts alone, including offers and scams related to online pharmacies, imitation goods, jobs, penny stocks and more.</p>
<p>[..]</p>
<p>This action has quickly and effectively cut off traffic to Waledac at the “.com” or domain registry level, severing the connection between the command and control centers of the botnet and most of its thousands of zombie computers around the world.</p></blockquote>
<p>via <a href="http://blogs.technet.com/microsoft_blog/archive/2010/02/25/cracking-down-on-botnets.aspx">The Official Microsoft Blog – Cracking Down on Botnets</a>.</p>
<p>Well done.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/botnet/the-official-microsoft-blog-%e2%80%93-news-and-perspectives-from-microsoft-cracking-down-on-botnets/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Zeus Steal $150,000 from insurance inc.</title>
		<link>http://www.honeynet.it/botnet/zeus-steal-150000-from-insurance-inc</link>
		<comments>http://www.honeynet.it/botnet/zeus-steal-150000-from-insurance-inc#comments</comments>
		<pubDate>Tue, 23 Feb 2010 08:57:15 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Media]]></category>
		<category><![CDATA[Press]]></category>
		<category><![CDATA[Financial Botnet]]></category>
		<category><![CDATA[zeus]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=174</guid>
		<description><![CDATA[
Port Austin, Mich. based United Shortline Insurance Service Inc., an insurance provider serving the railroad industry, discovered on Feb. 5 that the computer used by their firm’s controller was behaving oddly and would not respond. The company’s computer technician scoured the system with multiple security tools, and found it had been invaded by “ZeuS,” a [...]
]]></description>
			<content:encoded><![CDATA[<blockquote><p>Port Austin, Mich. based United Shortline Insurance Service Inc., an insurance provider serving the railroad industry, discovered on Feb. 5 that the computer used by their firm’s controller was behaving oddly and would not respond. The company’s computer technician scoured the system with multiple security tools, and found it had been invaded by “ZeuS,” a highly sophisticated banking Trojan that steals passwords and allows criminals to control infected hosts remotely</p>
<p>[...]</p>
<p>“The bank said whoever logged in to make these transfers successfully answered those questions,” he said. “They had some very detailed information. [The thieves] knew our patterns, they knew our passwords, my mother’s middle name, favorite sports team. And this is all information I don’t even have written down anywhere.”</p></blockquote>
<p>via <a href="http://www.krebsonsecurity.com/2010/02/hackers-steal-150000-from-mich-insurance-firm/">Hackers Steal $150,000 from Mich. Insurance Firm — Krebs on Security</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/botnet/zeus-steal-150000-from-insurance-inc/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Top 10 botnets and their impact</title>
		<link>http://www.honeynet.it/botnet/top-10-botnets-and-their-impact</link>
		<comments>http://www.honeynet.it/botnet/top-10-botnets-and-their-impact#comments</comments>
		<pubDate>Mon, 14 Dec 2009 13:16:45 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Media]]></category>
		<category><![CDATA[Report]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=157</guid>
		<description><![CDATA[
Message Labs&#38;apos; list of top 10 botnets in 2009 via Top 10 botnets and their impact.
]]></description>
			<content:encoded><![CDATA[<p>Message Labs&amp;apos; list of top 10 botnets in 2009</p>
<p>via <a href="http://www.net-security.org/secworld.php?id=8599">Top 10 botnets and their impact</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/botnet/top-10-botnets-and-their-impact/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Attending EC2ND</title>
		<link>http://www.honeynet.it/uncategorized/attending-ec2nd</link>
		<comments>http://www.honeynet.it/uncategorized/attending-ec2nd#comments</comments>
		<pubDate>Tue, 27 Oct 2009 16:14:22 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Media]]></category>
		<category><![CDATA[Paper]]></category>
		<category><![CDATA[The Dorothy Project]]></category>
		<category><![CDATA[The Italian Honeynet Project]]></category>
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=135</guid>
		<description><![CDATA[
I&#8217;m glad to inform that we will be attending the European Conference 2 Network Defence (EC2ND), scheduled on 9-10 November. This year the event is hosted by the Politecnico di Milano technical university in Milano, Italy. Me and marco will introduce the status of our  current activities. Hope to see you there!
]]></description>
			<content:encoded><![CDATA[<p>I&#8217;m glad to inform that we will be attending the European Conference 2 Network Defence (<a href="http://2009.ec2nd.org/" target="_blank">EC2ND</a>), scheduled on 9-10 November. This year the event is hosted by the <a href="http://www.polimi.it/">Politecnico di Milano</a> technical university in Milano, Italy.<br />
Me and marco will introduce the status of our  current activities.</p>
<p>Hope to see you there!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/uncategorized/attending-ec2nd/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>The botnet world is booming world &#124; The Industry Standard</title>
		<link>http://www.honeynet.it/media/the-botnet-world-is-booming-world-the-industry-standard</link>
		<comments>http://www.honeynet.it/media/the-botnet-world-is-booming-world-the-industry-standard#comments</comments>
		<pubDate>Fri, 10 Jul 2009 12:55:00 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Media]]></category>
		<category><![CDATA[Press]]></category>

		<guid isPermaLink="false">http://m4rc00.wordpress.com/2009/07/10/the-botnet-world-is-booming-world-the-industry-standard/</guid>
		<description><![CDATA[
The botnet world is booming world &#124; The Industry Standard Some press rumors.
]]></description>
			<content:encoded><![CDATA[<p><a href="http://m.thestandard.com/news/2009/07/09/botnet-world-booming-world">The botnet world is booming world | The Industry Standard</a> Some press rumors.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/media/the-botnet-world-is-booming-world-the-industry-standard/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
