<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>R-fx Networks &#187; malware</title>
	<atom:link href="http://www.rfxn.com/tag/malware/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.rfxn.com</link>
	<description> Linux Software &#38; Blog</description>
	<lastBuildDate>Mon, 09 Jan 2012 10:43:35 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>LMD 1.4.1: Delivering on your requests</title>
		<link>http://www.rfxn.com/lmd-1-4-1-delivering-on-your-requests/</link>
		<comments>http://www.rfxn.com/lmd-1-4-1-delivering-on-your-requests/#comments</comments>
		<pubDate>Sun, 20 Nov 2011 11:24:12 +0000</pubDate>
		<dc:creator>Ryan M.</dc:creator>
				<category><![CDATA[Development]]></category>
		<category><![CDATA[My Blog]]></category>
		<category><![CDATA[lmd]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[projects]]></category>

		<guid isPermaLink="false">http://www.rfxn.com/?p=917</guid>
		<description><![CDATA[The release of LMD 1.4.1 is now live and with it comes a few new features. In this small update, I have tried to deliver on on a couple of common feature requests from users which were in-line with my development goals. That said, right to it&#8230; The biggest change has come in the form <a href="http://www.rfxn.com/lmd-1-4-1-delivering-on-your-requests/" class="more-link">More &#62;</a>]]></description>
		<wfw:commentRss>http://www.rfxn.com/lmd-1-4-1-delivering-on-your-requests/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Linux Malware Detect: 2 Years Strong</title>
		<link>http://www.rfxn.com/linux-malware-detect-2-years-strong/</link>
		<comments>http://www.rfxn.com/linux-malware-detect-2-years-strong/#comments</comments>
		<pubDate>Thu, 06 Oct 2011 08:28:48 +0000</pubDate>
		<dc:creator>Ryan M.</dc:creator>
				<category><![CDATA[Development]]></category>
		<category><![CDATA[My Blog]]></category>
		<category><![CDATA[lmd]]></category>
		<category><![CDATA[malware]]></category>

		<guid isPermaLink="false">http://www.rfxn.com/?p=894</guid>
		<description><![CDATA[As cliche as it sounds, where has the time gone? Today we celebrate two years of Linux Malware Detect, open-source (web) malware detection. The project has seen allot of change since the first release. What was initially started as an internal project to deal with a large increase in malware activity at my job, a <a href="http://www.rfxn.com/linux-malware-detect-2-years-strong/" class="more-link">More &#62;</a>]]></description>
		<wfw:commentRss>http://www.rfxn.com/linux-malware-detect-2-years-strong/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
		<item>
		<title>LMD 1.4: Little Something For Everyone!</title>
		<link>http://www.rfxn.com/lmd-1-4-little-something-for-everyone/</link>
		<comments>http://www.rfxn.com/lmd-1-4-little-something-for-everyone/#comments</comments>
		<pubDate>Wed, 20 Apr 2011 05:25:50 +0000</pubDate>
		<dc:creator>Ryan M.</dc:creator>
				<category><![CDATA[Development]]></category>
		<category><![CDATA[bsd]]></category>
		<category><![CDATA[linux]]></category>
		<category><![CDATA[lmd]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[projects]]></category>
		<category><![CDATA[upgrade]]></category>

		<guid isPermaLink="false">http://www.rfxn.com/?p=870</guid>
		<description><![CDATA[The much awaited for 1.4 release of Linux Malware Detect is here! In this release there is quite literally something for everyone, from massive performance gains to FreeBSD support and everything in between . For those who wish to dive straight into it, you can run the -d or &#8211;update-ver option to update your install <a href="http://www.rfxn.com/lmd-1-4-little-something-for-everyone/" class="more-link">More &#62;</a>]]></description>
		<wfw:commentRss>http://www.rfxn.com/lmd-1-4-little-something-for-everyone/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>LMD 1.3.9r1: Hexdepth Bug</title>
		<link>http://www.rfxn.com/lmd-v1-3-9r1-hexdepth-bug/</link>
		<comments>http://www.rfxn.com/lmd-v1-3-9r1-hexdepth-bug/#comments</comments>
		<pubDate>Sun, 03 Apr 2011 04:18:51 +0000</pubDate>
		<dc:creator>Ryan M.</dc:creator>
				<category><![CDATA[Development]]></category>
		<category><![CDATA[My Blog]]></category>
		<category><![CDATA[bugs]]></category>
		<category><![CDATA[lmd]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[projects]]></category>

		<guid isPermaLink="false">http://www.rfxn.com/?p=844</guid>
		<description><![CDATA[I have put up a revision to the 1.3.9 release of LMD that fixes a hexdepth bug in which malware greater than 65Kbytes would cause an error in the internal hexstring.pl script and be considered clean on the stage2 hex scanning of malware. This would mean that unless malware had a MD5 signature for it <a href="http://www.rfxn.com/lmd-v1-3-9r1-hexdepth-bug/" class="more-link">More &#62;</a>]]></description>
		<wfw:commentRss>http://www.rfxn.com/lmd-v1-3-9r1-hexdepth-bug/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>LMD 1.3.9: Quietly Awesome</title>
		<link>http://www.rfxn.com/lmd-1-3-9-quietly-awesome/</link>
		<comments>http://www.rfxn.com/lmd-1-3-9-quietly-awesome/#comments</comments>
		<pubDate>Wed, 16 Mar 2011 08:20:20 +0000</pubDate>
		<dc:creator>Ryan M.</dc:creator>
				<category><![CDATA[Development]]></category>
		<category><![CDATA[My Blog]]></category>
		<category><![CDATA[lmd]]></category>
		<category><![CDATA[malware]]></category>

		<guid isPermaLink="false">http://www.rfxn.com/?p=781</guid>
		<description><![CDATA[It has been a busy couple of weeks for the LMD project, lots of late nights and sleepless days behind me and I can say I am a &#8216;little&#8217; happier with where things are in the project now This release has no major feature changes or additions other than a modification in the default hexdepth <a href="http://www.rfxn.com/lmd-1-3-9-quietly-awesome/" class="more-link">More &#62;</a>]]></description>
		<wfw:commentRss>http://www.rfxn.com/lmd-1-3-9-quietly-awesome/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Signature Updates &amp; Threat Database</title>
		<link>http://www.rfxn.com/signature-updates-threat-database/</link>
		<comments>http://www.rfxn.com/signature-updates-threat-database/#comments</comments>
		<pubDate>Thu, 16 Sep 2010 15:08:41 +0000</pubDate>
		<dc:creator>Ryan M.</dc:creator>
				<category><![CDATA[Development]]></category>
		<category><![CDATA[My Blog]]></category>
		<category><![CDATA[lmd]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[projects]]></category>

		<guid isPermaLink="false">http://www.rfxn.com/?p=677</guid>
		<description><![CDATA[It has been a very active month for those that pay attention to the signatures as they are released, you might have noticed a sudden spike about two weeks ago in signatures from 2,500&#8242;ish to the now 4,425 mark. The vast majority of these signatures were put up in MD5 format as a great many <a href="http://www.rfxn.com/signature-updates-threat-database/" class="more-link">More &#62;</a>]]></description>
		<wfw:commentRss>http://www.rfxn.com/signature-updates-threat-database/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Tracking &amp; Killing Bot Networks</title>
		<link>http://www.rfxn.com/tracking-killing-bot-networks/</link>
		<comments>http://www.rfxn.com/tracking-killing-bot-networks/#comments</comments>
		<pubDate>Tue, 17 Aug 2010 09:21:14 +0000</pubDate>
		<dc:creator>Ryan M.</dc:creator>
				<category><![CDATA[My Blog]]></category>
		<category><![CDATA[atf]]></category>
		<category><![CDATA[lmd]]></category>
		<category><![CDATA[malware]]></category>

		<guid isPermaLink="false">http://www.rfxn.com/?p=637</guid>
		<description><![CDATA[In a previous blog I discussed how one of the more enjoyable parts of my day-to-day malware rituals also involves the tracking and killing of command and control bot networks. Recently I have begun automating this process a bit; I have created a series of scripts that extract irc servers, port numbers and channels from <a href="http://www.rfxn.com/tracking-killing-bot-networks/" class="more-link">More &#62;</a>]]></description>
		<wfw:commentRss>http://www.rfxn.com/tracking-killing-bot-networks/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Signature Updates: Month In Review</title>
		<link>http://www.rfxn.com/signature-updates-month-in-review/</link>
		<comments>http://www.rfxn.com/signature-updates-month-in-review/#comments</comments>
		<pubDate>Sat, 24 Jul 2010 19:15:38 +0000</pubDate>
		<dc:creator>Ryan M.</dc:creator>
				<category><![CDATA[Development]]></category>
		<category><![CDATA[My Blog]]></category>
		<category><![CDATA[lmd]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[projects]]></category>

		<guid isPermaLink="false">http://www.rfxn.com/?p=611</guid>
		<description><![CDATA[Since I will be busy this coming week with other priorities, I am posting an early month in review blog on signature updates. In the last 3 weeks we have not seen a whole lot of action on in-the-wild malware, most of what is propagating at the moment are variants of already detected content. That <a href="http://www.rfxn.com/signature-updates-month-in-review/" class="more-link">More &#62;</a>]]></description>
		<wfw:commentRss>http://www.rfxn.com/signature-updates-month-in-review/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Signatures For The Masses</title>
		<link>http://www.rfxn.com/signatures-for-the-masses/</link>
		<comments>http://www.rfxn.com/signatures-for-the-masses/#comments</comments>
		<pubDate>Sun, 27 Jun 2010 01:06:25 +0000</pubDate>
		<dc:creator>Ryan M.</dc:creator>
				<category><![CDATA[Development]]></category>
		<category><![CDATA[lmd]]></category>
		<category><![CDATA[malware]]></category>

		<guid isPermaLink="false">http://www.rfxn.com/?p=579</guid>
		<description><![CDATA[Today I found the time and energy, despite how tedious it was, to go over the last two weeks worth of malware submissions and missed edge IPS data from when I was away. This resulted in a total of 126 new signatures (67 MD5 / 59 HEX) which brings LMD to a total of 2,471 <a href="http://www.rfxn.com/signatures-for-the-masses/" class="more-link">More &#62;</a>]]></description>
		<wfw:commentRss>http://www.rfxn.com/signatures-for-the-masses/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>I am Back: Signature Updates</title>
		<link>http://www.rfxn.com/i-am-back-signature-updates/</link>
		<comments>http://www.rfxn.com/i-am-back-signature-updates/#comments</comments>
		<pubDate>Thu, 24 Jun 2010 05:37:52 +0000</pubDate>
		<dc:creator>Ryan M.</dc:creator>
				<category><![CDATA[Development]]></category>
		<category><![CDATA[lmd]]></category>
		<category><![CDATA[malware]]></category>

		<guid isPermaLink="false">http://www.rfxn.com/?p=572</guid>
		<description><![CDATA[I am back, fresh off a trip home to Montreal, which I must say was an absolutely amazing time. It has left me reflecting on allot of things, most importantly that there really is no place like home &#8212; I miss Montreal more than I can even describe. That said though, time to get back <a href="http://www.rfxn.com/i-am-back-signature-updates/" class="more-link">More &#62;</a>]]></description>
		<wfw:commentRss>http://www.rfxn.com/i-am-back-signature-updates/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Linux Malware Detect v1.3.6: Loose Ends</title>
		<link>http://www.rfxn.com/linux-malware-detect-loose-ends/</link>
		<comments>http://www.rfxn.com/linux-malware-detect-loose-ends/#comments</comments>
		<pubDate>Mon, 24 May 2010 17:33:27 +0000</pubDate>
		<dc:creator>Ryan M.</dc:creator>
				<category><![CDATA[Development]]></category>
		<category><![CDATA[My Blog]]></category>
		<category><![CDATA[bugs]]></category>
		<category><![CDATA[linux]]></category>
		<category><![CDATA[lmd]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[projects]]></category>

		<guid isPermaLink="false">http://www.rfxn.com/?p=511</guid>
		<description><![CDATA[In LMD 1.3.3 there was allot of changes, 29 to be exact, that made LMD much more robust and especially the monitoring component, much more usable. If that release was about making good things better, then this release is about bringing loose ends together. I spent a couple of days running LMD through its paces <a href="http://www.rfxn.com/linux-malware-detect-loose-ends/" class="more-link">More &#62;</a>]]></description>
		<wfw:commentRss>http://www.rfxn.com/linux-malware-detect-loose-ends/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Linux Malware Detect v1.3.3: Making good things better</title>
		<link>http://www.rfxn.com/linux-malware-detect-v1-3-3-making-good-things-better/</link>
		<comments>http://www.rfxn.com/linux-malware-detect-v1-3-3-making-good-things-better/#comments</comments>
		<pubDate>Sat, 15 May 2010 06:45:27 +0000</pubDate>
		<dc:creator>Ryan M.</dc:creator>
				<category><![CDATA[Development]]></category>
		<category><![CDATA[lmd]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[projects]]></category>
		<category><![CDATA[upgrade]]></category>

		<guid isPermaLink="false">http://www.rfxn.com/?p=461</guid>
		<description><![CDATA[This morning I have put out LMD v1.3.3, this is on the back of two other successive releases in recent days that improved LMD in many areas, along with correcting some bugs that were graciously reported by those helping to break-in the project. I have also listened to feedback and revised a number of features <a href="http://www.rfxn.com/linux-malware-detect-v1-3-3-making-good-things-better/" class="more-link">More &#62;</a>]]></description>
		<wfw:commentRss>http://www.rfxn.com/linux-malware-detect-v1-3-3-making-good-things-better/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>LMD Signatures: RSS Feed &amp; XML</title>
		<link>http://www.rfxn.com/signature-updates-rss-feed/</link>
		<comments>http://www.rfxn.com/signature-updates-rss-feed/#comments</comments>
		<pubDate>Thu, 13 May 2010 00:40:50 +0000</pubDate>
		<dc:creator>Ryan M.</dc:creator>
				<category><![CDATA[Development]]></category>
		<category><![CDATA[lmd]]></category>
		<category><![CDATA[malware]]></category>

		<guid isPermaLink="false">http://www.rfxn.com/?p=446</guid>
		<description><![CDATA[While I was making some signature updates this afternoon, It occurred to me that it might be useful if the signatures were available through an RSS feed for update tracking or should anyone want to serialize the importing of my signature data into other applications. The signatures can be access in two data formats, the <a href="http://www.rfxn.com/signature-updates-rss-feed/" class="more-link">More &#62;</a>]]></description>
		<wfw:commentRss>http://www.rfxn.com/signature-updates-rss-feed/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Better Late Than Never: Linux Malware Detect 1.3</title>
		<link>http://www.rfxn.com/better-late-than-never-linux-malware-detect-1-3/</link>
		<comments>http://www.rfxn.com/better-late-than-never-linux-malware-detect-1-3/#comments</comments>
		<pubDate>Wed, 12 May 2010 05:13:23 +0000</pubDate>
		<dc:creator>Ryan M.</dc:creator>
				<category><![CDATA[Development]]></category>
		<category><![CDATA[My Blog]]></category>
		<category><![CDATA[linux]]></category>
		<category><![CDATA[lmd]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[projects]]></category>

		<guid isPermaLink="false">http://www.rfxn.com/?p=432</guid>
		<description><![CDATA[Today I have released Linux Malware Detect (LMD) 1.3, the first public stable release of my malware detection tool. The documentation is a little thin but the details are on the project page and the README file should fill you in on anything you need to know, otherwise you can post a comment on the <a href="http://www.rfxn.com/better-late-than-never-linux-malware-detect-1-3/" class="more-link">More &#62;</a>]]></description>
		<wfw:commentRss>http://www.rfxn.com/better-late-than-never-linux-malware-detect-1-3/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Out with the old, In with the new!</title>
		<link>http://www.rfxn.com/out-with-the-old-in-with-the-new/</link>
		<comments>http://www.rfxn.com/out-with-the-old-in-with-the-new/#comments</comments>
		<pubDate>Thu, 06 May 2010 07:25:11 +0000</pubDate>
		<dc:creator>Ryan M.</dc:creator>
				<category><![CDATA[My Blog]]></category>
		<category><![CDATA[apf]]></category>
		<category><![CDATA[atf]]></category>
		<category><![CDATA[bfd]]></category>
		<category><![CDATA[malware]]></category>

		<guid isPermaLink="false">http://www.rfxn.com/?p=310</guid>
		<description><![CDATA[The old theme was doing my head in, so I ditched it. Keep an eye out in the coming days/weeks for new releases of APF &#038; BFD in addition to a few more howto entries and the release of maldetect with a ATF stats landing page.]]></description>
		<wfw:commentRss>http://www.rfxn.com/out-with-the-old-in-with-the-new/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

