<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Hack a Day &#187; whitepaper</title>
	<atom:link href="http://hackaday.com/tag/whitepaper/feed/" rel="self" type="application/rss+xml" />
	<link>http://hackaday.com</link>
	<description>Fresh hacks every day</description>
	<lastBuildDate>Fri, 10 Feb 2012 11:18:55 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='hackaday.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://1.gravatar.com/blavatar/5560f98f805877b0e332f191cb9e0af3?s=96&#038;d=http%3A%2F%2Fs2.wp.com%2Fi%2Fbuttonw-com.png</url>
		<title>Hack a Day &#187; whitepaper</title>
		<link>http://hackaday.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://hackaday.com/osd.xml" title="Hack a Day" />
	<atom:link rel='hub' href='http://hackaday.com/?pushpress=hub'/>
		<item>
		<title>Containing Conficker</title>
		<link>http://hackaday.com/2009/03/30/containing-conficker/</link>
		<comments>http://hackaday.com/2009/03/30/containing-conficker/#comments</comments>
		<pubDate>Tue, 31 Mar 2009 00:22:01 +0000</pubDate>
		<dc:creator>Eliot</dc:creator>
				<category><![CDATA[downloads hacks]]></category>
		<category><![CDATA[security hacks]]></category>
		<category><![CDATA[conficker]]></category>
		<category><![CDATA[Dan Kaminsky]]></category>
		<category><![CDATA[honeynet project]]></category>
		<category><![CDATA[network scanner]]></category>
		<category><![CDATA[nmap]]></category>
		<category><![CDATA[patch]]></category>
		<category><![CDATA[rich mogull]]></category>
		<category><![CDATA[scan]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[svn]]></category>
		<category><![CDATA[whitepaper]]></category>
		<category><![CDATA[windows]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://hackaday.com/?p=9999</guid>
		<description><![CDATA[With all the noise about Conficker turning your computer into liquid hot magma on April 1st, there&#8217;s actually some positive news. Researchers from the HoneyNet Project have been following the worm since infections started in late 2008. They recently discovered an easy way to identify infected systems remotely. Conficker attempts to patch the MS08-067 vulnerability [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=9999&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img class="alignnone size-full wp-image-10000" title="conficker" src="http://hackadaycom.files.wordpress.com/2009/03/conficker.jpg" alt="conficker" width="450" height="220" /></p>
<p>With <a title="The Internet Is Infected - CBS News Video" href="http://www.cbsnews.com/video/watch/?id=4901282n">all the noise</a> about <a title="Conficker - Wikipedia, the free encyclopedia" href="http://en.wikipedia.org/wiki/Conficker">Conficker</a> turning your computer into liquid hot magma on April 1st, there&#8217;s actually some positive news. Researchers from the <a title="Honeynet Project Blog | The Honeynet Project" href="http://www.honeynet.org/">HoneyNet Project</a> have been following the worm since infections started in late 2008. They recently discovered an easy way to identify infected systems remotely. Conficker attempts to patch the MS08-067 vulnerability during infection. A flaw in the patch causes the machine to respond differently than both an unpatched system and an officially patched system. Using this knowledge, the team developed a proof of concept network scanner in python to find infected machines. You can find it in <a title="(Updated) Easily Detect Conficker Infections- Over the Network | securosis.com" href="http://securosis.com/2009/03/30/easily-detect-conficker-infections-over-the-network/">[Rich Mogull]&#8216;s initial post</a>. [Dan Kaminisky] has <a title="Tools, Tools, Tools : DoxPara Research" href="http://www.doxpara.com/?p=1291">packaged it as an EXE</a> and has instructions for how to build the SVN version of <a title="Nmap - Free Security Scanner For Network Exploration &amp; Security Audits." href="http://nmap.org/">Nmap</a>, which includes the new signature. Other network scanner vendors are adding the code as well.</p>
<p>In conjunction with this detection code, the team has also released the whitepaper <a title="Know Your Enemy: Containing Conficker | The Honeynet Project" href="http://www.honeynet.org/papers/conficker">Know Your Enemy: Containing Conficker</a>. It discusses ways to detect, contain, and remove Conficker. They&#8217;ve combined this with a <a title="Informatik IV: Containing Conficker" href="http://iv.cs.uni-bonn.de/wg/cs/applications/containing-conficker/">tool release</a> that covers Conficker&#8217;s dynamic domain generation among other things.</p>
<br />Posted in downloads hacks, security hacks  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackadaycom.wordpress.com/9999/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackadaycom.wordpress.com/9999/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackadaycom.wordpress.com/9999/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackadaycom.wordpress.com/9999/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hackadaycom.wordpress.com/9999/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hackadaycom.wordpress.com/9999/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hackadaycom.wordpress.com/9999/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hackadaycom.wordpress.com/9999/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackadaycom.wordpress.com/9999/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackadaycom.wordpress.com/9999/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackadaycom.wordpress.com/9999/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackadaycom.wordpress.com/9999/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackadaycom.wordpress.com/9999/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackadaycom.wordpress.com/9999/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=9999&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hackaday.com/2009/03/30/containing-conficker/feed/</wfw:commentRss>
		<slash:comments>49</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">RobotSkirts</media:title>
		</media:content>

		<media:content url="http://hackadaycom.files.wordpress.com/2009/03/conficker.jpg" medium="image">
			<media:title type="html">conficker</media:title>
		</media:content>
	</item>
		<item>
		<title>Dan Kaminsky&#8217;s DNS Black Hat video</title>
		<link>http://hackaday.com/2008/08/25/dan-kaminskys-dns-black-hat-video/</link>
		<comments>http://hackaday.com/2008/08/25/dan-kaminskys-dns-black-hat-video/#comments</comments>
		<pubDate>Mon, 25 Aug 2008 22:30:00 +0000</pubDate>
		<dc:creator>Eliot</dc:creator>
				<category><![CDATA[downloads hacks]]></category>
		<category><![CDATA[security hacks]]></category>
		<category><![CDATA[blackhat]]></category>
		<category><![CDATA[blackhat2008]]></category>
		<category><![CDATA[dankaminsky]]></category>
		<category><![CDATA[dns]]></category>
		<category><![CDATA[slides]]></category>
		<category><![CDATA[video]]></category>
		<category><![CDATA[whitepaper]]></category>

		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2008/08/25/dan-kaminskys-dns-black-hat-video/</guid>
		<description><![CDATA[Black Hat has published the media from Dan Kaminsky&#8217;s infamous DNS vulnerability talk. You can get the full video (101MB) or just the audio. The full archive of slides and white papers from this year has been posted too.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=2503&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img width="450" vspace="4" hspace="4" height="159" border="0" src="http://hackadaycom.files.wordpress.com/2008/08/had-fuzzing-v-statcodeanalysis.jpg?w=450&#038;h=159" alt="" /><br /><a href="http://www.mahalo.com/Black_Hat">Black Hat</a> has published the media from Dan Kaminsky&#8217;s <a href="http://www.hackaday.com/2008/08/06/black-hat-2008-dan-kaminsky-releases-dns-information/">infamous</a> DNS vulnerability talk. You can get the <a href="http://www.blackhat.com/presentations/bh-usa-08/Kaminsky/08_bhb_od2_slides.m4v">full video </a>(101MB) or just the <a href="http://www.blackhat.com/presentations/bh-usa-08/Kaminsky/08_bhb_od2.mp3">audio</a>.</p>
<p>The <a href="https://www.blackhat.com/html/bh-usa-08/bh-usa-08-archive.html">full archive of slides and white papers</a> from this year has been posted too.</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/hackadaycom.wordpress.com/2503/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/hackadaycom.wordpress.com/2503/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackadaycom.wordpress.com/2503/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackadaycom.wordpress.com/2503/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackadaycom.wordpress.com/2503/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackadaycom.wordpress.com/2503/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hackadaycom.wordpress.com/2503/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hackadaycom.wordpress.com/2503/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hackadaycom.wordpress.com/2503/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hackadaycom.wordpress.com/2503/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackadaycom.wordpress.com/2503/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackadaycom.wordpress.com/2503/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackadaycom.wordpress.com/2503/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackadaycom.wordpress.com/2503/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackadaycom.wordpress.com/2503/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackadaycom.wordpress.com/2503/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=2503&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hackaday.com/2008/08/25/dan-kaminskys-dns-black-hat-video/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">RobotSkirts</media:title>
		</media:content>

		<media:content url="http://hackadaycom.files.wordpress.com/2008/08/had-fuzzing-v-statcodeanalysis.jpg" medium="image" />
	</item>
	</channel>
</rss>
