<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Norwegian Honeynet Project &#187; Tools</title>
	<atom:link href="http://www.honeynor.no/category/tools/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.honeynor.no</link>
	<description>A chapter of the Honeynet Project</description>
	<lastBuildDate>Mon, 06 Sep 2010 12:05:49 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Enhanced CC2ASN</title>
		<link>http://www.honeynor.no/2010/03/23/enhanced-cc2asn/</link>
		<comments>http://www.honeynor.no/2010/03/23/enhanced-cc2asn/#comments</comments>
		<pubDate>Tue, 23 Mar 2010 21:46:49 +0000</pubDate>
		<dc:creator>Tor Inge Skaar</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[ASN]]></category>
		<category><![CDATA[CC2ASN]]></category>
		<category><![CDATA[country]]></category>
		<category><![CDATA[delta]]></category>
		<category><![CDATA[enhanced]]></category>
		<category><![CDATA[ISO-3166]]></category>
		<category><![CDATA[lookup]]></category>
		<category><![CDATA[netcat]]></category>
		<category><![CDATA[whois]]></category>

		<guid isPermaLink="false">http://www.honeynor.no/?p=404</guid>
		<description><![CDATA[For over 9 months we&#8217;ve run our CC2ASN service, allowing you to lookup up ISO-3166 country codes and get back all ASNs, IPv4 or IPv6 prefixes for that specific country. Now the time had come to do an update. A major issue with the RIR data (delegated-feeds) used by the CC2ASN service, is ASNs registered [...]]]></description>
			<content:encoded><![CDATA[<p>For over <a href="http://www.honeynor.no/2009/06/19/country-lookup/">9 months</a> we&#8217;ve run our <a href="http://www.honeynor.no/tools/cc2asn/">CC2ASN service</a>, allowing you to lookup up ISO-3166 country codes and get back all ASNs, IPv4 or IPv6 prefixes for that specific country. Now the time had come to do an update.</p>
<p>A major issue with the <a href="http://en.wikipedia.org/wiki/Regional_Internet_Registry">RIR</a> data (delegated-feeds) used by the CC2ASN service, is ASNs registered to a region instead of a specific country. There are currently two regions in use; European Union (EU) and Asia Pacific (AP). The reason for using this is the ever increasing globalization of corporations and organizations, and hence quite understandable. But when you want a list of AS numbers for any given country code, the regional registrations have to be included.</p>
<p>This is where the <strong>enhanced database</strong> comes into action. In this database we&#8217;ve manually overridden the country code assignments for those ASNs that in the RIR data were registered to either EU or AP. In addition we&#8217;ve also corrected a few other ASNs that we knew had a wrong country code. The list we&#8217;ve compiled is publicly available: <a href="http://www.honeynor.no/tools/cc2asn/asn_override.txt">asn_override.txt</a>.</p>
<p>It&#8217;s all been a manual job, going through all the EU and AP ASNs, plus a good portion of the CCs also. The CC override decision is based on one or more of the following actions:</p>
<ul>
<li>Looking at references to location in whois descr, address or country records.</li>
<li>Using location info in router names from tracepath of the AS prefixes.</li>
<li>The nationality of peers and upstream providers.</li>
<li>Location of corporate headquarters or regional headquarters.</li>
<li>General googling/binging.</li>
</ul>
<p>And this is a continuing job, whenever new ASNs are allocated to either EU or AP.</p>
<p>So, how do you access this new database? From the CC2ASN <a href="http://www.honeynor.no/tools/cc2asn/">web-interface</a> make sure you check the box labeled &#8220;<em>Use Enhanced Database</em>&#8220;. The database is also available by directly querying port 44/tcp (the normal CC2ASN database is available on standard whois port 43/tcp). Note that the enhanced database only outputs ASNs, not prefixes.</p>
<p><code style="font-size: 1.4em;">$ echo "GB" | nc atari.honeynor.no <strong>44</strong><br />
</code></p>
<p>Every day, when the latest RIR data are downloaded and parsed, all changes to the enhanced database are recorded. This allows us to provide you with an <strong>ASN history tool</strong>; <a href="http://www.honeynor.no/tools/cc2asn/delta/">CC2ASN Delta</a>. The main page lists changes over the last 90 days for ASNs registered to a spesific country. By clicking on a county, you get a textual representation of all registered changes for that country. By further clicking on an ASN, you get a listing of potential country changes for that AS.</p>
<p><a href="http://www.honeynor.no/tools/cc2asn/delta/"><img class="alignnone size-full wp-image-405" title="cc2asn.delta" src="http://www.honeynor.no/wp-content/uploads/2010/03/cc2asn.delta_.png" alt="" width="380" height="339" /></a></p>
<p>For more information, take a look at the <a href="http://www.honeynor.no/tools/cc2asn/about.php">documentation</a>.</p>
<div id="flaresmith" class="feedflare"><script src="http://feeds.feedburner.com/~s/honeynor?i=http://www.honeynor.no/2010/03/23/enhanced-cc2asn/" type="text/javascript" charset="utf-8"></script></div>]]></content:encoded>
			<wfw:commentRss>http://www.honeynor.no/2010/03/23/enhanced-cc2asn/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Country Lookup</title>
		<link>http://www.honeynor.no/2009/06/19/country-lookup/</link>
		<comments>http://www.honeynor.no/2009/06/19/country-lookup/#comments</comments>
		<pubDate>Fri, 19 Jun 2009 00:44:21 +0000</pubDate>
		<dc:creator>Tor Inge Skaar</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[ASN]]></category>
		<category><![CDATA[CC2ASN]]></category>
		<category><![CDATA[country]]></category>
		<category><![CDATA[IPv4]]></category>
		<category><![CDATA[IPv6]]></category>
		<category><![CDATA[ISO-3166]]></category>
		<category><![CDATA[lookup]]></category>
		<category><![CDATA[netcat]]></category>
		<category><![CDATA[whois]]></category>

		<guid isPermaLink="false">http://www.honeynor.no/?p=165</guid>
		<description><![CDATA[We&#8217;re pleased to announce a new service; CC2ASN &#8211; Country Lookup. This service will provide you with AS-numbers, IPv4 and IPv6 prefixes belonging to a specific country. The data is all based on publicly available information from the five RIRs in the world; ARIN, RIPE NCC, APNIC, LACNIC and AfriNIC. The database is updated once [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-full wp-image-174" title="flags.globe" src="http://www.honeynor.no/wp-content/uploads/2009/06/flags.globe.png" alt="flags.globe" width="150" height="117" align="right" />We&#8217;re pleased to announce a new service; <strong>CC2ASN &#8211; Country Lookup</strong>. This service will provide you with AS-numbers, IPv4 and IPv6 prefixes belonging to a specific country. The data is all based on publicly available information from the five <a href="http://en.wikipedia.org/wiki/Regional_Internet_Registry">RIRs</a> in the world; ARIN, RIPE NCC, APNIC, LACNIC and AfriNIC. The database is updated once every day.</p>
<p>As input to this service, use ISO-3166-1 alpha-2 country codes (<a href="http://www.iso.org/iso/country_codes/iso_3166_code_lists/english_country_names_and_code_elements.htm">more info</a>). Note that in addition to the ISO defined codes, the following two codes are also used when dealing with multi-regional networks; <em>AP</em> (asia-pacific) and <em>EU</em> (european union).</p>
<p>You may access the data either through the <a href="http://www.honeynor.no/tools/cc2asn/">web-interface</a>, or via your command line interface. A standard whois client can be used when the result set is &#8220;not too large&#8221;. The preferred way is to use a raw socket tool, like <a href="http://en.wikipedia.org/wiki/Netcat">netcat</a>. Here are some examples illustrating both ways:</p>
<p><code style="font-size:1.4em;">whois -h atari.honeynor.no no<br />
whois -h atari.honeynor.no ipv4 ke<br />
echo "all us" | nc atari.honeynor.no 43</code></p>
<p>The first will list all AS-numbers registered for Norway, while the second example will list all IPv4 prefixes for Kenya. The last line uses netcat to fetch everything (ASN, IPv4 and IPv6) registered for USA (this query will fail when using a standard whois client).</p>
<p>For more information, please read the <a href="http://www.honeynor.no/tools/cc2asn/about.php">documentation</a> (There are some caveats to be aware of, and more alternatives to download this data. It&#8217;s all in the docs).</p>
<div id="flaresmith" class="feedflare"><script src="http://feeds.feedburner.com/~s/honeynor?i=http://www.honeynor.no/2009/06/19/country-lookup/" type="text/javascript" charset="utf-8"></script></div>]]></content:encoded>
			<wfw:commentRss>http://www.honeynor.no/2009/06/19/country-lookup/feed/</wfw:commentRss>
		<slash:comments>9</slash:comments>
		</item>
		<item>
		<title>Using Nmap to scan for Conficker</title>
		<link>http://www.honeynor.no/2009/03/31/using-nmap-to-scan-for-conficker/</link>
		<comments>http://www.honeynor.no/2009/03/31/using-nmap-to-scan-for-conficker/#comments</comments>
		<pubDate>Tue, 31 Mar 2009 20:24:05 +0000</pubDate>
		<dc:creator>Tor Inge Skaar</dc:creator>
				<category><![CDATA[Tips & Tricks]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[Conficker]]></category>
		<category><![CDATA[Nmap]]></category>

		<guid isPermaLink="false">http://www.honeynor.no/?p=136</guid>
		<description><![CDATA[As a result of the latest KYE paper (Containing Conficker), many of the scanner tools out there have implemented (or are in the process of doing so) the method presented in chapter 5 of the paper, which explains basically how you may remotely scan a machine, and have the machine tell you whether or not [...]]]></description>
			<content:encoded><![CDATA[<p>As a result of the latest <a href="https://www.honeynet.org/papers/conficker/">KYE paper (Containing Conficker)</a>, many of the scanner tools out there have implemented (or are in the process of doing so) the method presented in chapter 5 of the paper, which explains basically how you may remotely scan a machine, and have the machine tell you whether or not Conficker has compromised the system. The method works for all current Conficker variants and is indiscriminate of the infection vector!</p>
<p><a href="http://nmap.org/">Nmap</a> was one of the first tools to implement this. Lets try it out!</p>
<p>Download the latest development release from <a href="http://download.insecure.org/nmap-dist/">http://download.insecure.org/nmap-dist/</a> (at the time of writing: <a href="http://nmap.ucsd.edu/nmap/dist/nmap-4.85BETA6.tar.bz2">4.85BETA6</a>) and the usual configure, make, sudo make install should to the trick, but in case you run into compile- or run-time errors you may want to check out <a href="http://nmap.org/book/inst-source.html">this page</a>. (If you face run-time complaints about openssl, you should follow <a href="http://www.skullsecurity.org/blog/?p=209">this link</a>). There&#8217;s also binaries available for <a href="http://nmap.ucsd.edu/nmap/dist/nmap-4.85BETA6-setup.exe">Windows</a> and <a href="http://nmap.ucsd.edu/nmap/dist/nmap-4.85BETA6.dmg">OSX</a>.</p>
<p>The following is an example of a basic scan for conficker</p>
<p><code style="font-size:1.4em;">nmap -sC -PN -d -p445 --script=smb-check-vulns \<br />
--script-args=safe=1 192.168.1.1</code></p>
<p>For large-scale scans, you may invoke nmap with some optimisations parameters as <a href="http://seclists.org/nmap-dev/2009/q1/0869.html">recommended here</a>.</p>
<p><code style="font-size:1.4em;">nmap -sC -PN -d -p445 -n -T4 --min-hostgroup 256 \<br />
--min-parallelism 64 --script=smb-check-vulns \<br />
--script-args=safe=1 10.0.0.0/8</code></p>
<p>In addition to the no-ping (PN) and port specific scan (p) we added no-dns-resolution (n), more aggressive timing controls (T) and parallel scanning with group of 256 hosts (with at least 64 simultaneously). The two latter parameters may be tuned even further for increased performance. <a href="http://seclists.org/nmap-dev/2009/q1/0869.html">The recommendation</a> is to maintain a 4:1 ratio between the two values, and keep the upper limit to 4096/1024.</p>
<p>Using safe=1 as an argument sent to the script, the <a href="http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx">MS08-067 vulnerability</a> is not really checked. Using unsafe=1 and it will be checked, however be aware of a possibility that the vulnerable server service may crash.</p>
<p>Here are some examples of the output from the script smb-check-vulns (with MS08-067 check enabled):</p>
<pre>|  MS08-067: LIKELY VULNERABLE (host stopped responding)
|  Conficker: Likely INFECTED

|  MS08-067: FIXED
|  Conficker: Likely CLEAN</pre>
<p>&#8230;So, scan your network now, while it&#8217;s still possible.</p>
<div id="flaresmith" class="feedflare"><script src="http://feeds.feedburner.com/~s/honeynor?i=http://www.honeynor.no/2009/03/31/using-nmap-to-scan-for-conficker/" type="text/javascript" charset="utf-8"></script></div>]]></content:encoded>
			<wfw:commentRss>http://www.honeynor.no/2009/03/31/using-nmap-to-scan-for-conficker/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Fighting Back!</title>
		<link>http://www.honeynor.no/2009/03/31/fighting-back/</link>
		<comments>http://www.honeynor.no/2009/03/31/fighting-back/#comments</comments>
		<pubDate>Tue, 31 Mar 2009 20:19:00 +0000</pubDate>
		<dc:creator>Tor Inge Skaar</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[Conficker]]></category>
		<category><![CDATA[kye paper]]></category>

		<guid isPermaLink="false">http://www.honeynor.no/?p=129</guid>
		<description><![CDATA[Yesterday, The Honeynet Project released a brand new Know-Your-Enemy (KYE) paper titled; Containing Conficker. Previous papers about the Conficker variants (like SRI&#8217;s analysis) have focused on explaining the inner workings of the malware. The KYE paper, on the other hand, proposes new ideas on how to identify, mitigate and remove Conficker from compromised hosts. The [...]]]></description>
			<content:encoded><![CDATA[<p>Yesterday, <a href="http://www.honeynet.org">The Honeynet Project</a> released a brand new Know-Your-Enemy (KYE) paper titled; <a href="https://www.honeynet.org/papers/conficker/">Containing Conficker</a>. Previous papers about the Conficker variants (like <a href="http://mtc.sri.com/Conficker/">SRI&#8217;s analysis</a>) have focused on explaining the inner workings of the malware. The KYE paper, on the other hand, proposes new ideas on how to identify, mitigate and remove Conficker from compromised hosts.</p>
<p>The paper contains a wealth of excellent information and actionable intelligence for both security analysts and network/system engineers trying to defend against the vexing issue that is; Conficker. Together with the paper, a series of different open source tools have also been <a href="http://iv.cs.uni-bonn.de/wg/cs/applications/containing-conficker/">released</a>:</p>
<ul>
<li>Domain Name Generation Tool &#8211; <a href="http://iv.cs.uni-bonn.de/uploads/media/downatool2_01.exe">Downatool2</a></li>
<li>Memory Disinfectant &#8211; <a href="http://iv.cs.uni-bonn.de/uploads/media/conficker_mem_killer.exe">conficker_mem_killer.exe</a></li>
<li>File and Registry Detector &#8211; <a href="http://iv.cs.uni-bonn.de/uploads/media/regnfile_01.exe">regnfile.exe</a></li>
<li>Conficker Remote Scanner &#8211; <a href="http://iv.cs.uni-bonn.de/uploads/media/scs_exe.zip">scs.exe</a></li>
<li>Nonficker Vaccination Tool &#8211; <a href="http://iv.cs.uni-bonn.de/uploads/media/nonficker_01.zip">nonficker.zip</a></li>
</ul>
<p>The <a href="http://iv.cs.uni-bonn.de/wg/cs/applications/containing-conficker/">collection page</a> includes the source code for all these tools and also <a href="http://nebula.carnivore.it/">Nebula</a>-generated Snort signatures for Conficker.</p>
<p>Here is the link to the paper again, in case you missed it: <a href="https://www.honeynet.org/files/KYE-Conficker.pdf">PDF</a>.</p>
<div id="flaresmith" class="feedflare"><script src="http://feeds.feedburner.com/~s/honeynor?i=http://www.honeynor.no/2009/03/31/fighting-back/" type="text/javascript" charset="utf-8"></script></div>]]></content:encoded>
			<wfw:commentRss>http://www.honeynor.no/2009/03/31/fighting-back/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Daemonlogger 1.1</title>
		<link>http://www.honeynor.no/2008/08/07/daemonlogger-11/</link>
		<comments>http://www.honeynor.no/2008/08/07/daemonlogger-11/#comments</comments>
		<pubDate>Thu, 07 Aug 2008 21:03:30 +0000</pubDate>
		<dc:creator>Tor Inge Skaar</dc:creator>
				<category><![CDATA[Tools]]></category>
		<category><![CDATA[packet capture]]></category>
		<category><![CDATA[pcap]]></category>
		<category><![CDATA[trace]]></category>

		<guid isPermaLink="false">http://www.honeynor.no/?p=38</guid>
		<description><![CDATA[Marty just released version 1.1 of daemonlogger. In addition to a small bug fix, it now includes the missing functionality I wrote about in the previous post; ring buffer activation based on disk utilization. The new option -M takes a percentage value as argument. The value specify the percentage of disk utilization you want before [...]]]></description>
			<content:encoded><![CDATA[<p>Marty just released version 1.1 of daemonlogger. In addition to a small bug fix, it now includes the missing functionality I wrote about in the <a href="http://www.honeynor.no/2008/08/01/daemonlogger-patch/">previous post</a>; <em>ring buffer activation based on disk utilization</em>. The new option <span style="font-family:monospace; font-size:1.3em;">-M</span> takes a percentage value as argument. The value specify the percentage of disk utilization you want before the ring buffer gets activated. Here is an example where old log files are deleted when there is only 2% of free space left:</p>
<p><code>daemonlogger -i eth0 -d -l /var/log/pcap -S 0 -t 1h <span style="color:red;">-M 98</span> -r</code></p>
<p>Get it at: <a href="http://www.snort.org/users/roesch/code/daemonlogger-1.1.0.tar.gz">http://www.snort.org/users/roesch/code/daemonlogger-1.1.0.tar.gz</a></p>
<div id="flaresmith" class="feedflare"><script src="http://feeds.feedburner.com/~s/honeynor?i=http://www.honeynor.no/2008/08/07/daemonlogger-11/" type="text/javascript" charset="utf-8"></script></div>]]></content:encoded>
			<wfw:commentRss>http://www.honeynor.no/2008/08/07/daemonlogger-11/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Daemonlogger Patch</title>
		<link>http://www.honeynor.no/2008/08/01/daemonlogger-patch/</link>
		<comments>http://www.honeynor.no/2008/08/01/daemonlogger-patch/#comments</comments>
		<pubDate>Fri, 01 Aug 2008 22:33:52 +0000</pubDate>
		<dc:creator>Tor Inge Skaar</dc:creator>
				<category><![CDATA[Tips & Tricks]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[packet capture]]></category>
		<category><![CDATA[patch]]></category>
		<category><![CDATA[pcap]]></category>
		<category><![CDATA[trace]]></category>

		<guid isPermaLink="false">http://www.honeynor.no/?p=31</guid>
		<description><![CDATA[I&#8217;ve been using Daemonlogger now for some time, and really like this compact yet highly functional packet capture tool from Marty Roesch (mr. Snort himself). It&#8217;s libpcap based and has some nice features like log-&#038;-replay, log rotation and ring-buffer. Features that are missing in the tcpdump implementation I used prior to Daemonlogger. In many situations [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.honeynor.no/img/daemonlogger.png" alt="A demonic log..." style="margin: 5px" align="right" />I&#8217;ve been using <a href="http://www.snort.org/users/roesch/Site/Daemonlogger/Daemonlogger.html">Daemonlogger</a> now for some time, and really like this compact yet highly functional packet capture tool from Marty Roesch (mr. Snort himself). It&#8217;s libpcap based and has some nice features like log-&#038;-replay, log rotation and ring-buffer. Features that are missing in the tcpdump implementation I used prior to Daemonlogger.</p>
<p>In many situations I like to use the <span style="font-family:monospace; font-size:1.3em;">-t</span> option to partition the log files based on time, e.g. <span style="font-family:monospace; font-size:1.3em;">-t 1h</span> to get one pcap file each hour (aligned on the hour). Also, I usually create a dedicated disk partition for pcap storage. In these situations I think Daemonlogger doesn&#8217;t quite &#8220;cut the mustard&#8221;. It&#8217;s missing an easy way to have it utilize most of the dedicated disk space and rotating the pcap files based on time intervals whilst maintaining an active ring-buffer. Of course, you may use the <span style="font-family:monospace; font-size:1.3em;">-s</span> option to rotate based on the size of the log file (in bytes) and also set a count limit with <span style="font-family:monospace; font-size:1.3em;">-m</span>. But, as I mentioned, I&#8217;m more of a time guy.</p>
<p>This is why I made a small patch to Daemonlogger which implements the missing feature. The added option (<span style="font-family:monospace; font-size:1.3em; font-weight:bold;">-x</span>) lets you specify the amount of free space you want to have on the disk where the pcap files are stored.</p>
<p><code>daemonlogger -i eth0 -d -l /var/log/pcap -S 0 -t 1h <span style="color:red;">-x 500</span> -r</code></p>
<p>In the above example, daemonlogger sniffs on eth0 interface, runs in daemon mode, logs to <span style="font-family:monospace; font-size:1.3em;">/var/log/pcap</span> with a max snap length and creates a new file every hour on the hour. When there is less than 500 MiB of free space on the disk device that holds <span style="font-family:monospace; font-size:1.3em;">/var/log/pcap</span>, the ring-buffer will activate and delete the oldest file in that directory.</p>
<p><strong>Download file: <a href="http://www.honeynor.no/tools/daemonlogger.honeynor.patch">daemonlogger.honeynor.patch</a></strong></p>
<p>Disclamer: <em>I&#8217;m by no means an experienced C-programmer, so you&#8217;re on your own pal if you apply this patch :)</em></p>
<div id="flaresmith" class="feedflare"><script src="http://feeds.feedburner.com/~s/honeynor?i=http://www.honeynor.no/2008/08/01/daemonlogger-patch/" type="text/javascript" charset="utf-8"></script></div>]]></content:encoded>
			<wfw:commentRss>http://www.honeynor.no/2008/08/01/daemonlogger-patch/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Capture-HPC 2.1</title>
		<link>http://www.honeynor.no/2008/03/27/capture-hpc-21/</link>
		<comments>http://www.honeynor.no/2008/03/27/capture-hpc-21/#comments</comments>
		<pubDate>Thu, 27 Mar 2008 21:17:27 +0000</pubDate>
		<dc:creator>Tor Inge Skaar</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[Client Honeypot]]></category>

		<guid isPermaLink="false">http://www.honeynor.no/index.php/2008/03/27/capture-hpc-21/</guid>
		<description><![CDATA[The Honeynet Project and School of Mathematics, Statistics and Computer Science at Victoria University of Wellington, New Zealand are excited to announce the release of Capture-HPC v2.1. Capture-HPC is a computer security product that allows anyone to: investigate client-side computer attacks; security researchers to find and study malicious servers; virus and malware researchers to collect [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.honeynor.no/img/capturelogo.png" alt="Capture-HPC Logo" style="margin: 5px" align="right" /></p>
<p><a href="http://www.honeynet.org">The Honeynet Project</a> and <a href="http://www.mcs.vuw.ac.nz/">School of Mathematics, Statistics and Computer Science</a> at Victoria University of Wellington, <a href="http://newzealand.honeynet.org/">New Zealand</a> are excited to announce the release of <strong>Capture-HPC v2.1</strong>.</p>
<p>Capture-HPC is a computer security product that allows anyone to: investigate client-side computer attacks; security researchers to find and study malicious servers; virus and malware researchers to collect malware pushed by malicious servers; network administrators to monitor their systems for client-side attacks; and web site operators to monitor their web sites for unauthorized modifications with client-side attack code.</p>
<p>The new version have a <strong>500% increase in performance</strong> over the previous version, which should be greatly appreciated by those already familiar with the tool. Besides malware and unauthorized state changes, Capture-HPC now <strong>collects network traffic for all client/server interactions</strong>. In addition, Capture-HPC now reports statistics about the performance of the system allowing operators to monitor and tune the Capture-HPC system during operation. Introduction of a <strong>client plug-in framework</strong><strong>.</strong>. This framework allows third-party developers to include client applications that are currently not supported by Capture-HPC. A Safari browser plug-in that makes use of this feature is provided with the 2.1 version of Capture-HPC adding support for this browser and demonstrating the capabilities of this framework. In addition, a wide range of browsers, office applications, and media players are supported by Capture-HPC.</p>
<p><a href="https://projects.honeynet.org/capture-hpc/wiki">Download Capture-HPC</a></p>
<div id="flaresmith" class="feedflare"><script src="http://feeds.feedburner.com/~s/honeynor?i=http://www.honeynor.no/2008/03/27/capture-hpc-21/" type="text/javascript" charset="utf-8"></script></div>]]></content:encoded>
			<wfw:commentRss>http://www.honeynor.no/2008/03/27/capture-hpc-21/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
