<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">

<channel>
	<title>Norwegian Honeynet Project</title>
	
	<link>http://www.honeynor.no</link>
	<description>A chapter of the Honeynet Project</description>
	<lastBuildDate>Thu, 02 Sep 2010 11:38:23 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/honeynor" /><feedburner:info uri="honeynor" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><item>
		<title>ISF conference</title>
		<link>http://feedproxy.google.com/~r/honeynor/~3/1UjyjCZc7XU/</link>
		<comments>http://www.honeynor.no/2010/09/02/isf-conference/#comments</comments>
		<pubDate>Thu, 02 Sep 2010 11:38:23 +0000</pubDate>
		<dc:creator>Tor Inge Skaar</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[conference]]></category>
		<category><![CDATA[ISF]]></category>
		<category><![CDATA[odp]]></category>
		<category><![CDATA[pdf]]></category>
		<category><![CDATA[ppt]]></category>
		<category><![CDATA[presentation]]></category>
		<category><![CDATA[tools]]></category>

		<guid isPermaLink="false">http://www.honeynor.no/?p=478</guid>
		<description><![CDATA[Yesterday we had the pleasure of doing a presentation at the Norwegian infosec conference &#8220;ISF&#8220;. Our presentation gave a brief introduction to the Honeynet Project in general, but the main part introduced to the audience a lot of the tools developed by the project together with a few external tools as well. The presentation is [...]]]></description>
			<content:encoded><![CDATA[<p>Yesterday we had the pleasure of doing a presentation at the Norwegian infosec conference &#8220;<a href="http://www.isf.no">ISF</a>&#8220;. Our presentation gave a brief introduction to the Honeynet Project in general, but the main part introduced to the audience a lot of the tools developed by the project together with a few external tools as well. The presentation is available for download in several formats: <a href="http://www.honeynor.no/pres/ISF2010.pdf">PDF</a>, <a href="http://www.honeynor.no/pres/ISF2010.odp">ODP</a> or <a href="http://www.honeynor.no/pres/ISF2010.ppt">PPT</a>.</p>
<div id="flaresmith" class="feedflare"><script src="http://feeds.feedburner.com/~s/honeynor?i=http://www.honeynor.no/2010/09/02/isf-conference/" type="text/javascript" charset="utf-8"></script></div><img src="http://feeds.feedburner.com/~r/honeynor/~4/1UjyjCZc7XU" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.honeynor.no/2010/09/02/isf-conference/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.honeynor.no/2010/09/02/isf-conference/</feedburner:origLink></item>
		<item>
		<title>Forensic Challenge 2010-5</title>
		<link>http://feedproxy.google.com/~r/honeynor/~3/429oIjHo_cg/</link>
		<comments>http://www.honeynor.no/2010/09/01/forensic-challenge-2010-5/#comments</comments>
		<pubDate>Wed, 01 Sep 2010 18:50:51 +0000</pubDate>
		<dc:creator>Tor Inge Skaar</dc:creator>
				<category><![CDATA[Challenge]]></category>

		<guid isPermaLink="false">http://www.honeynor.no/?p=472</guid>
		<description><![CDATA[The Honeynet Project is pleased to announce the next forensic challenge: Log Mysteries. This challenge takes you into the world of virtual systems and confusing log data. Figure out what happened to a virtual server using all the logs from a possibly compromised server. Challenge 5 has been created by Raffael Marty from the Bay [...]]]></description>
			<content:encoded><![CDATA[<p><a href="https://honeynet.org/challenges/2010_5_log_mysteries"><img class="alignnone size-full wp-image-471" style="border: 0pt none;" title="FC5" src="http://www.honeynor.no/wp-content/uploads/2010/09/FC5.png" alt="" width="380" height="354" /></a></p>
<p>The Honeynet Project is pleased to announce the next forensic challenge: <strong><a href="https://honeynet.org/challenges/2010_5_log_mysteries">Log Mysteries</a></strong>. This challenge takes you into the world of virtual systems and confusing log data. Figure out what happened to a virtual server using all the logs from a possibly compromised server.</p>
<p>Challenge 5 has been created by Raffael Marty from the <a href="http://www.honeynet.org/chapters/ba">Bay Area Chapter</a>, Anton Chuvakin from the <a href="http://www.honeynet.org/chapters/hawaii">Hawaiian Chapter</a>, and Sebastien Tricaud from the <a href="http://www.honeynet.org/chapters/france">French Chapter</a>.</p>
<p>Submission deadline is <strong>September 30th</strong> and we will be announcing  winners around October 21st. We have a few small prizes for the top  three submission.</p>
<p>Good luck, and enjoy!</p>
<div id="flaresmith" class="feedflare"><script src="http://feeds.feedburner.com/~s/honeynor?i=http://www.honeynor.no/2010/09/01/forensic-challenge-2010-5/" type="text/javascript" charset="utf-8"></script></div><img src="http://feeds.feedburner.com/~r/honeynor/~4/429oIjHo_cg" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.honeynor.no/2010/09/01/forensic-challenge-2010-5/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.honeynor.no/2010/09/01/forensic-challenge-2010-5/</feedburner:origLink></item>
		<item>
		<title>Another VoIP hacking in Norway</title>
		<link>http://feedproxy.google.com/~r/honeynor/~3/CEidZSU7Hn0/</link>
		<comments>http://www.honeynor.no/2010/07/28/another-voip-hacking-in-norway/#comments</comments>
		<pubDate>Wed, 28 Jul 2010 12:24:03 +0000</pubDate>
		<dc:creator>sjur</dc:creator>
				<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://www.honeynor.no/?p=467</guid>
		<description><![CDATA[The latest month of scanning has seemed valuable for the hackers. A Norwegian municipality has been hacked and their PBX has been calling Somalia and a lot of others destinations we have picked up on our VoIP honeypots during the last month. If you have an unsecure IP PBX on the net, now it will [...]]]></description>
			<content:encoded><![CDATA[<div>
<p>The latest month of scanning has seemed valuable for the  hackers. A Norwegian municipality has been hacked and their PBX has been  calling Somalia and a lot of others destinations we have picked up on  our VoIP honeypots during the last month.</p>
<p>If you have an unsecure IP PBX on the net, now it will only take  hours before it will be detected. Most normal cause for this is  misconfiguration. The people setting up the IP PBX has not taken  security seriously and the IP PBX is wide open for calling.</p>
<p>The simplest ways is that inbound calls is routed out again if no  local destination is found.  A little harder is to just brute-force the  password on extensions. I can only say, there will be more like this!</p>
<p><a onclick="javascript:pageTracker._trackPageview('/outbound/article/http://www.nettavisen.no/it/article2952472.ece');" href="http://www.nettavisen.no/it/article2952472.ece">Norwegian  version</a></p>
<p><a onclick="javascript:pageTracker._trackPageview('/outbound/article/http://translate.google.com/translate?js=y&amp;prev=_t&amp;hl=no&amp;ie=UTF-8&amp;layout=1&amp;eotf=1&amp;u=http%3A%2F%2Fwww.nettavisen.no%2Fit%2Farticle2952472.ece&amp;sl=no&amp;tl=en');" href="http://translate.google.com/translate?js=y&amp;prev=_t&amp;hl=no&amp;ie=UTF-8&amp;layout=1&amp;eotf=1&amp;u=http%3A%2F%2Fwww.nettavisen.no%2Fit%2Farticle2952472.ece&amp;sl=no&amp;tl=en" target="_blank">English version</a></p>
<p>The hacker can sell this “gateway” to a third party dealing with  calling cards. I have investigated frauds in Norway where they managed  to send 1,2 million NOK (approx 200 000 USD) within 10 days. This was a  Cisco installation, but misconfigured Asterisk installations are also  abused a lot.</p>
</div>
<div id="flaresmith" class="feedflare"><script src="http://feeds.feedburner.com/~s/honeynor?i=http://www.honeynor.no/2010/07/28/another-voip-hacking-in-norway/" type="text/javascript" charset="utf-8"></script></div><img src="http://feeds.feedburner.com/~r/honeynor/~4/CEidZSU7Hn0" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.honeynor.no/2010/07/28/another-voip-hacking-in-norway/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.honeynor.no/2010/07/28/another-voip-hacking-in-norway/</feedburner:origLink></item>
		<item>
		<title>VoIP Challenge released! Real attack data!</title>
		<link>http://feedproxy.google.com/~r/honeynor/~3/otaqbiDlaUQ/</link>
		<comments>http://www.honeynor.no/2010/06/01/voip-challenge-released-real-attack-challenge/#comments</comments>
		<pubDate>Tue, 01 Jun 2010 09:35:47 +0000</pubDate>
		<dc:creator>sjur</dc:creator>
				<category><![CDATA[Challenge]]></category>
		<category><![CDATA[voip challenge]]></category>

		<guid isPermaLink="false">http://www.honeynor.no/?p=452</guid>
		<description><![CDATA[The Honeynet Project has released a real VoIP attack challenge! It is real data and YOU must find out how the intruders does the attack! Are you up for it? You will learn more about VoIP and get an understanding of the current VoIP attack methods! Go for it here! Deadline in three weeks! Prizes [...]]]></description>
			<content:encoded><![CDATA[<p>The Honeynet Project has released a real VoIP attack challenge! It is real data and YOU must find out how the intruders does the attack! Are you up for it? You will learn more about VoIP and get an understanding of the current VoIP attack methods! <a href=" https://honeynet.org/challenges/2010_4_voip" target="_blank">Go for it here!</a> Deadline in three weeks! Prizes for the best answers!</p>
<p>The Chinese speaking members of the Honeynet Project has translated it even to simplified Chinese! Have fun and learn a lot!</p>
<p><strong>Update (26. jun):</strong> NB! Only a few days left to submit your answer! The deadline is June 30th.</p>
<p><strong>Update (28. jul):</strong> The solution and the winners of this challenge is available <a href="http://www.honeynet.org/node/564">here</a>.</p>
<div id="flaresmith" class="feedflare"><script src="http://feeds.feedburner.com/~s/honeynor?i=http://www.honeynor.no/2010/06/01/voip-challenge-released-real-attack-challenge/" type="text/javascript" charset="utf-8"></script></div><img src="http://feeds.feedburner.com/~r/honeynor/~4/otaqbiDlaUQ" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.honeynor.no/2010/06/01/voip-challenge-released-real-attack-challenge/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.honeynor.no/2010/06/01/voip-challenge-released-real-attack-challenge/</feedburner:origLink></item>
		<item>
		<title>Firefox prefetch</title>
		<link>http://feedproxy.google.com/~r/honeynor/~3/MOqGCj_zXF8/</link>
		<comments>http://www.honeynor.no/2010/05/18/firefox-prefetch/#comments</comments>
		<pubDate>Tue, 18 May 2010 22:47:10 +0000</pubDate>
		<dc:creator>Tor Inge Skaar</dc:creator>
				<category><![CDATA[Tips & Tricks]]></category>
		<category><![CDATA[config]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[precrime]]></category>
		<category><![CDATA[prefetch]]></category>
		<category><![CDATA[search]]></category>

		<guid isPermaLink="false">http://www.honeynor.no/?p=435</guid>
		<description><![CDATA[Are you aware of the effects of the network-prefetch-next preference in Firefox? It&#8217;s actually quite an old feature (according to this site it was introduced way back in 2003), but I&#8217;m pretty sure not everyone know the possibly scary side effect of this smart(tm) feature. It tries to make the browser being one step ahead [...]]]></description>
			<content:encoded><![CDATA[<p>Are you aware of the effects of the network-prefetch-next preference in Firefox? It&#8217;s actually quite an old feature (according to <a href="http://kb.mozillazine.org/Network.prefetch-next">this</a> site it was introduced way back in 2003), but I&#8217;m pretty sure not everyone know the possibly scary side effect of this smart(tm) feature. It tries to make the browser being one step ahead of its user, by prefetching sites it assumes the user will click on next.</p>
<p>This is what&#8217;s being logged on honeynor.no when I (84.215.x.y) google the word &#8220;<a href="http://www.google.com/#hl=en&#038;q=honeynor">honeynor</a>&#8220;.</p>
<p><code>84.215.x.y - - [18/May/2010:23:42:55 +0200] "GET / HTTP/1.1" 200 17832 "http://www.google.com/ \<br />
search?hl=en&#038;source=hp&#038;q=honeynor&#038;aq=f&#038;aqi=g-s1g-sx7&#038;aql=&#038;oq=&#038;gs_rfai=&#038;fp=64bbd6d9727d98e0" \<br />
"Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.9.2.3) Gecko/20100423 Ubuntu/10.04 (lucid) \<br />
Firefox/3.6.3"</code></p>
<p>I haven&#8217;t left google yet!, but my very intelligent browser thinks I might click on the first link (www.honeynor.no) so it goes ahead and access the site, way before my puny brain has had any chance on processing the search output. In true <a href="http://en.wikipedia.org/wiki/Philip_K._Dick">PKD</a>-style, I hereby accuse firefox of a precrime!</p>
<p>Why is this action bad? Let me answer the question with a question; Do you always want to access the sites presented to you when you search the web? I can think of several cases where I&#8217;m not keen on letting some third party know of my interest in them; either that&#8217;s during an analysis or in case of possible repercussions against me for accessing a site in an unexpected or socially engineered manner.</p>
<p>It seems google is in cahoots with firefox on this one, because I&#8217;m unable to reproduce the same result using bing, yahoo or alltheweb. Only on google is the prefetch mechanism activated.</p>
<p>So, how can you disable this feature? Luckily it very easy; go to <strong>about:config</strong> in your firefox/mozilla browser and set the parameter <strong>network.prefetch-next</strong> to <strong>false</strong>. That&#8217;s it! </p>
<div id="flaresmith" class="feedflare"><script src="http://feeds.feedburner.com/~s/honeynor?i=http://www.honeynor.no/2010/05/18/firefox-prefetch/" type="text/javascript" charset="utf-8"></script></div><img src="http://feeds.feedburner.com/~r/honeynor/~4/MOqGCj_zXF8" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.honeynor.no/2010/05/18/firefox-prefetch/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.honeynor.no/2010/05/18/firefox-prefetch/</feedburner:origLink></item>
		<item>
		<title>Firefox 3.6.x and vmrc</title>
		<link>http://feedproxy.google.com/~r/honeynor/~3/ME8dY06Of6g/</link>
		<comments>http://www.honeynor.no/2010/05/04/firefox-3-6-x-and-vmrc/#comments</comments>
		<pubDate>Tue, 04 May 2010 21:11:51 +0000</pubDate>
		<dc:creator>Tor Inge Skaar</dc:creator>
				<category><![CDATA[Tips & Tricks]]></category>
		<category><![CDATA[console]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[plugin]]></category>
		<category><![CDATA[remote]]></category>
		<category><![CDATA[server]]></category>
		<category><![CDATA[vmrc]]></category>
		<category><![CDATA[vmware]]></category>

		<guid isPermaLink="false">http://www.honeynor.no/?p=424</guid>
		<description><![CDATA[Recently I upgraded to the 3.6 series of Firefox (3.6.3 to be exact), and suddenly my VMware Remote Console (vmrc) was broken. We use VMware Server 2.0.1, but upgrading to the latest 2.0.2, didn&#8217;t help. At closer inspection, the problem was not with the server nor with vmrc itself, but rather with the integration of [...]]]></description>
			<content:encoded><![CDATA[<p>Recently I upgraded to the 3.6 series of Firefox (3.6.3 to be exact), and suddenly my VMware Remote Console (vmrc) was broken. We use VMware Server 2.0.1, but upgrading to the latest 2.0.2, didn&#8217;t help. At closer inspection, the problem was not with the server nor with vmrc itself, but rather with the integration of the plugin used with Firefox 3.6 (I&#8217;m using VMware Remote Console Plug-in 2.5.0.122581). Whether the problem is related to the plug-in or FF 3.6&#8242;s plug-in framework (or a combination of the two), I do not know. What I do know though, is that you don&#8217;t have to downgrade to FF 3.5.x if you use the following workaround.</p>
<p>On your vmware server, go to the following directory:<br />
<code style="font-size: 1.4em;">/usr/lib/vmware/webAccess/tomcat/ \<br />
apache-tomcat-6.0.16/webapps/ui/plugin/</code></p>
<p>Copy the appropriate vmrc plugin for your client platform (mine was a 32 bit Ubuntu 10.04 Desktop, so I grabbed vmware-vmrc-linux-x86.xpi).</p>
<p>On your client, unzip the xpi-file:</p>
<p><code style="font-size: 1.4em;">$ unzip vmware-vmrc-linux-x86.xpi</code></p>
<p>Run the vmrc executable (it&#8217;s actually just a wrapper script) manually by specifying the absolute path (I extracted the contents to /tmp):</p>
<p><code style="font-size: 1.4em;">$ /tmp/vmrc/plugins/vmware-vmrc</code></p>
<p>The vmrc UI starts, and you can connect to your vmware server by either specifying it&#8217;s hostname or it&#8217;s IP-address, together with your username and password (I also had to specify the port, e.g. &lt;IP&gt;:8333). When a connection has been established with the server, you will be presented with a selection of virtual machines you may connect to.</p>
<div id="flaresmith" class="feedflare"><script src="http://feeds.feedburner.com/~s/honeynor?i=http://www.honeynor.no/2010/05/04/firefox-3-6-x-and-vmrc/" type="text/javascript" charset="utf-8"></script></div><img src="http://feeds.feedburner.com/~r/honeynor/~4/ME8dY06Of6g" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.honeynor.no/2010/05/04/firefox-3-6-x-and-vmrc/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.honeynor.no/2010/05/04/firefox-3-6-x-and-vmrc/</feedburner:origLink></item>
		<item>
		<title>Forensic Challenge 2010-3</title>
		<link>http://feedproxy.google.com/~r/honeynor/~3/N86hB4s1IlA/</link>
		<comments>http://www.honeynor.no/2010/03/28/forensic-challenge-2010-3/#comments</comments>
		<pubDate>Sun, 28 Mar 2010 17:26:56 +0000</pubDate>
		<dc:creator>Tor Inge Skaar</dc:creator>
				<category><![CDATA[Challenge]]></category>
		<category><![CDATA[banking]]></category>
		<category><![CDATA[forensics]]></category>
		<category><![CDATA[memory]]></category>
		<category><![CDATA[vm]]></category>

		<guid isPermaLink="false">http://www.honeynor.no/?p=416</guid>
		<description><![CDATA[The Honeynet Project is proud to present our third Forensic Challenge 2010 created by Josh Smith and Matt Cote from The Rochester Institute of Technology Chapter, Angelo Dell&#8217;Aera from the Italian Chapter and Nicolas Collery from the Singapore Chapter. This challenge is a bit different than the previous two, as it involves investigating a memory [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://honeynet.org/challenges/2010_3_banking_troubles"><img class="alignnone size-full wp-image-415" title="banking.trouble" src="http://www.honeynor.no/wp-content/uploads/2010/03/banking.trouble.png" alt="" width="380" height="321" /></a></p>
<p>The Honeynet Project is proud to present our third Forensic Challenge 2010 created by Josh Smith and Matt Cote from <a href="http://honeynet.rit.edu/">The Rochester Institute of Technology Chapter</a>, Angelo Dell&#8217;Aera from the <a href="http://www.honeynet.it/">Italian Chapter</a> and Nicolas Collery from the <a href="http://www.honeynet.sg/">Singapore Chapter</a>. This challenge is a bit different than the previous two, as it involves investigating a <a href="http://honeynet.org/challenge2010/downloads/hn_forensics.tgz">memory image</a> of an infected virtual machine. Read all the <a href="http://honeynet.org/challenges/2010_3_banking_troubles">questions</a> for this challenge over at the main blog and <a href="http://www.honeynet.org/challenge2010/">submit</a> your answers by 17:00 EST, Sunday, April 18th 2010. Good luck!</p>
<p><strong>UPDATE (12.Apr):</strong> There are now additional third-party incentives to participate in this forensics challenge. Both <a href="http://volatility.tumblr.com/post/490537917/a-volatile-challenge-the-honeynet-project-has-banking">Volatile Systems</a> and <a href="http://blog.mandiant.com/archives/901">MANDIANT</a> are offering their own prices to the top three winners that apply their memory analysis tools; The Volatility Framework, Memoryze and Audit Viewer respectively. But remember, there are now only a few days left until deadline, so get moving!</p>
<p><strong>UPDATE (19.Apr):</strong> The submission deadline for this challenge has been extended till April 26th.</p>
<p><strong>UPDATE (14.May):</strong> The solution and the winners of this challenge is available <a href="https://www.honeynet.org/node/542">here</a>.</p>
<p>The solution and winners of the second challenge are shown <a href="https://www.honeynet.org/node/531">here</a>.</p>
<div id="flaresmith" class="feedflare"><script src="http://feeds.feedburner.com/~s/honeynor?i=http://www.honeynor.no/2010/03/28/forensic-challenge-2010-3/" type="text/javascript" charset="utf-8"></script></div><img src="http://feeds.feedburner.com/~r/honeynor/~4/N86hB4s1IlA" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.honeynor.no/2010/03/28/forensic-challenge-2010-3/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<feedburner:origLink>http://www.honeynor.no/2010/03/28/forensic-challenge-2010-3/</feedburner:origLink></item>
		<item>
		<title>Enhanced CC2ASN</title>
		<link>http://feedproxy.google.com/~r/honeynor/~3/J6aG-Z6Biek/</link>
		<comments>http://www.honeynor.no/2010/03/23/enhanced-cc2asn/#comments</comments>
		<pubDate>Tue, 23 Mar 2010 21:46:49 +0000</pubDate>
		<dc:creator>Tor Inge Skaar</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[ASN]]></category>
		<category><![CDATA[CC2ASN]]></category>
		<category><![CDATA[country]]></category>
		<category><![CDATA[delta]]></category>
		<category><![CDATA[enhanced]]></category>
		<category><![CDATA[ISO-3166]]></category>
		<category><![CDATA[lookup]]></category>
		<category><![CDATA[netcat]]></category>
		<category><![CDATA[whois]]></category>

		<guid isPermaLink="false">http://www.honeynor.no/?p=404</guid>
		<description><![CDATA[For over 9 months we&#8217;ve run our CC2ASN service, allowing you to lookup up ISO-3166 country codes and get back all ASNs, IPv4 or IPv6 prefixes for that specific country. Now the time had come to do an update. A major issue with the RIR data (delegated-feeds) used by the CC2ASN service, is ASNs registered [...]]]></description>
			<content:encoded><![CDATA[<p>For over <a href="http://www.honeynor.no/2009/06/19/country-lookup/">9 months</a> we&#8217;ve run our <a href="http://www.honeynor.no/tools/cc2asn/">CC2ASN service</a>, allowing you to lookup up ISO-3166 country codes and get back all ASNs, IPv4 or IPv6 prefixes for that specific country. Now the time had come to do an update.</p>
<p>A major issue with the <a href="http://en.wikipedia.org/wiki/Regional_Internet_Registry">RIR</a> data (delegated-feeds) used by the CC2ASN service, is ASNs registered to a region instead of a specific country. There are currently two regions in use; European Union (EU) and Asia Pacific (AP). The reason for using this is the ever increasing globalization of corporations and organizations, and hence quite understandable. But when you want a list of AS numbers for any given country code, the regional registrations have to be included.</p>
<p>This is where the <strong>enhanced database</strong> comes into action. In this database we&#8217;ve manually overridden the country code assignments for those ASNs that in the RIR data were registered to either EU or AP. In addition we&#8217;ve also corrected a few other ASNs that we knew had a wrong country code. The list we&#8217;ve compiled is publicly available: <a href="http://www.honeynor.no/tools/cc2asn/asn_override.txt">asn_override.txt</a>.</p>
<p>It&#8217;s all been a manual job, going through all the EU and AP ASNs, plus a good portion of the CCs also. The CC override decision is based on one or more of the following actions:</p>
<ul>
<li>Looking at references to location in whois descr, address or country records.</li>
<li>Using location info in router names from tracepath of the AS prefixes.</li>
<li>The nationality of peers and upstream providers.</li>
<li>Location of corporate headquarters or regional headquarters.</li>
<li>General googling/binging.</li>
</ul>
<p>And this is a continuing job, whenever new ASNs are allocated to either EU or AP.</p>
<p>So, how do you access this new database? From the CC2ASN <a href="http://www.honeynor.no/tools/cc2asn/">web-interface</a> make sure you check the box labeled &#8220;<em>Use Enhanced Database</em>&#8220;. The database is also available by directly querying port 44/tcp (the normal CC2ASN database is available on standard whois port 43/tcp). Note that the enhanced database only outputs ASNs, not prefixes.</p>
<p><code style="font-size: 1.4em;">$ echo "GB" | nc atari.honeynor.no <strong>44</strong><br />
</code></p>
<p>Every day, when the latest RIR data are downloaded and parsed, all changes to the enhanced database are recorded. This allows us to provide you with an <strong>ASN history tool</strong>; <a href="http://www.honeynor.no/tools/cc2asn/delta/">CC2ASN Delta</a>. The main page lists changes over the last 90 days for ASNs registered to a spesific country. By clicking on a county, you get a textual representation of all registered changes for that country. By further clicking on an ASN, you get a listing of potential country changes for that AS.</p>
<p><a href="http://www.honeynor.no/tools/cc2asn/delta/"><img class="alignnone size-full wp-image-405" title="cc2asn.delta" src="http://www.honeynor.no/wp-content/uploads/2010/03/cc2asn.delta_.png" alt="" width="380" height="339" /></a></p>
<p>For more information, take a look at the <a href="http://www.honeynor.no/tools/cc2asn/about.php">documentation</a>.</p>
<div id="flaresmith" class="feedflare"><script src="http://feeds.feedburner.com/~s/honeynor?i=http://www.honeynor.no/2010/03/23/enhanced-cc2asn/" type="text/javascript" charset="utf-8"></script></div><img src="http://feeds.feedburner.com/~r/honeynor/~4/J6aG-Z6Biek" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.honeynor.no/2010/03/23/enhanced-cc2asn/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.honeynor.no/2010/03/23/enhanced-cc2asn/</feedburner:origLink></item>
		<item>
		<title>GSoC 2010</title>
		<link>http://feedproxy.google.com/~r/honeynor/~3/avToozS9-aI/</link>
		<comments>http://www.honeynor.no/2010/03/19/gsoc-2010/#comments</comments>
		<pubDate>Fri, 19 Mar 2010 16:43:54 +0000</pubDate>
		<dc:creator>Tor Inge Skaar</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[GSoC]]></category>
		<category><![CDATA[summer]]></category>
		<category><![CDATA[work]]></category>

		<guid isPermaLink="false">http://www.honeynor.no/?p=389</guid>
		<description><![CDATA[The Honeynet Project has once again been accepted as a mentor organization in Google Summer of Code (GSoC). During the next week or so, we&#8217;ll keep updating our GSoC-2010 page, especially the page of proposed ideas. We&#8217;ve got a wide range of projects and develop tools using most of the popular programming languages, so if [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-full wp-image-396" style="border: 0pt none; margin: 10px;" title="GSoC" src="http://www.honeynor.no/wp-content/uploads/2010/03/art.gif" alt="" width="143" height="53" align="right" /><a href="https://www.honeynet.org">The Honeynet Project</a> has once again been accepted as a mentor organization in <a href="http://socghop.appspot.com/">Google Summer of Code</a> (GSoC). During the next week or so, we&#8217;ll keep updating our <a href="http://www.honeynet.org/gsoc">GSoC-2010</a> page, especially the <a href="http://www.honeynet.org/gsoc/ideas">page of proposed ideas</a>.</p>
<p>We&#8217;ve got a wide range of projects and develop tools using most of the popular programming languages, so if you are an <a href="http://socghop.appspot.com/document/show/gsoc_program/google/gsoc2010/faqs#eligibility">eligible student</a> interested in open source software, information security or honeynet technologies and think spending your summer being paid by Google to work on an exciting software development project sounds like a great plan, we look forward to hearing from you.</p>
<p>Simply connect to #gsoc-honeynet on irc.freenode.net to chat to our organizational admins and project mentors. Do remember that you don&#8217;t have to apply for one of our pre-defined project ideas, you can also propose your own project topic which we&#8217;ll try to find a suitable mentor for too. Google will start accepting student applications from <a href="http://socghop.appspot.com/document/show/gsoc_program/google/gsoc2010/faqs#timeline">Monday, March 29 at 19:00 UTC</a>.</p>
<div id="flaresmith" class="feedflare"><script src="http://feeds.feedburner.com/~s/honeynor?i=http://www.honeynor.no/2010/03/19/gsoc-2010/" type="text/javascript" charset="utf-8"></script></div><img src="http://feeds.feedburner.com/~r/honeynor/~4/avToozS9-aI" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.honeynor.no/2010/03/19/gsoc-2010/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.honeynor.no/2010/03/19/gsoc-2010/</feedburner:origLink></item>
		<item>
		<title>Forensic Challenge 2010-2</title>
		<link>http://feedproxy.google.com/~r/honeynor/~3/VMt6iotMnro/</link>
		<comments>http://www.honeynor.no/2010/02/17/forensic-challenge-2010-2/#comments</comments>
		<pubDate>Wed, 17 Feb 2010 18:18:56 +0000</pubDate>
		<dc:creator>Tor Inge Skaar</dc:creator>
				<category><![CDATA[Challenge]]></category>
		<category><![CDATA[attack]]></category>
		<category><![CDATA[Browser]]></category>
		<category><![CDATA[forensics]]></category>
		<category><![CDATA[pcap]]></category>
		<category><![CDATA[web]]></category>

		<guid isPermaLink="false">http://www.honeynor.no/?p=373</guid>
		<description><![CDATA[The Honeynet Project is proud to present our second Forensic Challenge 2010 created by by Nicolas Collery from the Singapore Chapter and Guillaume Arcas from the French Chapter. Provided with our pcap file, you&#8217;re challenged to answer ten questions before the deadline at March 1. Read all about it at honeynet.org. Good Luck! The solution [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://honeynet.org/challenges/2010_2_browsers_under_attack"><img class="size-full wp-image-372 alignnone" title="browsers.attack" src="http://www.honeynor.no/wp-content/uploads/2010/02/browsers.attack.png" alt="" width="380" height="293" /></a></p>
<p>The Honeynet Project is proud to present our second Forensic Challenge 2010 created by by Nicolas Collery from the <a href="http://www.honeynet.sg/">Singapore Chapter</a> and Guillaume Arcas from the French Chapter. Provided with our <a href="http://honeynet.org/files/suspicious-time.pcap">pcap file</a>, you&#8217;re challenged to answer <a href="http://honeynet.org/challenges/2010_2_browsers_under_attack">ten questions</a> before the deadline at March 1. Read all about it at <a href="http://honeynet.org/challenges/2010_2_browsers_under_attack">honeynet.org</a>. <strong>Good Luck!</strong></p>
<p>The solution and winners of the first challenge are shown <a href="http://honeynet.org/node/504">here</a>.</p>
<div id="flaresmith" class="feedflare"><script src="http://feeds.feedburner.com/~s/honeynor?i=http://www.honeynor.no/2010/02/17/forensic-challenge-2010-2/" type="text/javascript" charset="utf-8"></script></div><img src="http://feeds.feedburner.com/~r/honeynor/~4/VMt6iotMnro" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.honeynor.no/2010/02/17/forensic-challenge-2010-2/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<feedburner:origLink>http://www.honeynor.no/2010/02/17/forensic-challenge-2010-2/</feedburner:origLink></item>
	</channel>
</rss>
