<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>JANET CSIRT</title>
	<atom:link href="http://www.ja.net/services/csirt/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ja.net/services/csirt</link>
	<description>Just another WordPress weblog</description>
	<lastBuildDate>Tue, 02 Mar 2010 13:48:16 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>JANET CSIRT is hiring</title>
		<link>http://www.ja.net/services/csirt/2010/03/02/janet-csirt-is-hiring/</link>
		<comments>http://www.ja.net/services/csirt/2010/03/02/janet-csirt-is-hiring/#comments</comments>
		<pubDate>Tue, 02 Mar 2010 13:48:16 +0000</pubDate>
		<dc:creator>James Davis</dc:creator>
				<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://www.ja.net/services/csirt/?p=284</guid>
		<description><![CDATA[A vacancy has arisen in the team. We are looking for someone with solid networking and security skills, with knowledge of Linux or Windows administration, and great communication skills to join our team. 
Further information on the job and the application process are available.
]]></description>
			<content:encoded><![CDATA[<p>A vacancy has arisen in the team. We are looking for someone with solid networking and security skills, with knowledge of Linux or Windows administration, and great communication skills to join our team. </p>
<p>Further <a href="http://www.ja.net/company/vacancies/vn316.html">information on the job</a> and the <a href="http://www.ja.net/company/vacancies/index.html">application process</a> are available.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ja.net/services/csirt/2010/03/02/janet-csirt-is-hiring/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>More on the University of Exeter outbreak</title>
		<link>http://www.ja.net/services/csirt/2010/01/29/more-on-the-university-of-exeter-outbreak/</link>
		<comments>http://www.ja.net/services/csirt/2010/01/29/more-on-the-university-of-exeter-outbreak/#comments</comments>
		<pubDate>Fri, 29 Jan 2010 17:01:11 +0000</pubDate>
		<dc:creator>James Davis</dc:creator>
				<category><![CDATA[Advisories]]></category>
		<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://www.ja.net/services/csirt/?p=277</guid>
		<description><![CDATA[We are now able to confirm that the malware infected systems through the vulnerability highlighted in our previous e-mail. Further details and an update for this Windows Vista vulnerability can be found at
http://support.microsoft.com/kb/975517
Microsoft and Symantec performed an analysis of the malware, and updated Symantec definitions now detect it as a generic &#8216;downloader&#8217;.
There is no reason [...]]]></description>
			<content:encoded><![CDATA[<p>We are now able to confirm that the malware infected systems through the vulnerability highlighted in our previous e-mail. Further details and an update for this Windows Vista vulnerability can be found at</p>
<p><a href="http://support.microsoft.com/kb/975517">http://support.microsoft.com/kb/975517</a></p>
<p>Microsoft and Symantec performed an analysis of the malware, and updated Symantec definitions now detect it as a generic &#8216;downloader&#8217;.</p>
<p>There is no reason to suspect that this malware poses a specific threat to other JANET connected sites, and we have not seen any infections elsewhere. It is worth mentioning a few best practices that limit your risk to this and similar infections:</p>
<p>- Ensure that operating systems are kept fully patched<br />
- Ensure that anti-virus definitions are kept up to date<br />
- By default, <a href="services/csirt/technical-advice/blocking-lan-service-ports/">block Windows LAN service ports</a> at your network border</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ja.net/services/csirt/2010/01/29/more-on-the-university-of-exeter-outbreak/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>University of Exeter malware outbreak</title>
		<link>http://www.ja.net/services/csirt/2010/01/21/university-of-exeter-malware-outbreak/</link>
		<comments>http://www.ja.net/services/csirt/2010/01/21/university-of-exeter-malware-outbreak/#comments</comments>
		<pubDate>Thu, 21 Jan 2010 12:03:25 +0000</pubDate>
		<dc:creator>James Davis</dc:creator>
				<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://www.ja.net/services/csirt/?p=275</guid>
		<description><![CDATA[As you may have heard the University of Exeter has been dealing with a malware outbreak. The virus appears to be unknown, certainly to Symantec and Trend, and was first detected by high levels of traffic on their network and onto JANET. Whilst the malware has not yet been analysed it appears to have aspects [...]]]></description>
			<content:encoded><![CDATA[<p>As you may have heard the University of Exeter has been dealing with a malware outbreak. The virus appears to be unknown, certainly to Symantec and Trend, and was first detected by high levels of traffic on their network and onto JANET. Whilst the malware has not yet been analysed it appears to have aspects of both a Trojan and a &#8220;dropper&#8221;.</p>
<p>The malware appears to exploit Windows Vista systems and early indications are that installing Microsoft update KB975517 prevents infection. It is not yet certain if the update provides complete protection.</p>
<p><a href="http://support.microsoft.com/kb/975517">http://support.microsoft.com/kb/975517</a></p>
<p>The outbreak is currently being investigated by Symantec and Microsoft and we hope to have further information within a few days.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ja.net/services/csirt/2010/01/21/university-of-exeter-malware-outbreak/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Vulnerability in Microsoft Internet Explorer</title>
		<link>http://www.ja.net/services/csirt/2010/01/20/vulnerability-in-microsoft-internet-explorer/</link>
		<comments>http://www.ja.net/services/csirt/2010/01/20/vulnerability-in-microsoft-internet-explorer/#comments</comments>
		<pubDate>Wed, 20 Jan 2010 14:35:41 +0000</pubDate>
		<dc:creator>James Davis</dc:creator>
				<category><![CDATA[Advisories]]></category>

		<guid isPermaLink="false">http://www.ja.net/services/csirt/?p=272</guid>
		<description><![CDATA[There are reports that targeted attacks are exploiting a vulnerability in Internet Explorer. A specially crafted HTML document allows a remote attacker to execute arbitrary code. This vulnerability exists in Internet Explorer 6,7 and 8, but Data Execution Protection (DEP) appears to provide protection to users of versions 7 and 8. This leaves users of [...]]]></description>
			<content:encoded><![CDATA[<p>There are reports that targeted attacks are exploiting a vulnerability in Internet Explorer. A specially crafted HTML document allows a remote attacker to execute arbitrary code. This vulnerability exists in Internet Explorer 6,7 and 8, but Data Execution Protection (DEP) appears to provide protection to users of versions 7 and 8. This leaves users of Internet Explorer 6 particularly exposed.</p>
<p>Whilst we are not aware of this vulnerability being widely used, the targeted nature of this attack may see it being used against particular sites. An update is not yet available, but Microsoft have released advice that may mitigate an attack. More details are available at:</p>
<p><a href="http://www.kb.cert.org/vuls/id/492515">http://www.kb.cert.org/vuls/id/492515</a><br />
<a href="http://www.microsoft.com/technet/security/advisory/979352.mspx">http://www.microsoft.com/technet/security/advisory/979352.mspx</a><br />
<a href="http://support.microsoft.com/kb/979352">http://support.microsoft.com/kb/979352</a></p>
<p>Microsoft yesterday announced that they plan to release an update for this issue outside of their normal patch scedule.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ja.net/services/csirt/2010/01/20/vulnerability-in-microsoft-internet-explorer/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Conficker statistics</title>
		<link>http://www.ja.net/services/csirt/2009/12/16/conficker-statistics/</link>
		<comments>http://www.ja.net/services/csirt/2009/12/16/conficker-statistics/#comments</comments>
		<pubDate>Wed, 16 Dec 2009 15:30:53 +0000</pubDate>
		<dc:creator>James Davis</dc:creator>
				<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://www.ja.net/services/csirt/?p=254</guid>
		<description><![CDATA[The Shadowserver Foundation have produced a set of statistics that detail the number of infections of the Conficker infections per ASN. The statistics for JANET (ASN 786) look promising. Bearing in mind that the large increase in infections coincides with the start of the academic year, and that numbers will start to naturally decrease towards [...]]]></description>
			<content:encoded><![CDATA[<p>The Shadowserver Foundation have <a href="http://www.shadowserver.org/wiki/pmwiki.php/Stats/Conficker">produced a set of statistics</a> that detail the number of infections of the Conficker infections per ASN. The statistics for JANET (ASN 786) look promising. Bearing in mind that the large increase in infections coincides with the start of the academic year, and that numbers will start to naturally decrease towards the holiday period, the overall trend still appears to be downward. The numbers are very favorable compared to similarly sized commercial providers.</p>
<p>JANET CSIRT have <a href="http://www.ja.net/services/csirt/technical-advice/conficker/">more information on Conficker</a>, how to detect and investigation infections and protect your network.</p>
<p><a href="http://www.shadowserver.org/wiki/uploads/Stats/conficker-asn-abc-180day-786.png"><img src="http://www.shadowserver.org/wiki/uploads/Stats/conficker-asn-abc-180day-786.png" alt="Image provided by shadowserver.org" /><br />
</a></p>
<p style="text-align: center;"><a href="http://www.shadowserver.org/wiki/uploads/Stats/conficker-asn-abc-180day-786.png">Image provided by Shadowserver.org</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.ja.net/services/csirt/2009/12/16/conficker-statistics/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Continued Phishing Attacks</title>
		<link>http://www.ja.net/services/csirt/2009/11/23/continued-phishing-attacks/</link>
		<comments>http://www.ja.net/services/csirt/2009/11/23/continued-phishing-attacks/#comments</comments>
		<pubDate>Mon, 23 Nov 2009 16:38:38 +0000</pubDate>
		<dc:creator>James Davis</dc:creator>
				<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://www.ja.net/services/csirt/?p=235</guid>
		<description><![CDATA[We continue to see a number of suprisingly successful phishing attacks against academic e-mail addresses. The attackers send their targets customised e-mails redirecting them to a professional looking website asking for their e-mail account details.
The current trend is for the website to be hosted with a third party company that provides free web forms to [...]]]></description>
			<content:encoded><![CDATA[<p>We continue to see a number of suprisingly successful phishing attacks against academic e-mail addresses. The attackers send their targets customised e-mails redirecting them to a professional looking website asking for their e-mail account details.</p>
<p>The current trend is for the website to be hosted with a third party company that provides free web forms to web site authors. The page is usually convincing but the URL is usually questionable. Please make sure that your users know that you will never ask them for their password, and how they can spot the more obvious fraudulent e-mails and URLs.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ja.net/services/csirt/2009/11/23/continued-phishing-attacks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Networkshop 2010 &#8211; Call for suggestions</title>
		<link>http://www.ja.net/services/csirt/2009/10/29/suggestions/</link>
		<comments>http://www.ja.net/services/csirt/2009/10/29/suggestions/#comments</comments>
		<pubDate>Thu, 29 Oct 2009 16:32:18 +0000</pubDate>
		<dc:creator>James Davis</dc:creator>
				<category><![CDATA[Events]]></category>

		<guid isPermaLink="false">http://www.ja.net/services/csirt/?p=145</guid>
		<description><![CDATA[There was a good selection of security, and security related talks at this year&#8217;s Networkshop; here&#8217;s an opportunity to help shape next year&#8217;s conference.
JANET(UK) is currently seeking input from the community on topic areas they would like to see covered at Networkshop 2010. The topics areas could include challenging areas, common issues/problems, work around ideas [...]]]></description>
			<content:encoded><![CDATA[<p>There was a good selection of security, and security related talks at this year&#8217;s Networkshop; here&#8217;s an opportunity to help shape next year&#8217;s conference.</p>
<p>JANET(UK) is currently seeking input from the community on topic areas they would like to see covered at Networkshop 2010. The topics areas could include challenging areas, common issues/problems, work around ideas etc for networking or in the provision of application services.</p>
<p>Please could you send your suggestions to <a href="mailto:rina.samani@ja.net">Rina Samani</a>. Closing date for suggestions is Thursday 5th November 2009.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ja.net/services/csirt/2009/10/29/suggestions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Remote code execution affecting Microsoft Vista, Windows 7 and Server 2008</title>
		<link>http://www.ja.net/services/csirt/2009/09/21/vulnerability-in-smb20/</link>
		<comments>http://www.ja.net/services/csirt/2009/09/21/vulnerability-in-smb20/#comments</comments>
		<pubDate>Mon, 21 Sep 2009 09:49:28 +0000</pubDate>
		<dc:creator>James Davis</dc:creator>
				<category><![CDATA[Advisories]]></category>

		<guid isPermaLink="false">http://www.ja.net/services/csirt/blog/?p=103</guid>
		<description><![CDATA[If your not doing it already, there is yet another good reason why blocking TCP port 445 is a good idea. A new exploit ( http://seclists.org/fulldisclosure/2009/Sep/0039.html ) has been made public which has been reported as causing a crash on Windows Server 2008 but we have not verified this, but we have tested it as [...]]]></description>
			<content:encoded><![CDATA[<p>If your not doing it already, there is yet another good reason why blocking TCP port 445 is a good idea. A new exploit ( <a href="http://seclists.org/fulldisclosure/2009/Sep/0039.html">http://seclists.org/fulldisclosure/2009/Sep/0039.html</a> ) has been made public which has been reported as causing a crash on Windows Server 2008 but we have not verified this, but we have tested it as affecting both Vista and Windows 7. In most cases the system will restart after the crash causing a DOS attack.</p>
<p>Other reports ( <a href="http://www.reversemode.com/index.php?option=com_mamblog&amp;Itemid=15&amp;task=show&amp;action=view&amp;id=64&amp;Itemid=15">http://www.reversemode.com/index.php?option=com_mamblog&amp;Itemid=15&amp;task=show&amp;action=view&amp;id=64&amp;Itemid=15</a> ) suggest that this causes more than a crash and it results in remote code execution, which if true usually lead to new forms of malware spreading very rapidly.</p>
<p>TCP port 445 is commonly used for Windows shares which is generally not required over the Internet, and is frequently utilised for spreading malware. A recent notable case being Conficker which would scan for and infect vulnerable systems on this port. There is no patch for this latest vulnerability and the only way to prevent remote attackers causing this exploit is to prevent them from accessing your systems on TCP port 445, this is usually done on firewalls.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ja.net/services/csirt/2009/09/21/vulnerability-in-smb20/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
