<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments for Network Forensics Blog</title>
	<atom:link href="http://www.networkforensics.com/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.networkforensics.com</link>
	<description></description>
	<lastBuildDate>Tue, 20 Jul 2010 16:25:20 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>Comment on Visualize and Content Enhancements by New NetWitness Visualize : Welcome To The Future! &#124; Dragos Lungu Dot Com</title>
		<link>http://www.networkforensics.com/2010/07/19/visualize/comment-page-1/#comment-308</link>
		<dc:creator>New NetWitness Visualize : Welcome To The Future! &#124; Dragos Lungu Dot Com</dc:creator>
		<pubDate>Tue, 20 Jul 2010 16:25:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.networkforensics.com/?p=369#comment-308</guid>
		<description>[...] I have already written about how awesome NetWitness is so I won&#039;t repeat what i said in this NetWitness review ; instead I would like to present you the most advanced network traffic visualization system I&#039;ve ever seen, the NetWitness Visualize. [...]</description>
		<content:encoded><![CDATA[<p>[...] I have already written about how awesome NetWitness is so I won&#39;t repeat what i said in this NetWitness review ; instead I would like to present you the most advanced network traffic visualization system I&#39;ve ever seen, the NetWitness Visualize. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Kneber Update by Zeus Botnet: Interesting and In-depth Articles &#171; Mister Reiner</title>
		<link>http://www.networkforensics.com/2010/02/19/kneber-update/comment-page-1/#comment-112</link>
		<dc:creator>Zeus Botnet: Interesting and In-depth Articles &#171; Mister Reiner</dc:creator>
		<pubDate>Sat, 05 Jun 2010 10:38:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.networkforensics.com/?p=207#comment-112</guid>
		<description>[...] NetWitness Blog: Kneber Update (Web page &#8211; An attempt to set the record straight) [...]</description>
		<content:encoded><![CDATA[<p>[...] NetWitness Blog: Kneber Update (Web page &#8211; An attempt to set the record straight) [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on They are watching you&#8230;and your security vendors. by Content Delivery Networks for Security &#171; cdnXite Blog</title>
		<link>http://www.networkforensics.com/2010/05/30/they-are-watching-you-and-your-security-vendors/comment-page-1/#comment-109</link>
		<dc:creator>Content Delivery Networks for Security &#171; cdnXite Blog</dc:creator>
		<pubDate>Wed, 02 Jun 2010 13:34:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.networkforensics.com/?p=309#comment-109</guid>
		<description>[...] harmful websites use content delivery networks for this reason so that the address of the server that malicious websites are hosted on remains [...]</description>
		<content:encoded><![CDATA[<p>[...] harmful websites use content delivery networks for this reason so that the address of the server that malicious websites are hosted on remains [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on They are watching you&#8230;and your security vendors. by BelchSpeak &#187; Post Topic &#187; Anti-Antivirus- Concentrated Binary Evil!</title>
		<link>http://www.networkforensics.com/2010/05/30/they-are-watching-you-and-your-security-vendors/comment-page-1/#comment-107</link>
		<dc:creator>BelchSpeak &#187; Post Topic &#187; Anti-Antivirus- Concentrated Binary Evil!</dc:creator>
		<pubDate>Tue, 01 Jun 2010 21:26:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.networkforensics.com/?p=309#comment-107</guid>
		<description>[...] Networkforensics.com here: Scan4u.biz is essentially a “criminal virustotal plus”. That is, it is a service where a [...]</description>
		<content:encoded><![CDATA[<p>[...] Networkforensics.com here: Scan4u.biz is essentially a “criminal virustotal plus”. That is, it is a service where a [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on They are watching you&#8230;and your security vendors. by Network Forensics Blog » Blog Archive » They are watching you…and &#8230; &#171; Tips On Security</title>
		<link>http://www.networkforensics.com/2010/05/30/they-are-watching-you-and-your-security-vendors/comment-page-1/#comment-102</link>
		<dc:creator>Network Forensics Blog » Blog Archive » They are watching you…and &#8230; &#171; Tips On Security</dc:creator>
		<pubDate>Mon, 31 May 2010 05:39:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.networkforensics.com/?p=309#comment-102</guid>
		<description>[...] reading here: Network Forensics Blog » Blog Archive » They are watching you…and &#8230;   Comments [...]</description>
		<content:encoded><![CDATA[<p>[...] reading here: Network Forensics Blog » Blog Archive » They are watching you…and &#8230;   Comments [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Move over China, here comes Russia by Se vende o alquila Kneber (alquiler de habitaciones por 50 céntimos)* &#187; blog.trendmicro.es</title>
		<link>http://www.networkforensics.com/2010/02/18/move-over-china-here-comes-russia/comment-page-1/#comment-70</link>
		<dc:creator>Se vende o alquila Kneber (alquiler de habitaciones por 50 céntimos)* &#187; blog.trendmicro.es</dc:creator>
		<pubDate>Thu, 25 Feb 2010 17:20:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.networkforensics.com/?p=187#comment-70</guid>
		<description>[...] se ha mostrado aterrada por la magnitud de una “nueva” red zombi llamada Kneber. Según un informe de NetWitness, una red zombi en concreto que utiliza el crimeware ZeuS ha logrado infiltrarse en miles de [...]</description>
		<content:encoded><![CDATA[<p>[...] se ha mostrado aterrada por la magnitud de una “nueva” red zombi llamada Kneber. Según un informe de NetWitness, una red zombi en concreto que utiliza el crimeware ZeuS ha logrado infiltrarse en miles de [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Move over China, here comes Russia by Kommentar von Trend Micro zum Kneber-Hype » markus-arlt.de</title>
		<link>http://www.networkforensics.com/2010/02/18/move-over-china-here-comes-russia/comment-page-1/#comment-68</link>
		<dc:creator>Kommentar von Trend Micro zum Kneber-Hype » markus-arlt.de</dc:creator>
		<pubDate>Tue, 23 Feb 2010 19:47:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.networkforensics.com/?p=187#comment-68</guid>
		<description>[...] entsetzt über die Ausmaße eines &#8220;neuen&#8221; Botnetzes namens Kneber. Einem Bericht von NetWitness zufolge hat ein bestimmtes Botnet, das ZeuS-Crimeware nutzt, Tausende Unternehmen und Zehntausende [...]</description>
		<content:encoded><![CDATA[<p>[...] entsetzt über die Ausmaße eines &#8220;neuen&#8221; Botnetzes namens Kneber. Einem Bericht von NetWitness zufolge hat ein bestimmtes Botnet, das ZeuS-Crimeware nutzt, Tausende Unternehmen und Zehntausende [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Kneber Update by tim</title>
		<link>http://www.networkforensics.com/2010/02/19/kneber-update/comment-page-1/#comment-67</link>
		<dc:creator>tim</dc:creator>
		<pubDate>Tue, 23 Feb 2010 10:35:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.networkforensics.com/?p=207#comment-67</guid>
		<description>Where possible, and within reason, we have notified responsible network owners of the IP addresses that are infected.  In many articles, it mentioned we are working to notify parties.  We continue to work with others including service providers, banks, and social networking sites.</description>
		<content:encoded><![CDATA[<p>Where possible, and within reason, we have notified responsible network owners of the IP addresses that are infected.  In many articles, it mentioned we are working to notify parties.  We continue to work with others including service providers, banks, and social networking sites.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Kneber Update by tim</title>
		<link>http://www.networkforensics.com/2010/02/19/kneber-update/comment-page-1/#comment-66</link>
		<dc:creator>tim</dc:creator>
		<pubDate>Tue, 23 Feb 2010 10:33:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.networkforensics.com/?p=207#comment-66</guid>
		<description>In order:

The McAfee Rootkit Detector, when we tested it the other day, did not detect this &quot;variant.&quot;  We say variant, because these adversaries can take the executable and repackage it with various tools that make it undetectable to many signature based solutions.  Since the posting of this, we have various additional repackaged versions that remain undetected.

All AV vendors have similar challenges detecting these repackaged versions.  If your signatures are up to date, you will likely detect the original variant.  However, there are more that have been released that are difficult to detect.  AV plays an important role here - but cannot be relied upon exclusively.

The IE vulnerability can be used to deliver malware.  This particular group has access to a very large spamming bot, and is using custom crafted emails that can be very convincing.

See last response on patching.  If they successfully convince you to open an trojan document, or use a zero day, or to voluntarily install, you will be infected.  Patching, like AV, is part of the solution and makes you more resistant, but does not make anyone immune.</description>
		<content:encoded><![CDATA[<p>In order:</p>
<p>The McAfee Rootkit Detector, when we tested it the other day, did not detect this &#8220;variant.&#8221;  We say variant, because these adversaries can take the executable and repackage it with various tools that make it undetectable to many signature based solutions.  Since the posting of this, we have various additional repackaged versions that remain undetected.</p>
<p>All AV vendors have similar challenges detecting these repackaged versions.  If your signatures are up to date, you will likely detect the original variant.  However, there are more that have been released that are difficult to detect.  AV plays an important role here &#8211; but cannot be relied upon exclusively.</p>
<p>The IE vulnerability can be used to deliver malware.  This particular group has access to a very large spamming bot, and is using custom crafted emails that can be very convincing.</p>
<p>See last response on patching.  If they successfully convince you to open an trojan document, or use a zero day, or to voluntarily install, you will be infected.  Patching, like AV, is part of the solution and makes you more resistant, but does not make anyone immune.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Kneber Update by EJ</title>
		<link>http://www.networkforensics.com/2010/02/19/kneber-update/comment-page-1/#comment-64</link>
		<dc:creator>EJ</dc:creator>
		<pubDate>Mon, 22 Feb 2010 17:07:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.networkforensics.com/?p=207#comment-64</guid>
		<description>One item of interest to me in this but I haven&#039;t seen commented on is whether the victims that were detected in this 74K node botnet have been notified of their participation?</description>
		<content:encoded><![CDATA[<p>One item of interest to me in this but I haven&#8217;t seen commented on is whether the victims that were detected in this 74K node botnet have been notified of their participation?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
