<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>UK Honeynet Project &#187; Incidents</title>
	<atom:link href="http://www.ukhoneynet.org/category/incidents/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ukhoneynet.org</link>
	<description>News and information from the UK Honeynet Project</description>
	<lastBuildDate>Sun, 20 Feb 2011 21:28:04 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1</generator>
		<item>
		<title>It had to happen</title>
		<link>http://www.ukhoneynet.org/2008/06/30/it-had-to-happen/</link>
		<comments>http://www.ukhoneynet.org/2008/06/30/it-had-to-happen/#comments</comments>
		<pubDate>Mon, 30 Jun 2008 09:00:10 +0000</pubDate>
		<dc:creator>arthur</dc:creator>
				<category><![CDATA[Incidents]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Add new tag]]></category>

		<guid isPermaLink="false">http://www.ukhoneynet.org/2008/06/30/it-had-to-happen/</guid>
		<description><![CDATA[Today we received our first bit of spam from EC2. The message itself was pretty standard: From: "Microsoft" Date: 29 June 2008 11:47:43 BST To: XXX Subject: Important Update Notification Hello XXX, You are receiving this notification because the version of Windows you are running is effected by a critical security issue. For the protection [...]]]></description>
			<content:encoded><![CDATA[<p>Today we received our first bit of spam from EC2. The message itself was pretty standard:</p>
<pre>
From: "Microsoft" <UpdateNotify56@microsoft.biz>
Date: 29 June 2008 11:47:43 BST
To: XXX
Subject: Important Update Notification

Hello XXX,

You are receiving this notification because the version of Windows you are running is effected by a critical security issue.

For the protection of yourself and others using the Windows operating system, it is reccomended that all consumers update their operating system at their earliest convenience.

To do so, you may visit Microsoft Update by clicking here, and simply pressing "Open" or "Run" to begin the automatic update process.

Thank you for your cooperation in resolving this matter.

Kind Regards,
Microsoft Customer Support
</pre>
<p>The link points to a phishing site</p>
<pre>

http://XXX/go.nhn?url=http%3A%2F%2Fupdate%2Emicrosoft%2Ecom%2E00000000000000000000000000000000000000000000000000000000000000%2Enet
</pre>
<p>So far, so standard. The interesting bit is in the headers of the message:</p>
<pre>
Received: (qmail 29794 invoked from network); 29 Jun 2008 09:53:08 -0000
Received: from ec2-75-101-198-26.compute-1.amazonaws.com (HELO ec2-75-101-198-26.compute-1.amazonaws.com) (75.101.198.26)
  by server-14.tower-117.messagelabs.com with SMTP; 29 Jun 2008 09:53:08 -0000
From: "Microsoft" <UpdateNotify56@microsoft.biz>
</pre>
<p>How long before all email from EC2 is blacklisted? It was only a matter of time before services like this started to be used for sending spam, but this is the first time I&#8217;ve seen it in the wild.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ukhoneynet.org/2008/06/30/it-had-to-happen/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>French HP catch zero-day exploit</title>
		<link>http://www.ukhoneynet.org/2005/08/17/170805-a/</link>
		<comments>http://www.ukhoneynet.org/2005/08/17/170805-a/#comments</comments>
		<pubDate>Wed, 17 Aug 2005 00:01:00 +0000</pubDate>
		<dc:creator>david</dc:creator>
				<category><![CDATA[Incidents]]></category>
		<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://ukhoneynet.dev2.isotoma.com/?p=270</guid>
		<description><![CDATA[French Honeynet Project catch zero-day exploit: A honeypot run by the French Honeynet Project has caught a zero-day windows exploit (http://www.frenchhoneynetproject.org)]]></description>
			<content:encoded><![CDATA[<p>French Honeynet Project catch zero-day exploit: A honeypot run by the French Honeynet Project has caught a zero-day windows exploit (<a href="http://www.frenchhoneynetproject.org">http://www.frenchhoneynetproject.org</a>)</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ukhoneynet.org/2005/08/17/170805-a/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft&#8217;s &#8216;monkeys&#8217; find first zero-day exploit</title>
		<link>http://www.ukhoneynet.org/2005/08/09/090805/</link>
		<comments>http://www.ukhoneynet.org/2005/08/09/090805/#comments</comments>
		<pubDate>Tue, 09 Aug 2005 00:00:00 +0000</pubDate>
		<dc:creator>david</dc:creator>
				<category><![CDATA[Incidents]]></category>
		<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://ukhoneynet.dev2.isotoma.com/?p=274</guid>
		<description><![CDATA[Microsoft&#8217;s &#8220;monkeys&#8221; find first zero-day exploit: Microsoft&#8217;s well publicised Honeymonkey project has found its first zero day exploit: http://online.securityfocus.com/news/11273]]></description>
			<content:encoded><![CDATA[<p>Microsoft&#8217;s &#8220;monkeys&#8221; find first zero-day exploit: Microsoft&#8217;s well publicised Honeymonkey project has found its first zero day exploit: <a href="http://online.securityfocus.com/news/11273">http://online.securityfocus.com/news/11273</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.ukhoneynet.org/2005/08/09/090805/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Rootkit websites taken down by DDoS attacks</title>
		<link>http://www.ukhoneynet.org/2005/04/13/130405/</link>
		<comments>http://www.ukhoneynet.org/2005/04/13/130405/#comments</comments>
		<pubDate>Wed, 13 Apr 2005 00:00:00 +0000</pubDate>
		<dc:creator>david</dc:creator>
				<category><![CDATA[Incidents]]></category>

		<guid isPermaLink="false">http://ukhoneynet.dev2.isotoma.com/?p=302</guid>
		<description><![CDATA[Rootkit web sites taken down by DDoS attacks]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.nwfusion.com/news/2005/0411rootkwebs.html">Rootkit web sites taken down by DDoS attacks</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.ukhoneynet.org/2005/04/13/130405/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

