<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>
<channel>
	<title>Comments on: Storm Binary Tracker Updates</title>
	<atom:link href="http://www.sudosecure.net/archives/153/feed" rel="self" type="application/rss+xml" />
	<link>http://www.sudosecure.net/archives/153</link>
	<description>is anything truly secure...</description>
	<pubDate>Tue, 06 Jan 2009 04:35:55 +0000</pubDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: jeremy</title>
		<link>http://www.sudosecure.net/archives/153/comment-page-1#comment-89</link>
		<dc:creator>jeremy</dc:creator>
		<pubDate>Mon, 14 Jul 2008 20:09:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.sudosecure.net/?p=153#comment-89</guid>
		<description>1. based on each MD5 hash, having links to any of the online analyzers will be a good idea.

----The MD5 hash links shouldn't be hard, so I will look into that soon.  

2. bindiff of the each variant.

----Is their a bindiff tool for linux as I would want to automate this on the box already doing the analysis.  Maybe there is a switch in the standard diff for binaries... I will have to look at this.

3. probably, a column for ports, protrocols used by each variant.

----Now this would be hard....  Not easily done without automating the lab run of the actual binary, which is something I would like to do but haven't.  

Thanks for the suggestions and glad you found the information useful.

--jeremy</description>
		<content:encoded><![CDATA[<p>1. based on each MD5 hash, having links to any of the online analyzers will be a good idea.</p>
<p>&#8212;-The MD5 hash links shouldn&#8217;t be hard, so I will look into that soon.  </p>
<p>2. bindiff of the each variant.</p>
<p>&#8212;-Is their a bindiff tool for linux as I would want to automate this on the box already doing the analysis.  Maybe there is a switch in the standard diff for binaries&#8230; I will have to look at this.</p>
<p>3. probably, a column for ports, protrocols used by each variant.</p>
<p>&#8212;-Now this would be hard&#8230;.  Not easily done without automating the lab run of the actual binary, which is something I would like to do but haven&#8217;t.  </p>
<p>Thanks for the suggestions and glad you found the information useful.</p>
<p>&#8211;jeremy</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gopal</title>
		<link>http://www.sudosecure.net/archives/153/comment-page-1#comment-88</link>
		<dc:creator>Gopal</dc:creator>
		<pubDate>Mon, 14 Jul 2008 19:41:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.sudosecure.net/?p=153#comment-88</guid>
		<description>Jermey,

As it is, its pretty good info. 

In addtion to Spam tracking, Domain Name tracking, Name Server Tracking, Web Page Tracking, and a possible peers dataset.

If possible, This info might help few researchers.
1. based on each MD5 hash, having links to any of the online analyzers will be a good idea. 
2. bindiff of the each variant.
3. probably, a column for ports, protrocols used by each variant.

- lot of work, but i love your work.
-Thanks for sharing.</description>
		<content:encoded><![CDATA[<p>Jermey,</p>
<p>As it is, its pretty good info. </p>
<p>In addtion to Spam tracking, Domain Name tracking, Name Server Tracking, Web Page Tracking, and a possible peers dataset.</p>
<p>If possible, This info might help few researchers.<br />
1. based on each MD5 hash, having links to any of the online analyzers will be a good idea.<br />
2. bindiff of the each variant.<br />
3. probably, a column for ports, protrocols used by each variant.</p>
<p>- lot of work, but i love your work.<br />
-Thanks for sharing.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
