<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>InfoSecBits &#187; Uncategorized</title>
	<atom:link href="https://www.infosecbits.com/category/uncategorized/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.infosecbits.com</link>
	<description>Information Security Bits by Carlos Villalba &#38; Friends</description>
	<lastBuildDate>Mon, 16 Feb 2015 23:38:34 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>https://wordpress.org/?v=4.1.41</generator>
	<item>
		<title>North Korea Did it!</title>
		<link>https://www.infosecbits.com/north-korea-did-it/</link>
		<comments>https://www.infosecbits.com/north-korea-did-it/#comments</comments>
		<pubDate>Thu, 08 Jan 2015 05:56:57 +0000</pubDate>
		<dc:creator><![CDATA[cavallal]]></dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.infosecbits.com/?p=35</guid>
		<description><![CDATA[Well, after so much speculation the FBI Director James Comey unveiled information on Wednesday that he said provides a &#8220;very clear indication&#8221; that North Korea perpetrated the massive cyber attack against Sony. Newsweek reported the story Now, with the announcement of sanctions&#8230;<p class="more-link-p"><a class="more-link" href="https://www.infosecbits.com/north-korea-did-it/">Read more &#8594;</a></p>]]></description>
				<content:encoded><![CDATA[<p>Well, after so much speculation the FBI Director James Comey unveiled information on Wednesday that he said provides a &#8220;very clear indication&#8221; that North Korea perpetrated the massive cyber attack against Sony.</p>
<p>Newsweek reported the <a title="Newsweek" href="http://www.newsweek.com/fbi-director-provides-new-evidence-implicating-north-korea-sony-hack-297687" target="_blank">story</a> Now, with the announcement of sanctions and perhaps other forms of civil retaliation this single act may be the starting point in which countries will start taking formal and public actions against cyber attacks. I don&#8217;t intend to speculate on what those actions may be but certainly a change, only time will tell if it&#8217;s for the good or the beginning of taking wars to the electronic frontier.</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>https://www.infosecbits.com/north-korea-did-it/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Do we need antivirus in Linux?</title>
		<link>https://www.infosecbits.com/do-we-need-antivirus-in-linux/</link>
		<comments>https://www.infosecbits.com/do-we-need-antivirus-in-linux/#comments</comments>
		<pubDate>Tue, 09 Dec 2014 00:58:45 +0000</pubDate>
		<dc:creator><![CDATA[cavallal]]></dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.infosecbits.com/?p=32</guid>
		<description><![CDATA[The most common answer to the age old question is probably no. We as a community of security practitioners may have to update our position on this one given the latest findings in terms of Turla. A stealth trojan that&#8230;<p class="more-link-p"><a class="more-link" href="https://www.infosecbits.com/do-we-need-antivirus-in-linux/">Read more &#8594;</a></p>]]></description>
				<content:encoded><![CDATA[<p>The most common answer to the age old question is probably no. We as a community of security practitioners may have to update our position on this one given the latest findings in terms of <a title="Turla" href="http://arstechnica.com/security/2014/12/powerful-highly-stealthy-linux-trojan-may-have-infected-victims-for-years/" target="_blank">Turla</a>. A stealth trojan that steals data from systems. Turla is not exclusive to Linux, it is also available in its Windows variant but the ultimate goal is the same.</p>
<p>Hard to detect but with some behaviors that make detection possible. For instance outgoing traffic to 80.248.65.183 or the string &#8220;TREX_PID=%u&#8221; and &#8220;Remote VS is empty !&#8221; will help you identify the culprit.</p>
<p>Have your SIEMS or use our old friend grep or yara to look for these. Keep in ind that Turla is considered a sophisticated advanced persistent threat (APT).</p>
<p>Happy trojan hunting.</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>https://www.infosecbits.com/do-we-need-antivirus-in-linux/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
