<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The Italian Honey Project &#187; Uncategorized</title>
	<atom:link href="http://www.honeynet.it/category/uncategorized/feed" rel="self" type="application/rss+xml" />
	<link>http://www.honeynet.it</link>
	<description>The Italian chapter of the Honeynet Research Alliance</description>
	<lastBuildDate>Wed, 11 Jan 2012 11:44:56 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Zbot Targets Android Users &#8211; Softpedia</title>
		<link>http://www.honeynet.it/uncategorized/zbot-targets-android-users-softpedia</link>
		<comments>http://www.honeynet.it/uncategorized/zbot-targets-android-users-softpedia#comments</comments>
		<pubDate>Mon, 11 Jul 2011 11:10:18 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Financial Botnet]]></category>
		<category><![CDATA[mobile]]></category>
		<category><![CDATA[zbot]]></category>
		<category><![CDATA[zeus]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=420</guid>
		<description><![CDATA[
Security researchers have identified a Zbot component designed for Android which steals mobile transaction authentication numbers send by banks via SMS.ZeuS, aka Zbot, is one of the most popular banking trojans. Even though the original author of the malware has retired, the source code is available online for anyone to modify and fit it to [...]
]]></description>
			<content:encoded><![CDATA[<blockquote><p>Security researchers have identified a Zbot component designed for Android which steals mobile transaction authentication numbers send by banks via SMS.ZeuS, aka Zbot, is one of the most popular banking trojans. Even though the original author of the malware has retired, the source code is available online for anyone to modify and fit it to their needs.Zbot originally targeted desktop systems and stole financial information and online banking credentials which fraudsters exploited.</p></blockquote>
<p>via <a href="http://news.softpedia.com/news/Zbot-Targets-Android-Users-210645.shtml">Zbot Targets Android Users &#8211; Softpedia</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/uncategorized/zbot-targets-android-users-softpedia/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>TDL4 – High sophisticated botnet unveiled</title>
		<link>http://www.honeynet.it/uncategorized/tdl4-%e2%80%93-high-sophisticated-botnet-unveiled</link>
		<comments>http://www.honeynet.it/uncategorized/tdl4-%e2%80%93-high-sophisticated-botnet-unveiled#comments</comments>
		<pubDate>Fri, 01 Jul 2011 08:22:08 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Botnet]]></category>
		<category><![CDATA[P2P]]></category>
		<category><![CDATA[TDSS]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=418</guid>
		<description><![CDATA[
The fact that TDL-4 code shows active development — a rootkit for 64-bit systems, the malware running prior to operating system start launches, the use of exploits from Stuxnet’s arsenal, P2P technology, its own ‘antivirus’ and a lot more — place TDSS firmly in the ranks of the most technologically sophisticated, and most complex to [...]
]]></description>
			<content:encoded><![CDATA[<blockquote><p>The fact that TDL-4 code shows active development — a rootkit for 64-bit systems, the malware running prior to operating system start launches, the use of exploits from Stuxnet’s arsenal, P2P technology, its own ‘antivirus’ and a lot more — place TDSS firmly in the ranks of the most technologically sophisticated, and most complex to analyze, malware.</p></blockquote>
<p>via <a href="http://www.securelist.com/en/analysis/204792180/TDL4_Top_Bot">TDL4 – Top Bot &#8211; Securelist</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/uncategorized/tdl4-%e2%80%93-high-sophisticated-botnet-unveiled/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Chapter report for 2010 just published</title>
		<link>http://www.honeynet.it/uncategorized/chapter-report-for-2010-just-published</link>
		<comments>http://www.honeynet.it/uncategorized/chapter-report-for-2010-just-published#comments</comments>
		<pubDate>Wed, 15 Jun 2011 08:08:00 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=413</guid>
		<description><![CDATA[
Hi there, I&#8217;d like to announce that our yearly annual report has just been published. In addition, in our repository you can find the slides of the talks that I had at the Honeynet annual workshop. enjoy.
]]></description>
			<content:encoded><![CDATA[<p>Hi there,</p>
<p>I&#8217;d like to announce that our yearly annual report has just been <a href="https://www.honeynet.org/node/689">published</a>.</p>
<p>In addition, in our repository you can find the slides of the talks that I had at the Honeynet annual workshop.</p>
<p>enjoy.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/uncategorized/chapter-report-for-2010-just-published/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Dream Loader: a new bot C&amp;C engine</title>
		<link>http://www.honeynet.it/uncategorized/dream-loader-a-new-bot-cc-engine</link>
		<comments>http://www.honeynet.it/uncategorized/dream-loader-a-new-bot-cc-engine#comments</comments>
		<pubDate>Tue, 21 Dec 2010 09:41:49 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Botnet]]></category>
		<category><![CDATA[dream loader]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=375</guid>
		<description><![CDATA[
The backdoor offers very simple functionality, mainly to load other components. It has some common tricks to hide itself in the infected machine, in order to make it more difficult for a user to notice its presence. The main commands that can be sent to the backdoor are: download and run an executable, download and [...]
]]></description>
			<content:encoded><![CDATA[<blockquote><p>The backdoor offers very simple functionality, mainly to load other components. It has some common tricks to hide itself in the infected machine, in order to make it more difficult for a user to notice its presence.</p>
<p>The main commands that can be sent to the backdoor are: download and run an executable, download and install a plugin, update the bot itself, reboot the machine, and uninstall the bot. The main purpose of this backdoor is therefore to offer a gateway to the attacker so that he can download and install his own malware.</p></blockquote>
<blockquote><p>This backdoor is not very widespread yet, but it has the potential to evolve into a more dangerous threat in the future; as always, we recommend the users to update their software and security products, and to use common sense in order to avoid malware.</p></blockquote>
<p>via <a href="http://www.symantec.com/connect/blogs/dream-loader-new-bot-cc-engine-your-dreams#">Dream Loader: the new bot C&amp;C engine of your dreams | Symantec Connect</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/uncategorized/dream-loader-a-new-bot-cc-engine/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New Spyeye C&amp;C Server Targets Polish Users uncovered by Trend Micro</title>
		<link>http://www.honeynet.it/uncategorized/new-spyeye-cc-server-targets-polish-users-uncovered-by-trend-micro</link>
		<comments>http://www.honeynet.it/uncategorized/new-spyeye-cc-server-targets-polish-users-uncovered-by-trend-micro#comments</comments>
		<pubDate>Thu, 09 Sep 2010 09:18:59 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Financial Botnet]]></category>
		<category><![CDATA[SpyEye]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=341</guid>
		<description><![CDATA[
We were able to further investigate a command-and-control C&#38;C server of a SpyEye botnet, most of whose zombies were located in Poland. This is somewhat unusual, as bot herders prefer to target Western countries like the United States, the United Kingdom, Germany, Italy, Spain, and France. via Uncovered Spyeye C&#38;C Server Targets Polish Users &#124; [...]
]]></description>
			<content:encoded><![CDATA[<blockquote><p>We were able to further investigate a command-and-control C&amp;C server of a SpyEye botnet, most of whose zombies were located in Poland. This is somewhat unusual, as bot herders prefer to target Western countries like the United States, the United Kingdom, Germany, Italy, Spain, and France.</p></blockquote>
<p>via <a href="http://blog.trendmicro.com/uncovered-spyeye-cc-server-targets-polish-users/">Uncovered Spyeye C&amp;C Server Targets Polish Users | Malware Blog | Trend Micro</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/uncategorized/new-spyeye-cc-server-targets-polish-users-uncovered-by-trend-micro/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Honeynet Forensic Challange 5 kickoff</title>
		<link>http://www.honeynet.it/uncategorized/honeynet-forensic-challange-5-kickoff</link>
		<comments>http://www.honeynet.it/uncategorized/honeynet-forensic-challange-5-kickoff#comments</comments>
		<pubDate>Thu, 09 Sep 2010 07:06:49 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Forensic Challenge]]></category>
		<category><![CDATA[The Honeynet Project]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=338</guid>
		<description><![CDATA[
The FC5:  Log Mysteries   has started last week thanks of the collaboration of   Raffael Marty, Anton Chuvakin f and  Sebastien Tricaud. Everybody is welcome to participate to this intriguing challenge ! Below are the instructions of the challange : The Challenge: Analyze the attached sanitized_log.zip and answer the following questions: Was the system compromised [...]
]]></description>
			<content:encoded><![CDATA[<p>The FC5:  Log Mysteries   has started last week thanks of the collaboration of   Raffael Marty, Anton Chuvakin f and  Sebastien Tricaud.</p>
<p>Everybody is welcome to participate to this intriguing challenge !</p>
<p>Below are the instructions of the challange :</p>
<blockquote><p><strong>The Challenge:</strong><br />
Analyze the attached sanitized_log.zip and answer the following questions:</p>
<ol>
<li>Was the system compromised and when? How do you know that for sure? (5pts)</li>
<li>If the was compromised, what was the method used? (5pts)</li>
<li>Can you locate how many attackers failed? If some succeeded, how  many were they? How many stopped attacking after the first success?  (5pts)</li>
<li>What happened after the brute force attack? (5pts)</li>
<li>Locate the authentication logs, was a bruteforce attack performed? if yes how many? (5pts)</li>
<li>What is the timeline of significant events? How certain are you of the timing? (5pts)</li>
<li>Anything else that looks suspicious in the logs? Any misconfigurations? Other issues? (5pts)</li>
<li>Was an automatic tool used to perform the attack? if yes which one? (5pts)</li>
<li>What can you say about the attacker&#8217;s goals and methods? (5pts)</li>
</ol>
<p>Bonus. What would you have done to avoid this attack? (5pts)</p></blockquote>
<p><a title="FC5" href="http://www.honeynet.org/challenges/2010_5_log_mysteries" target="_blank">This </a>is the website of the challenge where you can find any other detail.</p>
<p>Enjoy!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/uncategorized/honeynet-forensic-challange-5-kickoff/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Realtime visualization by Nicter</title>
		<link>http://www.honeynet.it/uncategorized/realtime-visualization-by-diginfo</link>
		<comments>http://www.honeynet.it/uncategorized/realtime-visualization-by-diginfo#comments</comments>
		<pubDate>Mon, 28 Jun 2010 06:33:53 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Visualization]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=285</guid>
		<description><![CDATA[
A nice visualization method developed by Nicter. Here is  the demo
]]></description>
			<content:encoded><![CDATA[<p>A nice visualization method developed by Nicter.</p>
<p>Here is  the <a href="http://www.diginfo.tv/2010/06/22/10-0092-r-en.php">demo</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/uncategorized/realtime-visualization-by-diginfo/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Thieves Flood Victim’s Phone With Calls to Loot Bank Accounts</title>
		<link>http://www.honeynet.it/uncategorized/thieves-flood-victim%e2%80%99s-phone-with-calls-to-loot-bank-accounts</link>
		<comments>http://www.honeynet.it/uncategorized/thieves-flood-victim%e2%80%99s-phone-with-calls-to-loot-bank-accounts#comments</comments>
		<pubDate>Mon, 17 May 2010 07:57:22 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Financial Botnet]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=256</guid>
		<description><![CDATA[
Bank thieves have rolled out a new weapon in their arsenal of tactics — telephony denial-of-service attacks that flood a victim’s phone with diversionary calls while the thieves drain the victim’s account of money.A Florida dentist lost $400,000 from his retirement account last year in this manner, and the FBI said the attacks are growing. [...]
]]></description>
			<content:encoded><![CDATA[<blockquote><p>Bank thieves have rolled out a new weapon in their arsenal of tactics — telephony denial-of-service attacks that flood a victim’s phone with diversionary calls while the thieves drain the victim’s account of money.A Florida dentist lost $400,000 from his retirement account last year in this manner, and the FBI said the attacks are growing.</p></blockquote>
<p>via <a href="http://www.wired.com/threatlevel/2010/05/telephony-dos/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+wired%2Findex+%28Wired%3A+Index+3+%28Top+Stories+2%29%29">Thieves Flood Victim’s Phone With Calls to Loot Bank Accounts | Threat Level | Wired.com</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/uncategorized/thieves-flood-victim%e2%80%99s-phone-with-calls-to-loot-bank-accounts/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>InBot&#8217;10</title>
		<link>http://www.honeynet.it/uncategorized/inbot10</link>
		<comments>http://www.honeynet.it/uncategorized/inbot10#comments</comments>
		<pubDate>Sun, 18 Apr 2010 21:52:54 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=235</guid>
		<description><![CDATA[
I&#8217;m attended to InBot&#8217;10 conference for presenting our researches on Dorothy. My speech is planned for Wednesday 21th @ 16:00 , hope to see you there! p.s. &#8230;hoping that my flight wont be deleted due to the volcanic ash :S
]]></description>
			<content:encoded><![CDATA[<p>I&#8217;m attended to <a title="inbot'10" href="http://inbot.mwcollect.org/">InBot&#8217;10</a> conference for presenting our researches on Dorothy.</p>
<p>My speech is planned for Wednesday 21th @ 16:00 , hope to see you there!</p>
<p>p.s. &#8230;hoping that my flight wont be deleted due to the <a href="http://news.bbc.co.uk/2/hi/europe/8627720.stm">volcanic ash </a>:S</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/uncategorized/inbot10/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>March 18th &#8211; Italian Security Summit 2010 &#8211; Milan</title>
		<link>http://www.honeynet.it/uncategorized/march-18th-italian-security-summit-2010-milan</link>
		<comments>http://www.honeynet.it/uncategorized/march-18th-italian-security-summit-2010-milan#comments</comments>
		<pubDate>Mon, 15 Mar 2010 17:12:12 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=200</guid>
		<description><![CDATA[
Folks, I will attend to the Italian Security Summit 2010 in Milan on March 18th, for the the challenge &#8220;Best Italian thesis about IS &#8211; 2009&#8243;. I will present the The Dorothy Project as a work related to the honeynet chapter,showing all our last improvements. Hope to see you there! saludos
]]></description>
			<content:encoded><![CDATA[<p>Folks,</p>
<p>I will attend to the <a href="https://www.securitysummit.it/">Italian Security Summit</a> 2010 in Milan on March 18th, for the the <a href="https://tesi.clusit.it/">challenge</a> &#8220;Best Italian thesis about IS &#8211; 2009&#8243;.</p>
<p>I will present the The Dorothy Project as a work related to the honeynet chapter,showing all our last improvements.</p>
<p>Hope to see you there!</p>
<p>saludos</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/uncategorized/march-18th-italian-security-summit-2010-milan/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

