<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Malware Behavior Analysis: Zero Wine</title>
	<atom:link href="http://joxeankoret.com/blog/2008/12/28/malware-behavior-analysis-zero-wine/feed/" rel="self" type="application/rss+xml" />
	<link>http://joxeankoret.com/blog/2008/12/28/malware-behavior-analysis-zero-wine/</link>
	<description>Or maybe not</description>
	<lastBuildDate>Wed, 16 May 2012 06:40:59 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
	<item>
		<title>By: Samiam</title>
		<link>http://joxeankoret.com/blog/2008/12/28/malware-behavior-analysis-zero-wine/comment-page-1/#comment-78</link>
		<dc:creator>Samiam</dc:creator>
		<pubDate>Fri, 10 Jul 2009 15:47:23 +0000</pubDate>
		<guid isPermaLink="false">http://joxeankoret.com/blog/?p=33#comment-78</guid>
		<description>Intriguing.  I found this page while searching for information about analyzing (actually confirming) suspected exploited web sites from a VM.  I need what ZW can do, but I also need that capability.  If I installed one or more additional AV tools (ones that detect Trojan Droppers, etc. on web pages) into the ZW VM, could I do both tasks from this tool?  Thanks.  

-SAM</description>
		<content:encoded><![CDATA[<p>Intriguing.  I found this page while searching for information about analyzing (actually confirming) suspected exploited web sites from a VM.  I need what ZW can do, but I also need that capability.  If I installed one or more additional AV tools (ones that detect Trojan Droppers, etc. on web pages) into the ZW VM, could I do both tasks from this tool?  Thanks.  </p>
<p>-SAM</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Forensics</title>
		<link>http://joxeankoret.com/blog/2008/12/28/malware-behavior-analysis-zero-wine/comment-page-1/#comment-77</link>
		<dc:creator>Forensics</dc:creator>
		<pubDate>Tue, 16 Jun 2009 21:57:00 +0000</pubDate>
		<guid isPermaLink="false">http://joxeankoret.com/blog/?p=33#comment-77</guid>
		<description>Great work! Great setup and tool! Very good start to this project.  Just a thought of something perhaps to add to the project...

It would be very neat too if you incorporated Volatility and their python scripts into the project and allow you to parse through a lot of information on memory dumps too.  Processes any malware that might only be persistent in memory.  Just a thought! Keep up the good work.</description>
		<content:encoded><![CDATA[<p>Great work! Great setup and tool! Very good start to this project.  Just a thought of something perhaps to add to the project&#8230;</p>
<p>It would be very neat too if you incorporated Volatility and their python scripts into the project and allow you to parse through a lot of information on memory dumps too.  Processes any malware that might only be persistent in memory.  Just a thought! Keep up the good work.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Zero Wine &#124; PenTestIT</title>
		<link>http://joxeankoret.com/blog/2008/12/28/malware-behavior-analysis-zero-wine/comment-page-1/#comment-70</link>
		<dc:creator>Zero Wine &#124; PenTestIT</dc:creator>
		<pubDate>Thu, 26 Feb 2009 17:07:16 +0000</pubDate>
		<guid isPermaLink="false">http://joxeankoret.com/blog/?p=33#comment-70</guid>
		<description>[...] Malware Behavior Analysis: Zero Wine [...]</description>
		<content:encoded><![CDATA[<p>[...] Malware Behavior Analysis: Zero Wine [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Zero Wine: Malware Behavior Analysis</title>
		<link>http://joxeankoret.com/blog/2008/12/28/malware-behavior-analysis-zero-wine/comment-page-1/#comment-8</link>
		<dc:creator>Zero Wine: Malware Behavior Analysis</dc:creator>
		<pubDate>Sun, 04 Jan 2009 22:21:07 +0000</pubDate>
		<guid isPermaLink="false">http://joxeankoret.com/blog/?p=33#comment-8</guid>
		<description>[...] A new malware behaviour analysis tool called Zero Win has poped up. The tool was developed by Joxean Koret and released under GPL v2.0. Zero Wine uses [...]</description>
		<content:encoded><![CDATA[<p>[...] A new malware behaviour analysis tool called Zero Win has poped up. The tool was developed by Joxean Koret and released under GPL v2.0. Zero Wine uses [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: joxean</title>
		<link>http://joxeankoret.com/blog/2008/12/28/malware-behavior-analysis-zero-wine/comment-page-1/#comment-7</link>
		<dc:creator>joxean</dc:creator>
		<pubDate>Tue, 30 Dec 2008 18:24:53 +0000</pubDate>
		<guid isPermaLink="false">http://joxeankoret.com/blog/?p=33#comment-7</guid>
		<description>@Dinesh

Oops, sorry! For the user &quot;malware&quot; the password is &quot;malware&quot; and the root&#039;s password is zerowine.</description>
		<content:encoded><![CDATA[<p>@Dinesh</p>
<p>Oops, sorry! For the user &#8220;malware&#8221; the password is &#8220;malware&#8221; and the root&#8217;s password is zerowine.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ian Starkc</title>
		<link>http://joxeankoret.com/blog/2008/12/28/malware-behavior-analysis-zero-wine/comment-page-1/#comment-6</link>
		<dc:creator>Ian Starkc</dc:creator>
		<pubDate>Tue, 30 Dec 2008 15:53:01 +0000</pubDate>
		<guid isPermaLink="false">http://joxeankoret.com/blog/?p=33#comment-6</guid>
		<description>Cool work !!</description>
		<content:encoded><![CDATA[<p>Cool work !!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: joxean</title>
		<link>http://joxeankoret.com/blog/2008/12/28/malware-behavior-analysis-zero-wine/comment-page-1/#comment-5</link>
		<dc:creator>joxean</dc:creator>
		<pubDate>Tue, 30 Dec 2008 09:32:20 +0000</pubDate>
		<guid isPermaLink="false">http://joxeankoret.com/blog/?p=33#comment-5</guid>
		<description>@w0lf.

I think that it&#039;s possible, as well as it&#039;s possible with CWSandbox or Norman. However, you should run zerowine in a virtual machine in an isolated environment. Even if a specific and targeted malware finds a way to bypass the sandbox and exit from Wine, the malware must also exit from the virtual machine exploiting a 0day flaw with a low level (unprivileged) user so, it&#039;s highly unlikely.

However, it might be possible.</description>
		<content:encoded><![CDATA[<p>@w0lf.</p>
<p>I think that it&#8217;s possible, as well as it&#8217;s possible with CWSandbox or Norman. However, you should run zerowine in a virtual machine in an isolated environment. Even if a specific and targeted malware finds a way to bypass the sandbox and exit from Wine, the malware must also exit from the virtual machine exploiting a 0day flaw with a low level (unprivileged) user so, it&#8217;s highly unlikely.</p>
<p>However, it might be possible.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dinesh</title>
		<link>http://joxeankoret.com/blog/2008/12/28/malware-behavior-analysis-zero-wine/comment-page-1/#comment-4</link>
		<dc:creator>Dinesh</dc:creator>
		<pubDate>Tue, 30 Dec 2008 09:00:17 +0000</pubDate>
		<guid isPermaLink="false">http://joxeankoret.com/blog/?p=33#comment-4</guid>
		<description>Hi, What is the login id and password for the image?</description>
		<content:encoded><![CDATA[<p>Hi, What is the login id and password for the image?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: w0lf</title>
		<link>http://joxeankoret.com/blog/2008/12/28/malware-behavior-analysis-zero-wine/comment-page-1/#comment-3</link>
		<dc:creator>w0lf</dc:creator>
		<pubDate>Tue, 30 Dec 2008 06:09:48 +0000</pubDate>
		<guid isPermaLink="false">http://joxeankoret.com/blog/?p=33#comment-3</guid>
		<description>Nice work!!! But if the malware is able to bypass the sandbox restrictions, then the whole of the web server may be compromised. Targeted attack worms may be out where the attacker may upload them to zero wine website and then compromise the whole webserver. This may be a future scenario. Correct me if I am wrong.</description>
		<content:encoded><![CDATA[<p>Nice work!!! But if the malware is able to bypass the sandbox restrictions, then the whole of the web server may be compromised. Targeted attack worms may be out where the attacker may upload them to zero wine website and then compromise the whole webserver. This may be a future scenario. Correct me if I am wrong.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: New Sandbox - spamversand</title>
		<link>http://joxeankoret.com/blog/2008/12/28/malware-behavior-analysis-zero-wine/comment-page-1/#comment-2</link>
		<dc:creator>New Sandbox - spamversand</dc:creator>
		<pubDate>Mon, 29 Dec 2008 14:36:25 +0000</pubDate>
		<guid isPermaLink="false">http://joxeankoret.com/blog/?p=33#comment-2</guid>
		<description>[...] Honeypots Additionally to well known sandboxes like norman or CWsandbox there is a new one out: Zero Wine. A Python written malware analyzing tool, doing: &#8221; 1. Report: The complete raw report of all [...]</description>
		<content:encoded><![CDATA[<p>[...] Honeypots Additionally to well known sandboxes like norman or CWsandbox there is a new one out: Zero Wine. A Python written malware analyzing tool, doing: &#8221; 1. Report: The complete raw report of all [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>

