<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>InfoSecBits &#187; hacking</title>
	<atom:link href="https://www.infosecbits.com/category/hacking/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.infosecbits.com</link>
	<description>Information Security Bits by Carlos Villalba &#38; Friends</description>
	<lastBuildDate>Mon, 16 Feb 2015 23:38:34 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>https://wordpress.org/?v=4.1.41</generator>
	<item>
		<title>Wiper threat update</title>
		<link>https://www.infosecbits.com/wiper-threat-update/</link>
		<comments>https://www.infosecbits.com/wiper-threat-update/#comments</comments>
		<pubDate>Wed, 03 Dec 2014 06:16:32 +0000</pubDate>
		<dc:creator><![CDATA[cavallal]]></dc:creator>
				<category><![CDATA[data breach]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.infosecbits.com/?p=27</guid>
		<description><![CDATA[Today the FBI released FBI Liaison Alert System #A-000044-mw. In the release they describe the workings of the malware. It attacks the MBR and all data files. After infection the infected systems to connect to one of three random, one&#8230;<p class="more-link-p"><a class="more-link" href="https://www.infosecbits.com/wiper-threat-update/">Read more &#8594;</a></p>]]></description>
				<content:encoded><![CDATA[<p>Today the FBI released FBI Liaison Alert System #A-000044-mw.</p>
<p>In the release they describe the workings of the malware. It attacks the MBR and all data files. After infection the infected systems to connect to one of three random, one of these three IP addresses (88.53.215.64, 217.96.33.164, 203.131.222.102) via either port 8080 or 8000.<br />
Sony Pictures Entertainment is dealing with the aftermath of a massive infection that must be keeping them very busy and many people out of work.</p>
<p>Snort can be configured to detect the traffic. The FBI also release the following siganture:</p>
<pre>Alert tcp any any – &gt; [88.53.215.64, 217.96.33.164, 203.131.222.102] [8080, 8000] (msg: “wiper_callout”;
dsize:42; content: “|ff ff ff ff|”; offset: 26; depth: 4; sid: 314;</pre>
<p>It&#8217;s time to check your log files and check if those IPs are listed as destination IPs in any of your traffic or log data.</p>
]]></content:encoded>
			<wfw:commentRss>https://www.infosecbits.com/wiper-threat-update/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>U.S. Government Hacked, again?</title>
		<link>https://www.infosecbits.com/u-s-government-hacked-again/</link>
		<comments>https://www.infosecbits.com/u-s-government-hacked-again/#comments</comments>
		<pubDate>Thu, 20 Nov 2014 04:15:47 +0000</pubDate>
		<dc:creator><![CDATA[cavallal]]></dc:creator>
				<category><![CDATA[data breach]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.infosecbits.com/?p=18</guid>
		<description><![CDATA[The White House, NOAA, USPS (Postal Service), and now the State Department. Wondering what the level of forensics, if the incident response teams were in place to handle the incidents and aftermath. Is it based on NIST 800-61? Who could&#8230;<p class="more-link-p"><a class="more-link" href="https://www.infosecbits.com/u-s-government-hacked-again/">Read more &#8594;</a></p>]]></description>
				<content:encoded><![CDATA[<p>The White House, NOAA, USPS (Postal Service), and now the State Department.</p>
<p>Wondering what the level of forensics, if the incident response teams were in place to handle the incidents and aftermath. Is it based on NIST 800-61?</p>
<p>Who could it been? Russia, China, Venezuela, Brazil, a teenager from a basement?</p>
<p>On this day and age as soon as an organization is breach we get to read about the dirty details, the how, and more especially the who. How come we are not hearing these this time around?</p>
<p>The security community deserves an explanation and more importantly tax payers have the right to know.</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>https://www.infosecbits.com/u-s-government-hacked-again/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
