<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: FREE HoneyPoint to Capture Conflicker Infections</title>
	<atom:link href="http://stateofsecurity.com/?feed=rss2&#038;p=612" rel="self" type="application/rss+xml" />
	<link>http://stateofsecurity.com/?p=612</link>
	<description>Insight from the Information Security Experts</description>
	<lastBuildDate>Tue, 31 Aug 2010 17:42:12 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=abc</generator>
	<item>
		<title>By: Brent Huston</title>
		<link>http://stateofsecurity.com/?p=612&#038;cpage=1#comment-20642</link>
		<dc:creator>Brent Huston</dc:creator>
		<pubDate>Sun, 04 Oct 2009 16:54:58 +0000</pubDate>
		<guid isPermaLink="false">http://stateofsecurity.com/?p=612#comment-20642</guid>
		<description>Sorry for the 404, but this tool has now expired. The free version is no longer available, but &lt;a href=&quot;http://microsolved.com/?page_id=86&quot; rel=&quot;nofollow&quot;&gt;the trial and a license version is available here&lt;/a&gt; that does much more than catch Conficker. 

The price for the commercial tool is US $29.95 and available through the Digital River store.</description>
		<content:encoded><![CDATA[<p>Sorry for the 404, but this tool has now expired. The free version is no longer available, but <a href="http://microsolved.com/?page_id=86" rel="nofollow">the trial and a license version is available here</a> that does much more than catch Conficker. </p>
<p>The price for the commercial tool is US $29.95 and available through the Digital River store.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Joel</title>
		<link>http://stateofsecurity.com/?p=612&#038;cpage=1#comment-20641</link>
		<dc:creator>Joel</dc:creator>
		<pubDate>Sun, 04 Oct 2009 16:20:00 +0000</pubDate>
		<guid isPermaLink="false">http://stateofsecurity.com/?p=612#comment-20641</guid>
		<description>Hi,

Is this application still available? The download link returns a HTTP 404.

Thanks!</description>
		<content:encoded><![CDATA[<p>Hi,</p>
<p>Is this application still available? The download link returns a HTTP 404.</p>
<p>Thanks!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Danny</title>
		<link>http://stateofsecurity.com/?p=612&#038;cpage=1#comment-17012</link>
		<dc:creator>Danny</dc:creator>
		<pubDate>Fri, 27 Mar 2009 15:41:31 +0000</pubDate>
		<guid isPermaLink="false">http://stateofsecurity.com/?p=612#comment-17012</guid>
		<description>Silly question...how can I test this to make sure it is working?</description>
		<content:encoded><![CDATA[<p>Silly question&#8230;how can I test this to make sure it is working?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Brent Huston</title>
		<link>http://stateofsecurity.com/?p=612&#038;cpage=1#comment-17011</link>
		<dc:creator>Brent Huston</dc:creator>
		<pubDate>Fri, 27 Mar 2009 14:14:59 +0000</pubDate>
		<guid isPermaLink="false">http://stateofsecurity.com/?p=612#comment-17011</guid>
		<description>Neither. The tool is not a scanner, it is a honeypot for capturing incoming probes from Conficker compromised hosts. 

Once the worm is in control of a system, it uses that system to scan for other victims. The scanning is what this product is aimed at catching. 

See http://www.microsolved.com/honeypoint/ to learn more about the basic concepts behind this approach.</description>
		<content:encoded><![CDATA[<p>Neither. The tool is not a scanner, it is a honeypot for capturing incoming probes from Conficker compromised hosts. </p>
<p>Once the worm is in control of a system, it uses that system to scan for other victims. The scanning is what this product is aimed at catching. </p>
<p>See <a href="http://www.microsolved.com/honeypoint/" rel="nofollow">http://www.microsolved.com/honeypoint/</a> to learn more about the basic concepts behind this approach.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: James Friesen</title>
		<link>http://stateofsecurity.com/?p=612&#038;cpage=1#comment-17010</link>
		<dc:creator>James Friesen</dc:creator>
		<pubDate>Fri, 27 Mar 2009 14:01:19 +0000</pubDate>
		<guid isPermaLink="false">http://stateofsecurity.com/?p=612#comment-17010</guid>
		<description>Does it simply scan your LAN, or can it be told to look at a WAN port?</description>
		<content:encoded><![CDATA[<p>Does it simply scan your LAN, or can it be told to look at a WAN port?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Brent Huston</title>
		<link>http://stateofsecurity.com/?p=612&#038;cpage=1#comment-17004</link>
		<dc:creator>Brent Huston</dc:creator>
		<pubDate>Thu, 26 Mar 2009 12:06:32 +0000</pubDate>
		<guid isPermaLink="false">http://stateofsecurity.com/?p=612#comment-17004</guid>
		<description>I saw your blog post. Thanks for the feedback. I should have included a readme. 

Basically, you execute the application as root on a Linux box (preferably one without Samba) (a LiveCD such as Puppy Linux will also work). The instructions for it&#039;s use are in the How To: window of the application, but you just click start and the application will dilate port 445/tcp with a HoneyPoint listener. Then you wait for probes to arrive from conficker scans and the app will log the source IP addresses to the log window. Treat all source IP addresses as infected hosts and investigate them in accordance with your site&#039;s security policy. 

Let me know if you have other questions. Good hunting!</description>
		<content:encoded><![CDATA[<p>I saw your blog post. Thanks for the feedback. I should have included a readme. </p>
<p>Basically, you execute the application as root on a Linux box (preferably one without Samba) (a LiveCD such as Puppy Linux will also work). The instructions for it&#8217;s use are in the How To: window of the application, but you just click start and the application will dilate port 445/tcp with a HoneyPoint listener. Then you wait for probes to arrive from conficker scans and the app will log the source IP addresses to the log window. Treat all source IP addresses as infected hosts and investigate them in accordance with your site&#8217;s security policy. </p>
<p>Let me know if you have other questions. Good hunting!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Craig</title>
		<link>http://stateofsecurity.com/?p=612&#038;cpage=1#comment-17003</link>
		<dc:creator>Craig</dc:creator>
		<pubDate>Thu, 26 Mar 2009 10:54:00 +0000</pubDate>
		<guid isPermaLink="false">http://stateofsecurity.com/?p=612#comment-17003</guid>
		<description>How do we use this, are there any instructions?  Details on what it does?</description>
		<content:encoded><![CDATA[<p>How do we use this, are there any instructions?  Details on what it does?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
