<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Philosophically Secure &#187; forensics</title>
	<atom:link href="http://eugk.net/wordpress/category/forensics/feed/" rel="self" type="application/rss+xml" />
	<link>http://eugk.net/wordpress</link>
	<description>Eugene Kogan&#039;s blog on information security and software engineering</description>
	<lastBuildDate>Thu, 12 Aug 2010 20:58:19 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Restoring trust in a compromised network</title>
		<link>http://eugk.net/wordpress/2008/11/16/restoring-trust-in-a-compromised-network/</link>
		<comments>http://eugk.net/wordpress/2008/11/16/restoring-trust-in-a-compromised-network/#comments</comments>
		<pubDate>Sun, 16 Nov 2008 21:39:24 +0000</pubDate>
		<dc:creator>eugenekogan</dc:creator>
				<category><![CDATA[forensics]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://eugk.net/wordpress/?p=170</guid>
		<description><![CDATA[If you know that you have a deeply compromised network, but you can&#8217;t practically shut it down and rebuild it from scratch, how do you go about cleaning it up and restoring trust in its use? This is a very difficult problem, and I would say that in most cases, it&#8217;s pretty much impossible to [...]]]></description>
		<wfw:commentRss>http://eugk.net/wordpress/2008/11/16/restoring-trust-in-a-compromised-network/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DojoSec miniconference</title>
		<link>http://eugk.net/wordpress/2008/10/02/dojosec-miniconference/</link>
		<comments>http://eugk.net/wordpress/2008/10/02/dojosec-miniconference/#comments</comments>
		<pubDate>Fri, 03 Oct 2008 01:58:11 +0000</pubDate>
		<dc:creator>eugenekogan</dc:creator>
				<category><![CDATA[forensics]]></category>

		<guid isPermaLink="false">http://eugk.net/wordpress/?p=152</guid>
		<description><![CDATA[I attended the first ever DojoSec minicon tonight, put on free of charge by Sun Tzu Data. The idea behind DojoSec is to have top-notch information security presentations come to our local area for one night each month. It&#8217;s kind of like bringing a small part of a security conference to your backyard. Both of [...]]]></description>
		<wfw:commentRss>http://eugk.net/wordpress/2008/10/02/dojosec-miniconference/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>iPhones have Eyes</title>
		<link>http://eugk.net/wordpress/2008/09/12/iphones-have-eyes/</link>
		<comments>http://eugk.net/wordpress/2008/09/12/iphones-have-eyes/#comments</comments>
		<pubDate>Fri, 12 Sep 2008 11:55:41 +0000</pubDate>
		<dc:creator>eugenekogan</dc:creator>
				<category><![CDATA[apple]]></category>
		<category><![CDATA[forensics]]></category>

		<guid isPermaLink="false">http://eugk.net/wordpress/2008/09/12/iphones-have-eyes/</guid>
		<description><![CDATA[Here&#8217;s an interesting story of unintended consequences. iPhone users, you know how when you press the Home button, the screen you&#8217;re looking at shrinks away as the main menu comes up? Well, that&#8217;s a pretty simple graphics trick to do, but it does require treating the current screen as an image. So, each time the [...]]]></description>
		<wfw:commentRss>http://eugk.net/wordpress/2008/09/12/iphones-have-eyes/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Software Reverse Engineering Tool Library</title>
		<link>http://eugk.net/wordpress/2008/01/02/collaborative-rce-tool-library/</link>
		<comments>http://eugk.net/wordpress/2008/01/02/collaborative-rce-tool-library/#comments</comments>
		<pubDate>Thu, 03 Jan 2008 00:40:51 +0000</pubDate>
		<dc:creator>eugenekogan</dc:creator>
				<category><![CDATA[forensics]]></category>
		<category><![CDATA[reversing]]></category>

		<guid isPermaLink="false">http://eugenekogan.net/wordpress/2008/01/02/collaborative-rce-tool-library/</guid>
		<description><![CDATA[This is pretty cool. It&#8217;s the new Collaborative RCE Tool Library, a nearly comprehensive directory of reverse engineering tools. Not only does it list the tools and provide links to download them, the directory also has pretty good descriptions and resources to learn more about each topic. The tools are conveniently sorted by target type [...]]]></description>
		<wfw:commentRss>http://eugk.net/wordpress/2008/01/02/collaborative-rce-tool-library/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Investigating a Linux zombie</title>
		<link>http://eugk.net/wordpress/2007/09/17/investigating-a-linux-zombie/</link>
		<comments>http://eugk.net/wordpress/2007/09/17/investigating-a-linux-zombie/#comments</comments>
		<pubDate>Mon, 17 Sep 2007 15:17:11 +0000</pubDate>
		<dc:creator>eugenekogan</dc:creator>
				<category><![CDATA[forensics]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[linux]]></category>

		<guid isPermaLink="false">http://eugenekogan.net/wordpress/2007/09/17/investigating-a-linux-zombie/</guid>
		<description><![CDATA[This blog post details a guy&#8217;s ad hoc investigation of a Linux server that was compromised and turned into a zombie. Basically, the &#8220;hacker&#8221; came in, installed a root kit, an SSH back door, and an IRC bot for command and control. The post gives all the steps that the &#8220;investigator&#8221; goes through, and provides [...]]]></description>
		<wfw:commentRss>http://eugk.net/wordpress/2007/09/17/investigating-a-linux-zombie/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
