<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Hack a Day &#187; zero-day</title>
	<atom:link href="http://hackaday.com/tag/zero-day/feed/" rel="self" type="application/rss+xml" />
	<link>http://hackaday.com</link>
	<description>Fresh hacks every day</description>
	<lastBuildDate>Fri, 10 Feb 2012 11:18:55 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='hackaday.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://1.gravatar.com/blavatar/5560f98f805877b0e332f191cb9e0af3?s=96&#038;d=http%3A%2F%2Fs2.wp.com%2Fi%2Fbuttonw-com.png</url>
		<title>Hack a Day &#187; zero-day</title>
		<link>http://hackaday.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://hackaday.com/osd.xml" title="Hack a Day" />
	<atom:link rel='hub' href='http://hackaday.com/?pushpress=hub'/>
		<item>
		<title>Dismantling the Storm Worm botnet</title>
		<link>http://hackaday.com/2009/01/16/dismantling-the-storm-worm-botnet/</link>
		<comments>http://hackaday.com/2009/01/16/dismantling-the-storm-worm-botnet/#comments</comments>
		<pubDate>Sat, 17 Jan 2009 04:30:16 +0000</pubDate>
		<dc:creator>Eliot</dc:creator>
				<category><![CDATA[news]]></category>
		<category><![CDATA[security hacks]]></category>
		<category><![CDATA[25c3]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[ccc]]></category>
		<category><![CDATA[german]]></category>
		<category><![CDATA[isp]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[nat]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[storm worm]]></category>
		<category><![CDATA[stormfucker]]></category>
		<category><![CDATA[xor]]></category>
		<category><![CDATA[zero-day]]></category>

		<guid isPermaLink="false">http://hackaday.com/?p=7931</guid>
		<description><![CDATA[Zero Day has an interview with German researchers who have found a way to take down the Storm Worm botnet. Their program, Stormfucker, takes advantage of flaws in Storm&#8217;s command network: Nodes that are NAT&#8216;d only use a four-byte XOR challenge. Nodes that aren&#8217;t NAT&#8217;d are only using a trivial 64bit RSA signature. Their solution [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=7931&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img class="alignnone size-full wp-image-7486" title="malware" src="http://hackadaycom.files.wordpress.com/2009/01/malware.jpg" alt="malware" width="450" height="132" /></p>
<p>Zero Day has an interview with German researchers who have found a way to <a title="Zero Day mobile edition" href="http://blogs.zdnet.com/security/?p=2396">take down the Storm Worm botnet</a>. Their program, <a title="Owning the Storm Botnet" href="http://events.ccc.de/congress/2008/Fahrplan/events/3000.en.html">Stormfucker</a>, takes advantage of flaws in Storm&#8217;s command network: Nodes that are <a href="http://en.wikipedia.org/wiki/Network_address_translation">NAT</a>&#8216;d only use a four-byte <a href="http://en.wikipedia.org/wiki/XOR_gate">XOR</a> challenge. Nodes that aren&#8217;t NAT&#8217;d are only using a trivial 64bit RSA signature. Their solution can clean infected machines and also distribute to other nodes. Unfortunately, installing software without the user&#8217;s consent is the exact same behavior as malware. Don&#8217;t expect to see this in any sort of widespread use. The researchers did point out that some ISPs have moved to shutting off service for infected customers until their machines are cleaned.</p>
<br />Posted in news, security hacks  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackadaycom.wordpress.com/7931/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackadaycom.wordpress.com/7931/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackadaycom.wordpress.com/7931/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackadaycom.wordpress.com/7931/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hackadaycom.wordpress.com/7931/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hackadaycom.wordpress.com/7931/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hackadaycom.wordpress.com/7931/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hackadaycom.wordpress.com/7931/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackadaycom.wordpress.com/7931/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackadaycom.wordpress.com/7931/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackadaycom.wordpress.com/7931/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackadaycom.wordpress.com/7931/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackadaycom.wordpress.com/7931/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackadaycom.wordpress.com/7931/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=7931&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hackaday.com/2009/01/16/dismantling-the-storm-worm-botnet/feed/</wfw:commentRss>
		<slash:comments>23</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">RobotSkirts</media:title>
		</media:content>

		<media:content url="http://hackadaycom.files.wordpress.com/2009/01/malware.jpg" medium="image">
			<media:title type="html">malware</media:title>
		</media:content>
	</item>
		<item>
		<title>IBM sees influx in zero-day exploits</title>
		<link>http://hackaday.com/2008/08/26/ibm-sees-influx-in-zero-day-exploits/</link>
		<comments>http://hackaday.com/2008/08/26/ibm-sees-influx-in-zero-day-exploits/#comments</comments>
		<pubDate>Tue, 26 Aug 2008 23:56:00 +0000</pubDate>
		<dc:creator>Benjamin Eckel</dc:creator>
				<category><![CDATA[firefox hacks]]></category>
		<category><![CDATA[news]]></category>
		<category><![CDATA[security hacks]]></category>
		<category><![CDATA[browser]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[ibm]]></category>
		<category><![CDATA[plugin]]></category>
		<category><![CDATA[x force]]></category>
		<category><![CDATA[XForce]]></category>
		<category><![CDATA[zero-day]]></category>

		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2008/08/26/ibm-sees-influx-in-zero-day-exploits/</guid>
		<description><![CDATA[IBM&#8217;s X-Force security team has released a mid-year report(PDF) stating that the number of zero-day exploits is growing at an alarming rate. For those of you unfamiliar with the term, a zero-day exploit is a program that is created and implemented within 24 hours of the disclosure of a security flaw. These exploits usually affect [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=2511&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img width="450" vspace="4" hspace="4" height="60" border="0" alt="" src="http://hackadaycom.files.wordpress.com/2008/08/had_ff3dd.jpg?w=450&#038;h=60" /><br />IBM&#8217;s X-Force security team has released a <a href="http://www-935.ibm.com/services/us/iss/xforce/midyearreport/xforce-midyear-report-2008.pdf">mid-year report</a>(PDF) stating that <a href="http://technology.inquirer.net/infotech/infotech/view/20080826-156948/IBM-warns-zero-day-hacker-exploits-growing">the number of zero-day exploits is growing at an alarming rate</a>. For those of you unfamiliar with the term, a zero-day exploit is a program that is <a href="http://en.wikipedia.org/wiki/Zero_day_attack">created and implemented within 24 hours of the disclosure of a security flaw</a>. These exploits usually affect users before they even know the vulnerability exists and long before a patch is made available. The researchers also found that many of these exploits were targeted at browser plug-ins, which most users utilize on a daily basis.</p>
<p>[Kris Lamb], X-Force operations manager, is blaming the problem on a lack of a unified process for disclosing vulnerabilities. He also claims that the long-held practice of publishing example code of vulnerabilities should be frowned upon. </p>
<p>[via <a href="http://www.liquidmatrix.org/blog/2008/08/26/ibm-warns-%E2%80%98zero-day%E2%80%99-hacker-exploits-growing/">Liquidmatrix</a>]</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/hackadaycom.wordpress.com/2511/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/hackadaycom.wordpress.com/2511/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackadaycom.wordpress.com/2511/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackadaycom.wordpress.com/2511/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackadaycom.wordpress.com/2511/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackadaycom.wordpress.com/2511/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hackadaycom.wordpress.com/2511/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hackadaycom.wordpress.com/2511/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hackadaycom.wordpress.com/2511/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hackadaycom.wordpress.com/2511/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackadaycom.wordpress.com/2511/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackadaycom.wordpress.com/2511/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackadaycom.wordpress.com/2511/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackadaycom.wordpress.com/2511/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackadaycom.wordpress.com/2511/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackadaycom.wordpress.com/2511/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=2511&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hackaday.com/2008/08/26/ibm-sees-influx-in-zero-day-exploits/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">ben</media:title>
		</media:content>

		<media:content url="http://hackadaycom.files.wordpress.com/2008/08/had_ff3dd.jpg" medium="image" />
	</item>
	</channel>
</rss>
