<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Hack a Day &#187; Dan Kaminsky</title>
	<atom:link href="http://hackaday.com/tag/dan-kaminsky/feed/" rel="self" type="application/rss+xml" />
	<link>http://hackaday.com</link>
	<description>Fresh hacks every day</description>
	<lastBuildDate>Fri, 10 Feb 2012 12:56:16 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='hackaday.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://1.gravatar.com/blavatar/5560f98f805877b0e332f191cb9e0af3?s=96&#038;d=http%3A%2F%2Fs2.wp.com%2Fi%2Fbuttonw-com.png</url>
		<title>Hack a Day &#187; Dan Kaminsky</title>
		<link>http://hackaday.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://hackaday.com/osd.xml" title="Hack a Day" />
	<atom:link rel='hub' href='http://hackaday.com/?pushpress=hub'/>
		<item>
		<title>Containing Conficker</title>
		<link>http://hackaday.com/2009/03/30/containing-conficker/</link>
		<comments>http://hackaday.com/2009/03/30/containing-conficker/#comments</comments>
		<pubDate>Tue, 31 Mar 2009 00:22:01 +0000</pubDate>
		<dc:creator>Eliot</dc:creator>
				<category><![CDATA[downloads hacks]]></category>
		<category><![CDATA[security hacks]]></category>
		<category><![CDATA[conficker]]></category>
		<category><![CDATA[Dan Kaminsky]]></category>
		<category><![CDATA[honeynet project]]></category>
		<category><![CDATA[network scanner]]></category>
		<category><![CDATA[nmap]]></category>
		<category><![CDATA[patch]]></category>
		<category><![CDATA[rich mogull]]></category>
		<category><![CDATA[scan]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[svn]]></category>
		<category><![CDATA[whitepaper]]></category>
		<category><![CDATA[windows]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://hackaday.com/?p=9999</guid>
		<description><![CDATA[With all the noise about Conficker turning your computer into liquid hot magma on April 1st, there&#8217;s actually some positive news. Researchers from the HoneyNet Project have been following the worm since infections started in late 2008. They recently discovered an easy way to identify infected systems remotely. Conficker attempts to patch the MS08-067 vulnerability [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=9999&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img class="alignnone size-full wp-image-10000" title="conficker" src="http://hackadaycom.files.wordpress.com/2009/03/conficker.jpg" alt="conficker" width="450" height="220" /></p>
<p>With <a title="The Internet Is Infected - CBS News Video" href="http://www.cbsnews.com/video/watch/?id=4901282n">all the noise</a> about <a title="Conficker - Wikipedia, the free encyclopedia" href="http://en.wikipedia.org/wiki/Conficker">Conficker</a> turning your computer into liquid hot magma on April 1st, there&#8217;s actually some positive news. Researchers from the <a title="Honeynet Project Blog | The Honeynet Project" href="http://www.honeynet.org/">HoneyNet Project</a> have been following the worm since infections started in late 2008. They recently discovered an easy way to identify infected systems remotely. Conficker attempts to patch the MS08-067 vulnerability during infection. A flaw in the patch causes the machine to respond differently than both an unpatched system and an officially patched system. Using this knowledge, the team developed a proof of concept network scanner in python to find infected machines. You can find it in <a title="(Updated) Easily Detect Conficker Infections- Over the Network | securosis.com" href="http://securosis.com/2009/03/30/easily-detect-conficker-infections-over-the-network/">[Rich Mogull]&#8216;s initial post</a>. [Dan Kaminisky] has <a title="Tools, Tools, Tools : DoxPara Research" href="http://www.doxpara.com/?p=1291">packaged it as an EXE</a> and has instructions for how to build the SVN version of <a title="Nmap - Free Security Scanner For Network Exploration &amp; Security Audits." href="http://nmap.org/">Nmap</a>, which includes the new signature. Other network scanner vendors are adding the code as well.</p>
<p>In conjunction with this detection code, the team has also released the whitepaper <a title="Know Your Enemy: Containing Conficker | The Honeynet Project" href="http://www.honeynet.org/papers/conficker">Know Your Enemy: Containing Conficker</a>. It discusses ways to detect, contain, and remove Conficker. They&#8217;ve combined this with a <a title="Informatik IV: Containing Conficker" href="http://iv.cs.uni-bonn.de/wg/cs/applications/containing-conficker/">tool release</a> that covers Conficker&#8217;s dynamic domain generation among other things.</p>
<br />Posted in downloads hacks, security hacks  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackadaycom.wordpress.com/9999/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackadaycom.wordpress.com/9999/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackadaycom.wordpress.com/9999/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackadaycom.wordpress.com/9999/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hackadaycom.wordpress.com/9999/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hackadaycom.wordpress.com/9999/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hackadaycom.wordpress.com/9999/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hackadaycom.wordpress.com/9999/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackadaycom.wordpress.com/9999/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackadaycom.wordpress.com/9999/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackadaycom.wordpress.com/9999/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackadaycom.wordpress.com/9999/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackadaycom.wordpress.com/9999/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackadaycom.wordpress.com/9999/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=9999&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hackaday.com/2009/03/30/containing-conficker/feed/</wfw:commentRss>
		<slash:comments>49</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">RobotSkirts</media:title>
		</media:content>

		<media:content url="http://hackadaycom.files.wordpress.com/2009/03/conficker.jpg" medium="image">
			<media:title type="html">conficker</media:title>
		</media:content>
	</item>
		<item>
		<title>Apple finally fixes DNS bug</title>
		<link>http://hackaday.com/2008/09/15/apple-finally-fixes-dns-bug/</link>
		<comments>http://hackaday.com/2008/09/15/apple-finally-fixes-dns-bug/#comments</comments>
		<pubDate>Mon, 15 Sep 2008 21:24:29 +0000</pubDate>
		<dc:creator>Eliot</dc:creator>
				<category><![CDATA[iphone hacks]]></category>
		<category><![CDATA[macs hacks]]></category>
		<category><![CDATA[news]]></category>
		<category><![CDATA[security hacks]]></category>
		<category><![CDATA[apple]]></category>
		<category><![CDATA[bind]]></category>
		<category><![CDATA[bug]]></category>
		<category><![CDATA[Dan Kaminsky]]></category>
		<category><![CDATA[dns]]></category>
		<category><![CDATA[DNS cache poisoning]]></category>
		<category><![CDATA[iphone]]></category>
		<category><![CDATA[mdnsresponder]]></category>
		<category><![CDATA[security update]]></category>
		<category><![CDATA[time machine]]></category>

		<guid isPermaLink="false">http://hackadaycom.wordpress.com/?p=3211</guid>
		<description><![CDATA[With today&#8217;s release of Security Update 2008-006 Apple has finally addressed this summer&#8217;s DNS bug. In their previous update they fixed BIND, but that only affects people running servers. Now, they&#8217;ve updated mDNSResponder. Clients are no longer susceptible to DNS cache poisoning attacks thanks to the inclusion of source port randomization. The Security Update addresses [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=3211&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img class="alignnone size-full wp-image-3212" title="had_iphone" src="http://hackadaycom.files.wordpress.com/2008/09/had_iphone.jpg" alt="" width="450" height="140" /></p>
<p>With today&#8217;s release of <a href="http://support.apple.com/kb/HT3137">Security Update 2008-006</a> Apple has finally addressed this summer&#8217;s <a href="http://hackaday.com/tag/dns/">DNS bug</a>. In their previous update <a href="http://support.apple.com/kb/HT2647">they fixed BIND</a>, but that only affects people running servers. Now, they&#8217;ve updated mDNSResponder. Clients are no longer susceptible to DNS cache poisoning attacks thanks to the inclusion of source port randomization.</p>
<p>The Security Update addresses some other interesting bugs. Time Machine was saving sensitive logs without using the proper permissions, so any user could view them.</p>
<p>[photo: <a href="http://flickr.com/photos/edans/1526393678/">edans</a>]</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/hackadaycom.wordpress.com/3211/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/hackadaycom.wordpress.com/3211/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackadaycom.wordpress.com/3211/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackadaycom.wordpress.com/3211/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackadaycom.wordpress.com/3211/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackadaycom.wordpress.com/3211/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hackadaycom.wordpress.com/3211/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hackadaycom.wordpress.com/3211/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hackadaycom.wordpress.com/3211/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hackadaycom.wordpress.com/3211/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackadaycom.wordpress.com/3211/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackadaycom.wordpress.com/3211/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackadaycom.wordpress.com/3211/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackadaycom.wordpress.com/3211/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackadaycom.wordpress.com/3211/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackadaycom.wordpress.com/3211/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=3211&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hackaday.com/2008/09/15/apple-finally-fixes-dns-bug/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">RobotSkirts</media:title>
		</media:content>

		<media:content url="http://hackadaycom.files.wordpress.com/2008/09/had_iphone.jpg" medium="image">
			<media:title type="html">had_iphone</media:title>
		</media:content>
	</item>
		<item>
		<title>Black Hat 2008: Dan Kaminsky releases DNS information</title>
		<link>http://hackaday.com/2008/08/06/black-hat-2008-dan-kaminsky-releases-dns-information/</link>
		<comments>http://hackaday.com/2008/08/06/black-hat-2008-dan-kaminsky-releases-dns-information/#comments</comments>
		<pubDate>Thu, 07 Aug 2008 00:00:00 +0000</pubDate>
		<dc:creator>fabienneserriere</dc:creator>
				<category><![CDATA[cons]]></category>
		<category><![CDATA[misc hacks]]></category>
		<category><![CDATA[news]]></category>
		<category><![CDATA[Black Hat]]></category>
		<category><![CDATA[black hat 2008]]></category>
		<category><![CDATA[blackhat]]></category>
		<category><![CDATA[blackhat2008]]></category>
		<category><![CDATA[conference]]></category>
		<category><![CDATA[Dan Kaminsky]]></category>
		<category><![CDATA[dankaminsky]]></category>
		<category><![CDATA[dns]]></category>
		<category><![CDATA[DNS cache poisoning]]></category>
		<category><![CDATA[DnsCachePoisoning]]></category>

		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2008/08/06/black-hat-2008-dan-kaminsky-releases-dns-information/</guid>
		<description><![CDATA[[Dan Kaminsky]&#8216;s much anticipated talk on his DNS findings finally happened at Black Hat 2008 in Las Vegas today. [Dan] has already uploaded the complete slides from his talk as well as posted a short summary to his site. New information in the slides since our previous coverage includes &#8220;Forgot My Password&#8221; attacks and new [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=2404&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img width="450" vspace="4" hspace="4" height="206" border="0" src="http://hackadaycom.files.wordpress.com/2008/08/kaminskyshot.jpg?w=450&#038;h=206" alt="" /><br />[Dan Kaminsky]&#8216;s much anticipated talk on his DNS findings finally happened at <a href="http://mahalo.com/Black_Hat">Black Hat</a> 2008 in Las Vegas today. [Dan] has already uploaded the complete <a href="http://www.doxpara.com/DMK_BO2K8.ppt">slides</a> from his talk as well as posted a short <a href="http://www.doxpara.com/?p=1204">summary</a> to his site. New information in the slides <a href="http://www.hackaday.com/2008/07/31/securing-dns-on-osx/">since</a> <a href="http://www.hackaday.com/2008/07/24/dns-cache-poisoning-webcast/">our</a> <a href="http://www.hackaday.com/2008/07/23/dns-exploit-in-the-wild/">previous</a> <a href="http://www.hackaday.com/2008/07/08/major-dns-issue-causes-multivendor-patch-day/">coverage</a> includes &#8220;Forgot My Password&#8221; attacks and new attacks on internal network vulnerabilities as a side of effect of DNS cache poisoning. [Dan]&#8216;s talk today was over capacity; our shot of the conference room overflow is shown above.</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/hackadaycom.wordpress.com/2404/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/hackadaycom.wordpress.com/2404/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackadaycom.wordpress.com/2404/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackadaycom.wordpress.com/2404/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackadaycom.wordpress.com/2404/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackadaycom.wordpress.com/2404/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hackadaycom.wordpress.com/2404/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hackadaycom.wordpress.com/2404/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hackadaycom.wordpress.com/2404/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hackadaycom.wordpress.com/2404/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackadaycom.wordpress.com/2404/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackadaycom.wordpress.com/2404/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackadaycom.wordpress.com/2404/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackadaycom.wordpress.com/2404/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackadaycom.wordpress.com/2404/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackadaycom.wordpress.com/2404/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=2404&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hackaday.com/2008/08/06/black-hat-2008-dan-kaminsky-releases-dns-information/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">fabienneserriere</media:title>
		</media:content>

		<media:content url="http://hackadaycom.files.wordpress.com/2008/08/kaminskyshot.jpg" medium="image" />
	</item>
	</channel>
</rss>
