<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Hack a Day &#187; worm</title>
	<atom:link href="http://hackaday.com/tag/worm/feed/" rel="self" type="application/rss+xml" />
	<link>http://hackaday.com</link>
	<description>Fresh hacks every day</description>
	<lastBuildDate>Fri, 10 Feb 2012 10:01:11 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='hackaday.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://1.gravatar.com/blavatar/5560f98f805877b0e332f191cb9e0af3?s=96&#038;d=http%3A%2F%2Fs2.wp.com%2Fi%2Fbuttonw-com.png</url>
		<title>Hack a Day &#187; worm</title>
		<link>http://hackaday.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://hackaday.com/osd.xml" title="Hack a Day" />
	<atom:link rel='hub' href='http://hackaday.com/?pushpress=hub'/>
		<item>
		<title>Careless with your Jailbreak? You&#8217;ll get Rickrolled</title>
		<link>http://hackaday.com/2009/11/09/careless-with-your-jailbreak-youll-get-rickrolled/</link>
		<comments>http://hackaday.com/2009/11/09/careless-with-your-jailbreak-youll-get-rickrolled/#comments</comments>
		<pubDate>Mon, 09 Nov 2009 18:18:14 +0000</pubDate>
		<dc:creator>Mike Szczys</dc:creator>
				<category><![CDATA[iphone hacks]]></category>
		<category><![CDATA[iKee]]></category>
		<category><![CDATA[iphone]]></category>
		<category><![CDATA[jailbreak]]></category>
		<category><![CDATA[Rick Astley]]></category>
		<category><![CDATA[Rick Rolled]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://hackaday.com/?p=18246</guid>
		<description><![CDATA[Here&#8217;s further proof that you should understand what it is you&#8217;re doing when you go to hack your handheld. Jailbreaking an iPhone has been made quite easy to the point that a lot of folks do it without reading any of the accompanying documentation. Those who didn&#8217;t heed the warning to change the default SSH [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=18246&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img class="alignnone size-full wp-image-18247" title="iKee-Rickrolling-iPhone-Worm" src="http://hackadaycom.files.wordpress.com/2009/11/ikee-rickrolling-iphone-worm.jpg" alt="iKee-Rickrolling-iPhone-Worm" width="470" height="343" /></p>
<p>Here&#8217;s further proof that you should understand what it is you&#8217;re doing when you go to hack your handheld. Jailbreaking an iPhone has been made quite easy to the point that a lot of folks do it without reading any of the accompanying documentation. Those who didn&#8217;t heed the warning to change the default SSH password on a Jailbroken phone might get a bit of a surprise. A <a href="http://www.geeky-gadgets.com/ikee-rickrolling-iphone-worm-09-11-2009/">worm has been unleashed that finds Jailbroken iPhones</a> and changes the background image to a picture of [Rick Astley]. That&#8217;s right, they&#8217;ve been <a href="http://www.youtube.com/watch?v=oHg5SJYRHA0">Rickrolled</a>.</p>
<p>It&#8217;s a clever little devil that propagates by grabbing the IP address of the iPhone it is currently on, then testing all of the IP address in that family to find other devices using the default password. Luckily this worm&#8217;s activities are not what we&#8217;d call malicious. It doesn&#8217;t format the root or create a cell based bot-net (that we know of). This would be akin to the antics of <a href="http://www.google.com/webhp?hl=en#hl=en&amp;source=hp&amp;q=%22Welcome+to+MythWeb!%22&amp;btnG=Google+Search&amp;aq=f&amp;aqi=&amp;oq=%22Welcome+to+MythWeb!%22&amp;fp=aa7ac5834e645580">searching Google for unprotected installations of MythWeb</a> and setting some poor schmuck&#8217;s MythTV to record every infomercial ever. The point is, this could have been a lot worse, but the attack is predicated on stupidity. In our digital age, why are people leaving default passwords in place?</p>
<br />Posted in iphone hacks  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackadaycom.wordpress.com/18246/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackadaycom.wordpress.com/18246/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackadaycom.wordpress.com/18246/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackadaycom.wordpress.com/18246/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hackadaycom.wordpress.com/18246/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hackadaycom.wordpress.com/18246/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hackadaycom.wordpress.com/18246/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hackadaycom.wordpress.com/18246/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackadaycom.wordpress.com/18246/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackadaycom.wordpress.com/18246/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackadaycom.wordpress.com/18246/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackadaycom.wordpress.com/18246/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackadaycom.wordpress.com/18246/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackadaycom.wordpress.com/18246/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=18246&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hackaday.com/2009/11/09/careless-with-your-jailbreak-youll-get-rickrolled/feed/</wfw:commentRss>
		<slash:comments>30</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Mike Szczys</media:title>
		</media:content>

		<media:content url="http://hackadaycom.files.wordpress.com/2009/11/ikee-rickrolling-iphone-worm.jpg" medium="image">
			<media:title type="html">iKee-Rickrolling-iPhone-Worm</media:title>
		</media:content>
	</item>
		<item>
		<title>Containing Conficker</title>
		<link>http://hackaday.com/2009/03/30/containing-conficker/</link>
		<comments>http://hackaday.com/2009/03/30/containing-conficker/#comments</comments>
		<pubDate>Tue, 31 Mar 2009 00:22:01 +0000</pubDate>
		<dc:creator>Eliot</dc:creator>
				<category><![CDATA[downloads hacks]]></category>
		<category><![CDATA[security hacks]]></category>
		<category><![CDATA[conficker]]></category>
		<category><![CDATA[Dan Kaminsky]]></category>
		<category><![CDATA[honeynet project]]></category>
		<category><![CDATA[network scanner]]></category>
		<category><![CDATA[nmap]]></category>
		<category><![CDATA[patch]]></category>
		<category><![CDATA[rich mogull]]></category>
		<category><![CDATA[scan]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[svn]]></category>
		<category><![CDATA[whitepaper]]></category>
		<category><![CDATA[windows]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://hackaday.com/?p=9999</guid>
		<description><![CDATA[With all the noise about Conficker turning your computer into liquid hot magma on April 1st, there&#8217;s actually some positive news. Researchers from the HoneyNet Project have been following the worm since infections started in late 2008. They recently discovered an easy way to identify infected systems remotely. Conficker attempts to patch the MS08-067 vulnerability [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=9999&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img class="alignnone size-full wp-image-10000" title="conficker" src="http://hackadaycom.files.wordpress.com/2009/03/conficker.jpg" alt="conficker" width="450" height="220" /></p>
<p>With <a title="The Internet Is Infected - CBS News Video" href="http://www.cbsnews.com/video/watch/?id=4901282n">all the noise</a> about <a title="Conficker - Wikipedia, the free encyclopedia" href="http://en.wikipedia.org/wiki/Conficker">Conficker</a> turning your computer into liquid hot magma on April 1st, there&#8217;s actually some positive news. Researchers from the <a title="Honeynet Project Blog | The Honeynet Project" href="http://www.honeynet.org/">HoneyNet Project</a> have been following the worm since infections started in late 2008. They recently discovered an easy way to identify infected systems remotely. Conficker attempts to patch the MS08-067 vulnerability during infection. A flaw in the patch causes the machine to respond differently than both an unpatched system and an officially patched system. Using this knowledge, the team developed a proof of concept network scanner in python to find infected machines. You can find it in <a title="(Updated) Easily Detect Conficker Infections- Over the Network | securosis.com" href="http://securosis.com/2009/03/30/easily-detect-conficker-infections-over-the-network/">[Rich Mogull]&#8216;s initial post</a>. [Dan Kaminisky] has <a title="Tools, Tools, Tools : DoxPara Research" href="http://www.doxpara.com/?p=1291">packaged it as an EXE</a> and has instructions for how to build the SVN version of <a title="Nmap - Free Security Scanner For Network Exploration &amp; Security Audits." href="http://nmap.org/">Nmap</a>, which includes the new signature. Other network scanner vendors are adding the code as well.</p>
<p>In conjunction with this detection code, the team has also released the whitepaper <a title="Know Your Enemy: Containing Conficker | The Honeynet Project" href="http://www.honeynet.org/papers/conficker">Know Your Enemy: Containing Conficker</a>. It discusses ways to detect, contain, and remove Conficker. They&#8217;ve combined this with a <a title="Informatik IV: Containing Conficker" href="http://iv.cs.uni-bonn.de/wg/cs/applications/containing-conficker/">tool release</a> that covers Conficker&#8217;s dynamic domain generation among other things.</p>
<br />Posted in downloads hacks, security hacks  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackadaycom.wordpress.com/9999/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackadaycom.wordpress.com/9999/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackadaycom.wordpress.com/9999/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackadaycom.wordpress.com/9999/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hackadaycom.wordpress.com/9999/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hackadaycom.wordpress.com/9999/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hackadaycom.wordpress.com/9999/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hackadaycom.wordpress.com/9999/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackadaycom.wordpress.com/9999/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackadaycom.wordpress.com/9999/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackadaycom.wordpress.com/9999/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackadaycom.wordpress.com/9999/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackadaycom.wordpress.com/9999/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackadaycom.wordpress.com/9999/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=9999&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hackaday.com/2009/03/30/containing-conficker/feed/</wfw:commentRss>
		<slash:comments>49</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">RobotSkirts</media:title>
		</media:content>

		<media:content url="http://hackadaycom.files.wordpress.com/2009/03/conficker.jpg" medium="image">
			<media:title type="html">conficker</media:title>
		</media:content>
	</item>
		<item>
		<title>Botnet attack via P2P software</title>
		<link>http://hackaday.com/2008/06/29/botnet-attack-via-p2p-software/</link>
		<comments>http://hackaday.com/2008/06/29/botnet-attack-via-p2p-software/#comments</comments>
		<pubDate>Sun, 29 Jun 2008 07:30:00 +0000</pubDate>
		<dc:creator>Juan Aguilar</dc:creator>
				<category><![CDATA[news]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[botnets]]></category>
		<category><![CDATA[crime]]></category>
		<category><![CDATA[filsharing]]></category>
		<category><![CDATA[law]]></category>
		<category><![CDATA[limewire]]></category>
		<category><![CDATA[p2p]]></category>
		<category><![CDATA[p2pnetworks]]></category>
		<category><![CDATA[peer2peer]]></category>
		<category><![CDATA[prosectution]]></category>
		<category><![CDATA[worm]]></category>
		<category><![CDATA[worms]]></category>

		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2008/06/29/botnet-attack-via-p2p-software/</guid>
		<description><![CDATA[P2P networks have long been a legal gray area, used for various spam schemes, illegal filesharing, and lots and lots of adware. Last year, though, the first botnet created by a worm distributed via P2P software surfaced, the work of 19-year-old [Jason Michael Milmont] of Cheyenne, Wyoming, who distributed his Nugache Worm by offering free [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=2144&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img width="450" vspace="4" hspace="4" height="250" border="0" alt="" src="http://hackadaycom.files.wordpress.com/2008/06/had-p2p-botnet-1.jpg?w=450&#038;h=250" /><br />P2P networks have long been a legal gray area, used for various spam schemes, illegal filesharing, and lots and lots of adware. Last year, though, <a href="http://blog.wired.com/27bstroke6/2008/06/hacker-launches.html">the first botnet created by a worm distributed via P2P software</a> surfaced, the work of 19-year-old [Jason Michael Milmont] of Cheyenne, Wyoming, who distributed his Nugache Worm by offering free downloads of the P2P app Limewire with the worm embedded. He later began distributing it using bogus MySpace and Photobucket links shared via chats on AOL Instant Messenger. The strategy proved effective, as the botnet peaked with around 15,000 bots. [Milmont] has plead guilty to the charges against him. Per his plea agreement, he will pay $73,000 in restitution and may serve up to five years in prison.</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/hackadaycom.wordpress.com/2144/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/hackadaycom.wordpress.com/2144/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackadaycom.wordpress.com/2144/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackadaycom.wordpress.com/2144/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackadaycom.wordpress.com/2144/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackadaycom.wordpress.com/2144/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hackadaycom.wordpress.com/2144/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hackadaycom.wordpress.com/2144/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hackadaycom.wordpress.com/2144/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hackadaycom.wordpress.com/2144/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackadaycom.wordpress.com/2144/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackadaycom.wordpress.com/2144/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackadaycom.wordpress.com/2144/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackadaycom.wordpress.com/2144/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackadaycom.wordpress.com/2144/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackadaycom.wordpress.com/2144/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=2144&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hackaday.com/2008/06/29/botnet-attack-via-p2p-software/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">juanaguilar</media:title>
		</media:content>

		<media:content url="http://hackadaycom.files.wordpress.com/2008/06/had-p2p-botnet-1.jpg" medium="image" />
	</item>
	</channel>
</rss>
