<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Hack a Day &#187; anthony lineberry</title>
	<atom:link href="http://hackaday.com/tag/anthony-lineberry/feed/" rel="self" type="application/rss+xml" />
	<link>http://hackaday.com</link>
	<description>Fresh hacks every day</description>
	<lastBuildDate>Sun, 12 Feb 2012 08:18:03 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='hackaday.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://1.gravatar.com/blavatar/5560f98f805877b0e332f191cb9e0af3?s=96&#038;d=http%3A%2F%2Fs2.wp.com%2Fi%2Fbuttonw-com.png</url>
		<title>Hack a Day &#187; anthony lineberry</title>
		<link>http://hackaday.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://hackaday.com/osd.xml" title="Hack a Day" />
	<atom:link rel='hub' href='http://hackaday.com/?pushpress=hub'/>
		<item>
		<title>The Malware Challenge</title>
		<link>http://hackaday.com/2009/01/03/the-malware-challenge/</link>
		<comments>http://hackaday.com/2009/01/03/the-malware-challenge/#comments</comments>
		<pubDate>Sun, 04 Jan 2009 01:00:35 +0000</pubDate>
		<dc:creator>Eliot</dc:creator>
				<category><![CDATA[news]]></category>
		<category><![CDATA[security hacks]]></category>
		<category><![CDATA[anthony lineberry]]></category>
		<category><![CDATA[assembly]]></category>
		<category><![CDATA[contest]]></category>
		<category><![CDATA[debug]]></category>
		<category><![CDATA[flexilis]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[malware challenge]]></category>
		<category><![CDATA[ollydbg]]></category>
		<category><![CDATA[packer]]></category>
		<category><![CDATA[reverse engineer]]></category>
		<category><![CDATA[wireshark]]></category>

		<guid isPermaLink="false">http://hackaday.com/?p=7485</guid>
		<description><![CDATA[Our own [Anthony Lineberry] has written up his experience participating in the 2008 Malware Challenge as part of his work for Flexilis. The contest involved taking a piece of provided malware, doing a thorough analysis of its behavior, and reporting the results. This wasn&#8217;t just to test the chops of the researchers, but also to [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=7485&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img class="alignnone size-full wp-image-7486" title="malware" src="http://hackadaycom.files.wordpress.com/2009/01/malware.jpg" alt="malware" width="450" height="132" /></p>
<p>Our own [Anthony Lineberry] has written up <a title="The Official Flexilis Blog  |  The 2008 Malware Challenge" href="http://blog.flexilis.com/2008/12/the-2008-malware-challenge/">his experience participating in the </a><a title="2008 Malware Challenge" href="http://www.malwarechallenge.info/">2008 Malware Challenge</a> as part of his work for Flexilis. The contest involved taking a piece of provided malware, doing a thorough analysis of its behavior, and reporting the results. This wasn&#8217;t just to test the chops of the researchers, but also to demonstrate to network/system administrators how they could get into malware analysis themselves.</p>
<p>[Anthony] gives a good overview of how he created his entry (a more <a href="http://blog.flexilis.com/wp-content/uploads/2008/12/malwarechallenge2008.pdf">detailed PDF is here</a>). First, he unpacked the malware using <a title="OllyDbg v1.10" href="http://www.ollydbg.de/">Ollydbg</a>. Packers are used to obfuscate the actual malware code so that it&#8217;s harder for antivirus to pick it up. After taking a good look at the assembly, he executed the code. He used <a title="Go deep." href="http://www.wireshark.org/">Wireshark</a> to monitor the network traffic and determine what URL the malware was trying to reach. He changed the hostname to point at an IRC server he controlled. Eventually he would be able to issue botnet control commands directly to the malware. We look forward to seeing what next year&#8217;s contest will bring.</p>
<br />Posted in news, security hacks  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackadaycom.wordpress.com/7485/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackadaycom.wordpress.com/7485/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackadaycom.wordpress.com/7485/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackadaycom.wordpress.com/7485/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hackadaycom.wordpress.com/7485/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hackadaycom.wordpress.com/7485/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hackadaycom.wordpress.com/7485/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hackadaycom.wordpress.com/7485/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackadaycom.wordpress.com/7485/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackadaycom.wordpress.com/7485/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackadaycom.wordpress.com/7485/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackadaycom.wordpress.com/7485/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackadaycom.wordpress.com/7485/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackadaycom.wordpress.com/7485/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=7485&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hackaday.com/2009/01/03/the-malware-challenge/feed/</wfw:commentRss>
		<slash:comments>15</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">RobotSkirts</media:title>
		</media:content>

		<media:content url="http://hackadaycom.files.wordpress.com/2009/01/malware.jpg" medium="image">
			<media:title type="html">malware</media:title>
		</media:content>
	</item>
	</channel>
</rss>
