angelo.dellaera's blog

Forensic Challenge 9 - "Mobile Malware"

I am pleased to announce the next forensic challenge: Forensic Challenge 9 - "Mobile Malware".

The challenge has been created by by Franck Guenichot from French Chapter, Mahmud Ab Rahman and Ahmad Azizan Idris from Malaysia Chapter and Matt Erasmus from South Africa Chapter.

Submission deadline is September 4th and we will be announcing winners around the third week of September. We have a few small prizes for the top three submissions.

Have fun!

Angelo Dell'Aera
The Honeynet Project

Forensic Challenge 8 - Submission deadline passed

Folks,
the submission deadline for the Forensic Challenge 8 – “Malware Reverse Engineering” - put up by Guido Landi and Angelo Dell'Aera from the Sysenter Chapter - has passed. We have received 6 submissions and will be announcing results on Wed, Aug 31th 2011. The top three submissions will be awarded little prizes.

For your information a new Forensic Challenge will start in a few hours. This time you will be asked to dive into the mobile malware world. Stay tuned!

Angelo Dell'Aera
The Honeynet Project

Forensic Challenge 8 - "Malware Reverse Engineering" - Deadline Extended Again

We are realizing that the Forensic Challenge 8 - "Malware Reverse Engineering" - is really difficult to solve because right now we received just 5 submissions. For this reason we decided to extend the submission deadline again to July 31th.

Those who already submitted a solution before June 30th are granted the possibility to submit again thus taking advantage of this one-month extra time. Moreover a few extra bonus points will be assigned to them.

Have fun!

Angelo Dell'Aera
The Honeynet Project

Forensic Challenge 8 "Malware Reverse Engineering" - 4 days left!

Folks,
Forensic Challenge 8 "Malware Reverse Engineering" put up by Guido Landi and Angelo Dell'Aera from the Sysenter Chapter is in full swing. Submissions are due by June 30th, so if you want to participate, you have 4 days left. We award little prizes for the top three submissions! Hope to see your submission.

Angelo Dell'Aera
The Honeynet Project

Forensic Challenge 8 - "Malware Reverse Engineering" - Deadline Extended

Taking a look at the first submissions it seems like the Forensic Challenge 8 - "Malware Reverse Engineering" - is quite difficult to solve. For this reason we decided to extend the submission deadline to June 30th.

Have fun!

Angelo Dell'Aera
The Honeynet Project

Forensic Challenge 8 - "Malware Reverse Engineering"

I am pleased to announce the next forensic challenge: Forensic Challenge 8 - "Malware Reverse Engineering".

The challenge has been created by Angelo Dell'Aera and Guido Landi from the Sysenter Honeynet Project Chapter.

Submission deadline is June 15th and we will be announcing winners around the third week of July. We have a few small prizes for the top three submissions.

Have fun!

Angelo Dell'Aera
The Honeynet Project

Forensic Challenge 7 – “Forensic Analysis of a Compromised System” - And the winners are...

Folks, Guillame and Hugo have judged all submissions and results have been posted on the challenge web site. The winners are:

1. Dev Anand
2. Fernando Quintero & Camilo Zapata
3. (3 submissions) Matt Erasmus, Joseph Kahlich and Kevin Mau

Congratulations to the winners!

With challenge 7 completed, we are getting ready to launch challenge 8 on May 9th. This challenge has been prepared by Guido Landi and Angelo Dell'Aera from the Sysenter Chapter and it deals with

Forensic Challenge 7 - Publication of Results Delayed

An important update for Forensic Challenge 7 challengers. For reasons related to reviewers' everyday job committments the challenge results will be announced on Friday, May 6th 2011 and not on Friday, 29th April as announced in the previous blog post.

Thanks for your patience and regards.

Angelo Dell'Aera
The Honeynet Project

Forensic Challenge 7 - Submission deadline passed

Folks the submission deadline for the Forensic Challenge 7 – “Forensic Analysis of a Compromised System” - put up by Hugo Gonzalez from the Mexico Chapter and Guillaume Arcas from the French Chapter - has passed. We have received 16 submissions and will be announcing results on Friday, Apr 29th 2011. The winners will get a copy of the book "Virtual Honeypots - From Botnet Tracking to Intrusion Detection" written by Niels Provos and Thorsten Holz.

UPDATE: Forensic Challenge 7 results will be announced on Friday, May 6th 2011.

Angelo Dell'Aera
The Honeynet Project

PHoneyC DOM Emulation – Browser Personality

A new improvement in PHoneyC DOM emulation code was committed in SVN r1624. The idea is to better emulate the DOM behaviour depending on the selected browser personality. Let's take a look at the code starting from the personalities definition in config.py.

39 UserAgents = [
40     (1,
41      "Internet Explorer 6.0 (Windows 2000)",
42      "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727)",
43      "Mozilla",
44      "Microsoft Internet Explorer",
Syndicate content