<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>I Am Security &#187; toolkit</title>
	<atom:link href="http://www.iamit.org/blog/tag/toolkit/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.iamit.org/blog</link>
	<description>Security news and research</description>
	<lastBuildDate>Mon, 26 Jul 2010 09:20:36 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=abc</generator>
<cloud domain='www.iamit.org' port='80' path='/blog/?rsscloud=notify' registerProcedure='' protocol='http-post' />
		<item>
		<title>Down the rabbit hole all the way to Miami</title>
		<link>http://www.iamit.org/blog/2009/09/down-the-rabbit-hole-all-the-way-to-miami/</link>
		<comments>http://www.iamit.org/blog/2009/09/down-the-rabbit-hole-all-the-way-to-miami/#comments</comments>
		<pubDate>Fri, 25 Sep 2009 01:13:47 +0000</pubDate>
		<dc:creator>iamit</dc:creator>
				<category><![CDATA[Opinion]]></category>
		<category><![CDATA[Security Research]]></category>
		<category><![CDATA[conference]]></category>
		<category><![CDATA[cyberwarfare]]></category>
		<category><![CDATA[eCrime]]></category>
		<category><![CDATA[research]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[toolkit]]></category>

		<guid isPermaLink="false">http://www.iamit.org/blog/?p=368</guid>
		<description><![CDATA[So the talk at Hacker Halted was really good &#8211; I was impressed with the quality of the audience and the presentations. As promised, I&#8217;m posting my slide deck here for your reference. Enjoy! Down_the_rabbit_Hole-Ian_Amit Related posts:Taking the Red Pill Down the Rabbit Hole ExcaliburCon summary and general China notes Cyber[Crime&#124;War] &#8211; connecting the dots [...]


Related posts:<ol><li><a href='http://www.iamit.org/blog/2008/10/taking-the-red-pill-down-the-rabbit-hole/' rel='bookmark' title='Permanent Link: Taking the Red Pill Down the Rabbit Hole'>Taking the Red Pill Down the Rabbit Hole</a></li>
<li><a href='http://www.iamit.org/blog/2009/11/excaliburcon-summary-and-general-china-notes/' rel='bookmark' title='Permanent Link: ExcaliburCon summary and general China notes'>ExcaliburCon summary and general China notes</a></li>
<li><a href='http://www.iamit.org/blog/2010/04/cybercrimewar-connecting-the-dots-blackhat-eu-2010/' rel='bookmark' title='Permanent Link: Cyber[Crime|War] &#8211; connecting the dots &#8211; BlackHat EU 2010'>Cyber[Crime|War] &#8211; connecting the dots &#8211; BlackHat EU 2010</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>So the talk at Hacker Halted was really good &#8211; I was impressed with the quality of the audience and the presentations.<br />
As promised, I&#8217;m posting my slide deck here for your reference. Enjoy!<br />
<a href="http://www.iamit.org/blog/wp-content/uploads/2009/09/Down_the_rabbit_Hole-Ian_Amit.ppt">Down_the_rabbit_Hole-Ian_Amit</a></p>


<p>Related posts:<ol><li><a href='http://www.iamit.org/blog/2008/10/taking-the-red-pill-down-the-rabbit-hole/' rel='bookmark' title='Permanent Link: Taking the Red Pill Down the Rabbit Hole'>Taking the Red Pill Down the Rabbit Hole</a></li>
<li><a href='http://www.iamit.org/blog/2009/11/excaliburcon-summary-and-general-china-notes/' rel='bookmark' title='Permanent Link: ExcaliburCon summary and general China notes'>ExcaliburCon summary and general China notes</a></li>
<li><a href='http://www.iamit.org/blog/2010/04/cybercrimewar-connecting-the-dots-blackhat-eu-2010/' rel='bookmark' title='Permanent Link: Cyber[Crime|War] &#8211; connecting the dots &#8211; BlackHat EU 2010'>Cyber[Crime|War] &#8211; connecting the dots &#8211; BlackHat EU 2010</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.iamit.org/blog/2009/09/down-the-rabbit-hole-all-the-way-to-miami/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>The impact of just 5 random letters&#8230;</title>
		<link>http://www.iamit.org/blog/2008/01/the-impact-of-just-5-random-letters/</link>
		<comments>http://www.iamit.org/blog/2008/01/the-impact-of-just-5-random-letters/#comments</comments>
		<pubDate>Thu, 17 Jan 2008 02:50:00 +0000</pubDate>
		<dc:creator>iamit</dc:creator>
				<category><![CDATA[Finjan]]></category>
		<category><![CDATA[Security Research]]></category>
		<category><![CDATA[press]]></category>
		<category><![CDATA[research]]></category>
		<category><![CDATA[toolkit]]></category>

		<guid isPermaLink="false">http://www.iamit.org/blog/?p=36</guid>
		<description><![CDATA[We have been watching in amazement the impact our latest Malicious Page of the Month had on the industry and media. From coverage at Fox Business News, and the Washington Post, all the way to the more &#8220;traditional&#8221; security outlets such as SecurityFocus, SC Magazine and bloggers such as Dancho Danchev. The scary thing is the [...]


Related posts:<ol><li><a href='http://www.iamit.org/blog/2009/09/two-steps-forward-one-step-back-controling-botnets/' rel='bookmark' title='Permanent Link: Two steps forward, one step back &#8211; controling botnets&#8230;'>Two steps forward, one step back &#8211; controling botnets&#8230;</a></li>
<li><a href='http://www.iamit.org/blog/2007/09/hitting-the-nail-on-the-head/' rel='bookmark' title='Permanent Link: Hitting the nail on the head'>Hitting the nail on the head</a></li>
<li><a href='http://www.iamit.org/blog/2008/11/hosting-provider-crackdown/' rel='bookmark' title='Permanent Link: Hosting provider crackdown?'>Hosting provider crackdown?</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<div>
<p>We have been watching in amazement the impact our latest <a href="http://www.finjan.com/GetObject.aspx?ObjId=550&amp;Openform=50">Malicious Page of the Month</a> had on the industry and media.<br />
From coverage at <a href="http://www.foxbusiness.com/article/finjan-uncovers-insidious-new-variant-crimeware-toolkit-infecting-10000_434265_1.html" target="_blank">Fox Business News</a>, and the <a href="http://www.washingtonpost.com/wp-dyn/content/article/2008/01/15/AR2008011500025.html" target="_blank">Washington Post</a>, all the way to the more &#8220;traditional&#8221; security outlets such as <a href="http://www.securityfocus.com/news/11501" target="_blank">SecurityFocus</a>, <a href="http://www.scmagazineus.com/JavaScript-toolkit-hit-10000-websites-in-December-Finjan/article/104174/" target="_blank">SC Magazine</a> and bloggers such as <a href="http://ddanchev.blogspot.com/2008/01/random-js-malware-exploitation-kit.html" target="_blank">Dancho Danchev</a>.</p>
<p>The scary thing is the non-media related impact &#8211; we are still seeing a tremendous amount of domains (and sites) that are still compromised. Just a quick preview of the ongoing research we are putting into this &#8211; we are getting closer to getting to the root (no pun intended) cause of the problem that seems to affect Linux webservers (and this time it may not be a cPanel related issue for a change).</p>
<p>Looking forward to posting an update soon as we make progress in cracking this one.</p></div>


<p>Related posts:<ol><li><a href='http://www.iamit.org/blog/2009/09/two-steps-forward-one-step-back-controling-botnets/' rel='bookmark' title='Permanent Link: Two steps forward, one step back &#8211; controling botnets&#8230;'>Two steps forward, one step back &#8211; controling botnets&#8230;</a></li>
<li><a href='http://www.iamit.org/blog/2007/09/hitting-the-nail-on-the-head/' rel='bookmark' title='Permanent Link: Hitting the nail on the head'>Hitting the nail on the head</a></li>
<li><a href='http://www.iamit.org/blog/2008/11/hosting-provider-crackdown/' rel='bookmark' title='Permanent Link: Hosting provider crackdown?'>Hosting provider crackdown?</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.iamit.org/blog/2008/01/the-impact-of-just-5-random-letters/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Tying it all up &#8211; explosive exploits&#8230;</title>
		<link>http://www.iamit.org/blog/2007/03/tying-it-all-up-explosive-exploits/</link>
		<comments>http://www.iamit.org/blog/2007/03/tying-it-all-up-explosive-exploits/#comments</comments>
		<pubDate>Thu, 22 Mar 2007 02:33:30 +0000</pubDate>
		<dc:creator>iamit</dc:creator>
				<category><![CDATA[Finjan]]></category>
		<category><![CDATA[Security Research]]></category>
		<category><![CDATA[toolkit]]></category>

		<guid isPermaLink="false">http://www.iamit.org/blog/?p=6</guid>
		<description><![CDATA[The funniest thing happened yesterday &#8211; at a watercooler conversation our CTO informs us of a site that uses techniques from almost all of our trend reports (which means we are right as usual&#8230;). The interesting part was that it was one of those &#8220;iframe&#8221; sites that give you a small iframe html code to [...]


Related posts:<ol><li><a href='http://www.iamit.org/blog/2007/03/analyzing-an-ajax-attack-vector-in-the-wild/' rel='bookmark' title='Permanent Link: Analyzing an AJAX Attack Vector in the wild'>Analyzing an AJAX Attack Vector in the wild</a></li>
<li><a href='http://www.iamit.org/blog/2007/06/have-something-to-hide-make-a-lot-of-noise-about-it/' rel='bookmark' title='Permanent Link: Have something to hide? make a lot of noise about it!'>Have something to hide? make a lot of noise about it!</a></li>
<li><a href='http://www.iamit.org/blog/2007/10/iframe-is-a-security-risk/' rel='bookmark' title='Permanent Link: IFRAME is a security risk???'>IFRAME is a security risk???</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>The funniest thing happened yesterday &#8211; at a watercooler conversation our CTO informs us of a site that uses techniques from almost all of our trend reports (which means we are right as usual&#8230;). The interesting part was that it was one of those &#8220;iframe&#8221; sites that give you a small iframe html code to put in your website and they&#8217;ll pay you &#8220;per-infection&#8221; (is this thing copyrighted/patented yet??? <img src='http://www.iamit.org/blog/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' />  ).</p>
<p>Old news&#8230;</p>
<p>But &#8211; after looking into the code he figured that this is pretty nasty stuff that basically BYPASSES every major security vendor&#8217;s detection technology (except for ours of course &#8211; and no &#8211; it&#8217;s not a marketing spin&#8230;).</p>
<p>A few hours later we pushed out an &#8220;Extra&#8221; version of the &#8220;Malicious Page of the Month&#8221; dubbed &#8220;Malicious Page Under Benchmark&#8221; to show how the most modern names in security can&#8217;t handle a bunch of hackers that publicly spread their exploits.</p>
<p>Check it out at: <a href="http://www.finjan.com/content.aspx?id=1367">http://www.finjan.com/content.aspx?id=1367</a></p>
<p>Be safe&#8230;</p>


<p>Related posts:<ol><li><a href='http://www.iamit.org/blog/2007/03/analyzing-an-ajax-attack-vector-in-the-wild/' rel='bookmark' title='Permanent Link: Analyzing an AJAX Attack Vector in the wild'>Analyzing an AJAX Attack Vector in the wild</a></li>
<li><a href='http://www.iamit.org/blog/2007/06/have-something-to-hide-make-a-lot-of-noise-about-it/' rel='bookmark' title='Permanent Link: Have something to hide? make a lot of noise about it!'>Have something to hide? make a lot of noise about it!</a></li>
<li><a href='http://www.iamit.org/blog/2007/10/iframe-is-a-security-risk/' rel='bookmark' title='Permanent Link: IFRAME is a security risk???'>IFRAME is a security risk???</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.iamit.org/blog/2007/03/tying-it-all-up-explosive-exploits/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
