<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>Updates of www.CERT.at</title>
    <link>http://www.cert.at</link>
    <description>This feed serves updates of www.CERT.at</description>
    <item>
      <title>(Services/Services) - Services</title>
      <link>http://www.cert.at/services/index/index_en.html</link>
      <description>&lt;h1&gt;Services&lt;/h1&gt;
Besides the &lt;a href="http://www.cert.at/warnings/all/ListPage1.html"&gt;warnings&lt;/a&gt; - which are only published in German language - and miscellaneous &lt;a href='http://www.cert.at/downloads/summary/summary_en.html'&gt;downloads&lt;/a&gt; there are still some more services CERT.at offers via this website.</description>
      <pubDate>Thu, 10 Sep 2009 11:31:12 GMT</pubDate>
      <guid>http://www.cert.at/services/index/index_en.html</guid>
      <dc:creator>CERT.at</dc:creator>
      <dc:date>2009-09-10T11:31:12Z</dc:date>
    </item>
    <item>
      <title>(Services/Feeds) - Feeds</title>
      <link>http://www.cert.at/services/feeds/feeds_en.html</link>
      <description>&lt;h1&gt;Feeds&lt;/h1&gt;

If you want to receive CERT.at's latest site-activities in your &lt;a href="http://en.wikipedia.org/wiki/Rss"&gt;RSS&lt;/a&gt;/&lt;a href="http://en.wikipedia.org/wiki/Atom_(standard)"&gt;Atom&lt;/a&gt; &lt;a href="http://en.wikipedia.org/wiki/Feedreader"&gt;Feed Reader&lt;/a&gt;
please choose:

&lt;h2&gt;Updates of www.CERT.at&lt;/h2&gt;
This feed serves all updates of www.CERT.at.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;img src="http://www.cert.at/static/icons/rss.png" style="border:0px;width:13px;" /&gt; RSS 2.0&lt;/b&gt; &lt;a href="http://www.cert.at/all_en.rss_2.0.xml"&gt;http://www.cert.at/all_en.rss_2.0.xml&lt;/a&gt;&lt;br /&gt;
&lt;b&gt;&lt;img src="http://www.cert.at/static/icons/atom.png" style="border:0px;width:13px;" /&gt; ATOM 1.0&lt;/b&gt; &lt;a href="http://www.cert.at/all_en.atom_1.0.xml"&gt;http://www.cert.at/all_en.atom_1.0.xml&lt;/a&gt;

&lt;h2&gt;CERT.at Downloads&lt;/h2&gt;
All CERT.at downloads as a feed.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;img src="http://www.cert.at/static/icons/rss.png" style="border:0px;width:13px;" /&gt; RSS 2.0&lt;/b&gt; &lt;a href="http://www.cert.at/all.downloads_en.rss_2.0.xml"&gt;http://www.cert.at/all.downloads_en.rss_2.0.xml&lt;/a&gt;&lt;br /&gt;
&lt;b&gt;&lt;img src="http://www.cert.at/static/icons/atom.png" style="border:0px;width:13px;" /&gt; ATOM 1.0&lt;/b&gt; &lt;a href="http://www.cert.at/all.downloads_en.atom_1.0.xml"&gt;http://www.cert.at/all.downloads_en.atom_1.0.xml&lt;/a&gt;</description>
      <pubDate>Thu, 15 Oct 2009 14:58:32 GMT</pubDate>
      <guid>http://www.cert.at/services/feeds/feeds_en.html</guid>
      <dc:creator>CERT.at</dc:creator>
      <dc:date>2009-10-15T14:58:32Z</dc:date>
    </item>
    <item>
      <title>(Services/Incident Report Form) - Incident report form</title>
      <link>http://www.cert.at/services/incident_report/incident_report_en.html</link>
      <description>&lt;h1&gt;Incident report form&lt;/h1&gt;

We propose that you use the following &lt;a href="http://www.cert.at/static/form.txt"&gt;form&lt;/a&gt; to guide you 
through the process of writing a helpful incident report.</description>
      <pubDate>Wed, 09 Sep 2009 14:57:09 GMT</pubDate>
      <guid>http://www.cert.at/services/incident_report/incident_report_en.html</guid>
      <dc:creator>CERT.at</dc:creator>
      <dc:date>2009-09-09T14:57:09Z</dc:date>
    </item>
    <item>
      <title>(Services/Links) - Links</title>
      <link>http://www.cert.at/services/links/links_en.html</link>
      <description>&lt;h1&gt;Links&lt;/h1&gt;
&lt;table width="100%" border=0 cellspacing="9" cellpadding="0"&gt;
	&lt;tr&gt;
        &lt;td&gt;
		    &lt;a href="https://www.buerger-cert.de/default.aspx"&gt;
		    	&lt;img src="http://www.cert.at/static/otherlogos/bsi.png" border="0" 
		    	     alt="BSI / Bürger-CERT" /&gt;
		   	&lt;/a&gt;
       	&lt;/td&gt;
		&lt;td&gt;
			BSI advisories regarding miscellaneous vulnerabilities&lt;br /&gt;
			(german)
		&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr&gt;
        &lt;td&gt;
		    &lt;a href="http://www.kb.cert.org/vuls/"&gt;
		    	&lt;img src="http://www.cert.at/static/otherlogos/certcc.png" border="0" 
		    	     alt="CERT.org" /&gt;
		   	&lt;/a&gt;
       	&lt;/td&gt;
		&lt;td&gt;
			US-CERT advisories regarding miscellaneous vulnerabilities&lt;br /&gt;
			(english)
		&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr&gt;&lt;td colspan=2&gt;&lt;hr /&gt;&lt;/td&gt;&lt;/tr&gt;
	&lt;tr&gt;
        &lt;td&gt;
		    &lt;a href="http://www.heise.de/security"&gt;
		    	&lt;img src="http://www.cert.at/static/otherlogos/heise.png" border="0" 
		    	     alt="Heise" /&gt;
		   	&lt;/a&gt;
       	&lt;/td&gt;
		&lt;td&gt;
			IT-Security advisories with marks for alerts&lt;br /&gt;
			(german)
		&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr&gt;
        &lt;td&gt;
		    &lt;a href="http://secunia.com/advisories/"&gt;
		    	&lt;img src="http://www.cert.at/static/otherlogos/secunia.png" border="0" 
		    	     alt="Secunia" /&gt;
		   	&lt;/a&gt;
       	&lt;/td&gt;
		&lt;td&gt;
			Advisories regarding miscellaneous vulnerabilities with priority-tags&lt;br /&gt;
			(german)
		&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr&gt;
        &lt;td&gt;
		    &lt;a href="http://isc.sans.org/"&gt;
		    	&lt;img src="http://www.cert.at/static/otherlogos/isc.png" border="0" 
		    	     alt="Internet Storm Center" /&gt;
		   	&lt;/a&gt;
       	&lt;/td&gt;
		&lt;td&gt;
			Advisories regarding miscellaneous vulnerabilities and SANS interpretation of the actual level of global security&lt;br /&gt;
			(english)
		&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr&gt;
        &lt;td&gt;
		    &lt;a href="http://www.securityfocus.com/vulnerabilities"&gt;
		    	&lt;img src="http://www.cert.at/static/otherlogos/securityfocus.png" border="0" 
		    	     alt="SecurityFocus" /&gt;
		   	&lt;/a&gt;
       	&lt;/td&gt;
		&lt;td&gt;
			Advisories regarding miscellaneous actual vulnerabilities&lt;br /&gt;
			(english)
		&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr&gt;&lt;td colspan=2&gt;&lt;hr /&gt;&lt;/td&gt;&lt;/tr&gt;
	&lt;tr&gt;
        &lt;td&gt;
		    &lt;a href="http://www.microsoft.com/technet/security/current.aspx"&gt;
		    	&lt;img src="http://www.cert.at/static/otherlogos/microsoft.png" border="0" 
		    	     alt="Microsoft Security Bulletins" /&gt;
		   	&lt;/a&gt;
       	&lt;/td&gt;
		&lt;td&gt;
			Advisories regarding miscellaneous actual vulnerabilities in Microsoft products&lt;br /&gt;
			(english)
		&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr&gt;
        &lt;td&gt;
		    &lt;a href="http://support.apple.com/kb/HT1222?viewlocale=de_DE"&gt;
		    	&lt;img src="http://www.cert.at/static/otherlogos/apple.png" border="0" 
		    	     alt="Apple" /&gt;
		   	&lt;/a&gt;
       	&lt;/td&gt;
		&lt;td&gt;
			Advisories regarding miscellaneous actual vulnerabilities in Apple products&lt;br /&gt;
			(german)
		&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr&gt;
        &lt;td&gt;
		    &lt;a href="http://www.debian.org/security/"&gt;
		    	&lt;img src="http://www.cert.at/static/otherlogos/debian.png" border="0" 
		    	     alt="Debian" /&gt;
		   	&lt;/a&gt;
       	&lt;/td&gt;
		&lt;td&gt;
			Advisories regarding miscellaneous actual vulnerabilities in software relating to Debian GNU/Linux&lt;br /&gt;
			(english)
		&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr&gt;
        &lt;td&gt;
		    &lt;a href="http://rhn.redhat.com/errata/"&gt;
		    	&lt;img src="http://www.cert.at/static/otherlogos/redhat.png" border="0" 
		    	     alt="Redhat" /&gt;
		   	&lt;/a&gt;
       	&lt;/td&gt;
		&lt;td&gt;
			Advisories regarding miscellaneous actual vulnerabilities in software relating to Red Hat&lt;br /&gt;
			(english)
		&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr&gt;
        &lt;td&gt;
		    &lt;a href="http://www.novell.com/linux/security/advisories.html"&gt;
		    	&lt;img src="http://www.cert.at/static/otherlogos/suse.png" border="0" 
		    	     alt="Suse" /&gt;
		   	&lt;/a&gt;
       	&lt;/td&gt;
		&lt;td&gt;
			Advisories regarding miscellaneous actual vulnerabilities in software relating to SUSE Linux Enterprise&lt;br /&gt;
			(english)
		&lt;/td&gt;
	&lt;/tr&gt;
&lt;/table&gt;</description>
      <pubDate>Thu, 24 Sep 2009 10:17:44 GMT</pubDate>
      <guid>http://www.cert.at/services/links/links_en.html</guid>
      <dc:creator>CERT.at</dc:creator>
      <dc:date>2009-09-24T10:17:44Z</dc:date>
    </item>
    <item>
      <title>(Downloads/Summary) - Downloads</title>
      <link>http://www.cert.at/downloads/summary/summary_en.html</link>
      <description>&lt;h1&gt;Downloads&lt;/h1&gt;
In this area of our homepage we offer you material for free download. Please read the related licence agreements.
&lt;p /&gt;
Downloads which are only available in German language will be shortly mentioned in the English area as well, but the full description and the download-link itself will only be found in the German area.
&lt;p /&gt;
These are the available categories for downloads:
&lt;h2&gt;Data&lt;/h2&gt;
Here you'll find files that contain information for the purpose of being read by machines (i.e.: configuration files).
&lt;h2&gt;Papers&lt;/h2&gt;
This area contains all papers that have been published by CERT.at so far.
&lt;h2&gt;Press&lt;/h2&gt;
This is the place for all material that are of typical use for the public press (i.e.: CERT.at's logo).
&lt;h2&gt;Software&lt;/h2&gt;
"Open" software with its root in CERT.at's daily work will be found here, including descriptions.
&lt;!--h2&gt;Grouped by topic&lt;/h2&gt;
This special area bundles all the downloads being spread over the categories that are sharing the same topic as a list of links. The corresponding descriptions, though, will still be found under the detail-categories.--&gt;</description>
      <pubDate>Thu, 24 Sep 2009 10:13:22 GMT</pubDate>
      <guid>http://www.cert.at/downloads/summary/summary_en.html</guid>
      <dc:creator>CERT.at</dc:creator>
      <dc:date>2009-09-24T10:13:22Z</dc:date>
    </item>
    <item>
      <title>(Downloads/Papers) - An Analysis of the Skype IMBot Logic and Functionality</title>
      <link>http://www.cert.at/downloads/papers/skype_imbot_en.html</link>
      <description>&lt;h1&gt;An Analysis of the Skype IMBot Logic and Functionality&lt;/h1&gt;
2010/03/08
&lt;p /&gt;
An Analysis of the Skype IMBot Logic and Functionality. 
&lt;!--more--&gt;

&lt;hr /&gt;

&lt;div style="float:right;text-align:right;"&gt;
	&lt;a class="pdf" href="http://www.cert.at/static/downloads/papers/cert.at-an_analysis_of_the_skype_imbot_logic_and_functionality_1.2.pdf"&gt;Download&lt;/a&gt;
&lt;/div&gt;

&lt;h2&gt;Publication Date&lt;/h2&gt;
March, 08th 2010

&lt;h2&gt;Author&lt;/h2&gt;
Christian Wojner, L. Aaron Kaplan

&lt;h2&gt;Language&lt;/h2&gt;
English

&lt;h2&gt;History&lt;/h2&gt;
You can download the full document in pdf format
&lt;a href="http://www.cert.at/static/downloads/papers/cert.at-an_analysis_of_the_skype_imbot_logic_and_functionality_1.2.pdf"&gt;here&lt;/a&gt;.

&lt;hr /&gt;

&lt;h2&gt;Content&lt;/h2&gt;
The following report analyzes the Skype Instant Messenger Bot ("Skype IMBot", a variation of the W32.Nytemare trojan) and reports our reverse engineering efforts. One peculiar aspect of Skype IMBot was the way it controlled Skype (and other Instant Messengers) - simulating user input and user keystrokes. This reminded us of a limited Turing Test: did the malware or a true user send the URL? 

The report covers the reverse engineering of the Skype IMbot, network logic and recommendations to CERTs, users and Skype. It closed with an outlook on further instant messenger bots.</description>
      <pubDate>Mon, 08 Mar 2010 13:12:20 GMT</pubDate>
      <guid>http://www.cert.at/downloads/papers/skype_imbot_en.html</guid>
      <dc:creator>CERT.at</dc:creator>
      <dc:date>2010-03-08T13:12:20Z</dc:date>
    </item>
    <item>
      <title>(Downloads/Papers) - Mass Malware Analysis: A Do-It-Yourself Kit</title>
      <link>http://www.cert.at/downloads/papers/mass_malware_analysis_en.html</link>
      <description>&lt;h1&gt;Mass Malware Analysis: A Do-It-Yourself Kit&lt;/h1&gt;
2009/10/14
&lt;p /&gt;
Theory, practice and a construction manual for an automated analysis station for malware using trivial and free instruments.
&lt;!--more--&gt;

&lt;hr /&gt;

&lt;div style="float:right;text-align:right;"&gt;
	&lt;a class="pdf" href="http://www.cert.at/static/downloads/papers/cert.at-mass_malware_analysis_1.0.pdf"&gt;Download&lt;/a&gt;
&lt;/div&gt;

&lt;h2&gt;Publication Date&lt;/h2&gt;
October, 14th 2009

&lt;h2&gt;Author&lt;/h2&gt;
Christian Wojner

&lt;h2&gt;Language&lt;/h2&gt;
English

&lt;h2&gt;History&lt;/h2&gt;
You can download the full document in pdf format
&lt;a href="http://www.cert.at/static/downloads/papers/cert.at-mass_malware_analysis_1.0.pdf"&gt;here&lt;/a&gt;.

&lt;hr /&gt;

&lt;h2&gt;Content&lt;/h2&gt;
This paper outlines the relevant steps to build up a customizable automated malware analysis station 
by using only freely available components with the exception of the target OS (Windows XP) itself. 
Further a special focus lies in handling a huge amount of malware samples and the actual implementation 
at CERT.at. As primary goal the reader of this paper should be able to build up her own specific 
installation and configuration while being free in her decision which components to use.
&lt;p /&gt;
The first part of this document will cover all the theoretical, strategic and methodological aspects. 
The second part is focusing on the practical aspects by diving into CERT.at's automated malware analysis 
station closing with an easy to follow step-by-step tutorial, how to build up CERT.at's implementation 
for your own use. So feel free to skip parts.</description>
      <pubDate>Wed, 14 Oct 2009 15:29:37 GMT</pubDate>
      <guid>http://www.cert.at/downloads/papers/mass_malware_analysis_en.html</guid>
      <dc:creator>CERT.at</dc:creator>
      <dc:date>2009-10-14T15:29:37Z</dc:date>
    </item>
    <item>
      <title>(Downloads/Papers) - Detecting Conficker in your Network</title>
      <link>http://www.cert.at/downloads/papers/confickerdetection_en.html</link>
      <description>&lt;h1&gt;Detecting Conficker in your Network&lt;/h1&gt;
2009/02/11
&lt;p /&gt;
Description of a method to detect earlystate Conficker worm infections through blocklists
fitting the needs of small and medium enterprises.
&lt;!--more--&gt;

&lt;hr /&gt;

&lt;div style="float:right;text-align:right;"&gt;
	&lt;a class="pdf" href="http://www.cert.at/static/downloads/papers/TR_Conficker_Detection.pdf"&gt;Download&lt;/a&gt;
&lt;/div&gt;

&lt;h2&gt;Publication Date&lt;/h2&gt;
2009/02/11

&lt;h2&gt;Author&lt;/h2&gt;
Adi Kriegisch

&lt;h2&gt;Language&lt;/h2&gt;
English

&lt;h2&gt;Download&lt;/h2&gt;
You can download the full document in pdf format &lt;a href="http://www.cert.at/static/downloads/papers/TR_Conficker_Detection.pdf"&gt;here&lt;/a&gt;.

&lt;hr /&gt;

&lt;h2&gt;Content&lt;/h2&gt;
Conficker is a computer worm spreading on Windows operating system by mainly
using a buffer overflow or the Windows Autorun feature. The worm itself does not contain
malware functions but contains a routine to load such code after infection. The purpose of
this article is to sketch a way to detect such a worm in a small to medium business network
as early as possible so that the effects of the worm can be minimized.</description>
      <pubDate>Thu, 17 Sep 2009 13:18:01 GMT</pubDate>
      <guid>http://www.cert.at/downloads/papers/confickerdetection_en.html</guid>
      <dc:creator>CERT.at</dc:creator>
      <dc:date>2009-09-17T13:18:01Z</dc:date>
    </item>
    <item>
      <title>(Downloads/Papers) - Patching Nameservers: Austria reacts to VU#800113</title>
      <link>http://www.cert.at/downloads/papers/0802_en.html</link>
      <description>&lt;h1&gt;Patching Nameservers: Austria reacts to VU#800113&lt;/h1&gt;
2008/07/24
&lt;p /&gt;
A report on the patch-rate of Austrian nameservers 
following announcement of the DNS cache poisoning vulnerabilty.
&lt;!--more--&gt;

&lt;hr /&gt;

&lt;div style="float:right;text-align:right;"&gt;
	&lt;a class="pdf" href="http://www.cert.at/static/downloads/papers/cert.at-0802-DNS-patchanalysis.pdf"&gt;Download Original&lt;/a&gt;
	&lt;p /&gt;
	&lt;a class="pdf" href="http://www.cert.at/static/downloads/papers/cert.at-0802bis-DNS-patchanalysis-update.pdf"&gt;Download Update&lt;/a&gt;
&lt;/div&gt;

&lt;h2&gt;Publication Date&lt;/h2&gt;
July, 24th 2008

&lt;h2&gt;Authors&lt;/h2&gt;
Otmar Lendl and L. Aaron Kaplan

&lt;h2&gt;Language&lt;/h2&gt;
English

&lt;h2&gt;History&lt;/h2&gt;
You can download the full document in pdf format
&lt;a href="http://www.cert.at/static/downloads/papers/cert.at-0802-DNS-patchanalysis.pdf"&gt;here&lt;/a&gt;.
&lt;p&gt;
We also published a &lt;a href="http://www.cert.at/static/downloads/papers/cert.at-0802bis-DNS-patchanalysis-update.pdf"&gt;short update&lt;/a&gt; on July 28th.

&lt;hr /&gt;

&lt;h2&gt;Content&lt;/h2&gt;
This paper analyses the impact of the coordinated efforts to patch Austria's recursive DNS server 
infrastructure following the revealings of Dan Kaminsky (US-CERT VU#800113) which showed 
that almost all DNS servers on the Internet are vulnerable to DNS cache poisoning.  CERT.at -- 
being run by nic.at, the Austrian domain registry -- is in a special position to be able to assess the 
reaction of the Austrian nameserver operators to the discovered DNS vulnerability. We analyzed the 
rate at which DNS servers were patched from an insecure to more secure state. The paper discusses 
a methodology to measure the patch level "score" of a recursive DNS server. We believe that this 
score methodology can be applied to cleanly discern patched from unpatched DNS servers.
&lt;p /&gt;
We describe a methodology how a TLD operator can use his query logs to check which operators 
have patched their DNS resolvers according to the published advisories. 
&lt;p /&gt;
The conclusions are rather grim so far -- more than two thirds of the Austrian Internet's recursive 
DNS servers are unpatched while at the same time the upgrade adoption rate seems rather slow. 
Our findings are matched by the observations of Alexander Klink of Cynops GmbH who analyzed 
the results of the online vulnerability test on Dan Kaminsky's doxpara site. 
&lt;p /&gt;
We hereby present the information to the concerned public in the  hope that DNS -- a central and 
crucial part of the Internet -- remains secure.
&lt;p /&gt;
Our recommendation to IT system administrators is to update their recursive DNS servers 
immediately and check that their upgrades were successful.
&lt;p /&gt;</description>
      <pubDate>Thu, 24 Sep 2009 10:04:43 GMT</pubDate>
      <guid>http://www.cert.at/downloads/papers/0802_en.html</guid>
      <dc:creator>CERT.at</dc:creator>
      <dc:date>2009-09-24T10:04:43Z</dc:date>
    </item>
    <item>
      <title>(Downloads/Software) - Bytehist</title>
      <link>http://www.cert.at/downloads/software/bytehist_en.html</link>
      <description>&lt;h1&gt;Bytehist&lt;/h1&gt;
A tool for generating byte-usage-histograms for all types of files with a special focus on binary executables in  PE-format (Windows).
&lt;!--more--&gt;

&lt;hr /&gt;

&lt;div style="float:right;text-align:right;"&gt;
	&lt;a class="zip" href="http://www.cert.at/static/downloads/software/bytehist/windows/bytehist_beta_1.zip"&gt;Download latest Windows version&lt;/a&gt;
	&lt;p /&gt;
	&lt;a class="zip" href="http://www.cert.at/static/downloads/software/bytehist/linux/bytehist_beta_1.zip"&gt;Download latest Linux version&lt;/a&gt;
&lt;/div&gt;

&lt;h2&gt;Author&lt;/h2&gt;
Christian Wojner

&lt;h2&gt;Language&lt;/h2&gt;
English

&lt;h2&gt;License&lt;/h2&gt;
&lt;a href="http://en.wikipedia.org/wiki/ISC_license"&gt;ISCL&lt;/a&gt;

&lt;table cellpadding=0 cellspacing=0&gt;
	&lt;tr&gt;
		&lt;td&gt;&lt;h2&gt;Releases&lt;/h2&gt;&lt;/a&gt;&lt;/td&gt;
		&lt;td style="padding-left:20px;width:100%;"&gt;&lt;h2&gt;Changes&lt;/h2&gt;&lt;/a&gt;&lt;/td&gt;
		&lt;td style="padding-left:20px;text-align:center;"&gt;&lt;img src="http://www.cert.at/static/icons/icon_windows_small.gif" /&gt;&lt;/td&gt;
		&lt;td style="padding-left:20px;text-align:center;"&gt;&lt;img src="http://www.cert.at/static/icons/icon_linux_small.gif" /&gt;&lt;/td&gt;
		&lt;td style="padding-left:20px;text-align:center;"&gt;&lt;img src="http://www.cert.at/static/icons/icon_apple_small.gif" /&gt;&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr&gt;
		&lt;td nowrap&gt;1.0 beta 1&lt;/td&gt;
		&lt;td style="padding-left:20px"&gt;-&lt;/td&gt;
		&lt;td style="padding-left:20px;text-align:center;"&gt;&lt;a class="zip" href="http://www.cert.at/static/downloads/software/bytehist/windows/bytehist_beta_1.zip"&gt;&amp;nbsp;&lt;/a&gt;&lt;/td&gt;
		&lt;td style="padding-left:20px;text-align:center;"&gt;&lt;a class="zip" href="http://www.cert.at/static/downloads/software/bytehist/linux/bytehist_beta_1.zip"&gt;&amp;nbsp;&lt;/a&gt;&lt;/td&gt;
		&lt;td style="padding-left:20px;text-align:center;"&gt;x&lt;/td&gt;
	&lt;/tr&gt;
&lt;/table&gt;

&lt;hr /&gt;

&lt;h2&gt;Features&lt;/h2&gt;
&lt;ul&gt;
	&lt;li&gt;Makes byte-usage-histograms of any file of any size&lt;/li&gt;
	&lt;li&gt;Histograms are generated as sorted and unsorted diagrams&lt;/li&gt;
	&lt;li&gt;Sub-histograms for each section of binary executables (PE)&lt;/li&gt;
	&lt;li&gt;Quick overview with GUI navigation in case of sub-histograms&lt;/li&gt;
	&lt;li&gt;Percentage for the share in the total filesize for sub-histograms&lt;/li&gt;
	&lt;li&gt;Sourcerelated names for sub-histograms (= section-names in case of PEs)&lt;/li&gt;
	&lt;li&gt;Results can be saved as .jpg, .bmp and .png files&lt;/li&gt;
	&lt;li&gt;Works as GUI and also as commandline tool (for scripting purposes)&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Syntax&lt;/h2&gt;
&lt;tt&gt;bytehist [&lt;i&gt;options&lt;/i&gt; &lt;i&gt;file&lt;/i&gt;]&lt;/tt&gt;
&lt;p /&gt;
Executing &lt;i&gt;bytehist&lt;/i&gt; without any parameters activates full GUI-mode.&lt;p /&gt;
&lt;table style="margin-left:-3px"&gt;
	&lt;tr&gt;&lt;td&gt;&lt;i&gt;options&lt;/i&gt;: &lt;/td&gt;&lt;td&gt;-nogui&lt;/td&gt;&lt;td&gt;... don't bring up any GUI&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;/tr&gt;
	&lt;tr&gt;&lt;td&gt;&lt;/td&gt;&lt;td&gt;-save file&lt;/td&gt;&lt;td&gt;... save histogram to given file (bmp, png or jpg)&lt;/td&gt;&lt;/tr&gt;
	&lt;tr&gt;&lt;td&gt;&lt;/td&gt;&lt;td&gt;-h&lt;/td&gt;&lt;td&gt;... show a short help&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;

&lt;h2&gt;Description&lt;/h2&gt;
Statistics can be a very good method if you want to detect encrypted or packed data. Data that has been manipulated in such a way usually comes up with a very even distribution of bytes being used. In contrast &lt;i&gt;normal&lt;/i&gt; data typically has some bytes that are used constantly, which is caused by any kind of structures. So the byte-distribution of unencrypted and unpacked clear text, database-files, ... and even executable binaries differ massevily from the encrypted and/or packed ones. By putting this "phenomenon" into a picture this difference can be easily visualized by histograms.
&lt;p /&gt;
&lt;span style="vertical-align:top"&gt;Examples:&lt;/span&gt;&lt;br&gt;
&lt;a href="http://www.cert.at/static/downloads/software/bytehist/example_unpacked_file.jpg"&gt;
	&lt;img src="http://www.cert.at/static/downloads/software/bytehist/example_unpacked_file.jpg" style="width:50px" border=0 /&gt;
&lt;/a&gt;
&lt;a href="http://www.cert.at/static/downloads/software/bytehist/example_packed_archive.jpg"&gt;
	&lt;img src="http://www.cert.at/static/downloads/software/bytehist/example_packed_archive.jpg" style="width:50px" border=0 /&gt;
&lt;/a&gt;
&lt;p /&gt;
The first example shows an unpacked file. In fact the source of this histogram was a log-file - so that's human readable information.&lt;br&gt;
The second example roots in an usual ZIP-archive.&lt;br&gt;
So as formerly said, to see the difference between them is an easy one.
&lt;p /&gt;
Let's take a closer look at these examples. Both of them have a green and a red section. In the green section every pixel-column complies to it's positional matching bytecode and visualizes the number of occurrences in a vertical bar. In other words, a tall green bar on the most left side tells us that the byte-code 0h had lots of occurrences. And on the most right side you'll find byte-code FFh.&lt;br&gt;
The red section has the same roots like the green section but this time we got all the possible byte-codes in a descending order regarding their occurrences. This makes it much easier to see the evenness.&lt;br&gt;
Besides that two sections you'll also find the filename being shown on the top right corner and a percentage.&lt;br&gt;
&lt;br&gt;
To get an understanding for what this percentage is trying to tell, let's take a look at what more &lt;i&gt;bytehist&lt;/i&gt; can do for us. &lt;i&gt;bytehist&lt;/i&gt; can split up histograms in sub-histograms. At the moment the most senseful situation of providing sub-histograms is when you have to deal with binary executables. Binary executables are usually internally split up in a number of sections. There are sections for containing data, code, and so on. It is a common approach that executables are being packed or/and even encrypted before they get publicly rolled out. Especially in the malware-sector encryption and packing is massively used as a kind of hurdle to hinder deep analysis through reversing (i.e.). So, in the case of a binary executable in PE format - that's the one Microsoft Windows uses - &lt;i&gt;bytehist&lt;/i&gt; will come up with an overall-histogram as well as providing one histogram per section it found and even one for possible rest behind the last section. Regarding the percentage the overall-histogram will still say "100%" but all the others will tell the percentage of their specific share in the total filesize.
&lt;p /&gt;
&lt;span style="vertical-align:top"&gt;Examples:&lt;/span&gt;&lt;br&gt;
&lt;a href="http://www.cert.at/static/downloads/software/bytehist/example_unpacked_executable.jpg"&gt;
	&lt;img src="http://www.cert.at/static/downloads/software/bytehist/example_unpacked_executable.jpg" style="width:50px" border=0 /&gt;
&lt;/a&gt;
&lt;a href="http://www.cert.at/static/downloads/software/bytehist/example_packed_executable.jpg"&gt;
	&lt;img src="http://www.cert.at/static/downloads/software/bytehist/example_packed_executable.jpg" style="width:50px" border=0 /&gt;
&lt;/a&gt;
&lt;p /&gt;
Both of the examples have a scrollarea on the right side showing thumbs of the relating (sub-)histogram. By clicking them with the left mouse-button they can be zoomed. Once again we have firstly an unpacked and secondly a packed file, but this time, binary executables.
&lt;p /&gt;
This feature gives a reverser the possibility to instantly find out the section that's containing (if so) packed/encrypted data.
&lt;p /&gt;
Full examples ...
&lt;p /&gt;
&lt;span style="vertical-align:top"&gt;Packed data behind sections:&lt;/span&gt;&lt;br&gt;
&lt;a href="http://www.cert.at/static/downloads/software/bytehist/test.png"&gt;
	&lt;img src="http://www.cert.at/static/downloads/software/bytehist/test.png" style="width:50px" border=0 /&gt;
&lt;/a&gt;
&lt;a href="http://www.cert.at/static/downloads/software/bytehist/test.sec01.CODE.png"&gt;
	&lt;img src="http://www.cert.at/static/downloads/software/bytehist/test.sec01.CODE.png" style="width:50px" border=0 /&gt;
&lt;/a&gt;
&lt;a href="http://www.cert.at/static/downloads/software/bytehist/test.sec02.DATA.png"&gt;
	&lt;img src="http://www.cert.at/static/downloads/software/bytehist/test.sec02.DATA.png" style="width:50px" border=0 /&gt;
&lt;/a&gt;
&lt;a href="http://www.cert.at/static/downloads/software/bytehist/test.sec03.BSS.png"&gt;
	&lt;img src="http://www.cert.at/static/downloads/software/bytehist/test.sec03.BSS.png" style="width:50px" border=0 /&gt;
&lt;/a&gt;
&lt;a href="http://www.cert.at/static/downloads/software/bytehist/test.sec04..idata.png"&gt;
	&lt;img src="http://www.cert.at/static/downloads/software/bytehist/test.sec04..idata.png" style="width:50px" border=0 /&gt;
&lt;/a&gt;
&lt;a href="http://www.cert.at/static/downloads/software/bytehist/test.sec05..tls.png"&gt;
	&lt;img src="http://www.cert.at/static/downloads/software/bytehist/test.sec05..tls.png" style="width:50px" border=0 /&gt;
&lt;/a&gt;
&lt;a href="http://www.cert.at/static/downloads/software/bytehist/test.sec06..rdata.png"&gt;
	&lt;img src="http://www.cert.at/static/downloads/software/bytehist/test.sec06..rdata.png" style="width:50px" border=0 /&gt;
&lt;/a&gt;
&lt;a href="http://www.cert.at/static/downloads/software/bytehist/test.sec07..reloc.png"&gt;
	&lt;img src="http://www.cert.at/static/downloads/software/bytehist/test.sec07..reloc.png" style="width:50px" border=0 /&gt;
&lt;/a&gt;
&lt;a href="http://www.cert.at/static/downloads/software/bytehist/test.sec08..rsrc.png"&gt;
	&lt;img src="http://www.cert.at/static/downloads/software/bytehist/test.sec08..rsrc.png" style="width:50px" border=0 /&gt;
&lt;/a&gt;
&lt;a href="http://www.cert.at/static/downloads/software/bytehist/test.Rest.png"&gt;
	&lt;img src="http://www.cert.at/static/downloads/software/bytehist/test.Rest.png" style="width:50px" border=0 /&gt;
&lt;/a&gt;
&lt;p /&gt;
&lt;span style="vertical-align:top"&gt;An UPX packed executable: &lt;/span&gt;&lt;br&gt;
&lt;a href="http://www.cert.at/static/downloads/software/bytehist/setup.jpg"&gt;
	&lt;img src="http://www.cert.at/static/downloads/software/bytehist/setup.jpg" style="width:50px" border=0 /&gt;
&lt;/a&gt;
&lt;a href="http://www.cert.at/static/downloads/software/bytehist/setup.sec01.UPX0.jpg"&gt;
	&lt;img src="http://www.cert.at/static/downloads/software/bytehist/setup.sec01.UPX0.jpg" style="width:50px" border=0 /&gt;
&lt;/a&gt;
&lt;a href="http://www.cert.at/static/downloads/software/bytehist/setup.sec02.UPX1.jpg"&gt;
	&lt;img src="http://www.cert.at/static/downloads/software/bytehist/setup.sec02.UPX1.jpg" style="width:50px" border=0 /&gt;
&lt;/a&gt;
&lt;a href="http://www.cert.at/static/downloads/software/bytehist/setup.sec03..rsrc.jpg"&gt;
	&lt;img src="http://www.cert.at/static/downloads/software/bytehist/setup.sec03..rsrc.jpg" style="width:50px" border=0 /&gt;
&lt;/a&gt;
&lt;p /&gt;
&lt;span style="vertical-align:top"&gt;&lt;i&gt;bytehist&lt;/i&gt; itself - unpacked: &lt;/span&gt;&lt;br&gt;
&lt;a href="http://www.cert.at/static/downloads/software/bytehist/bytehist.jpg"&gt;
	&lt;img src="http://www.cert.at/static/downloads/software/bytehist/bytehist.jpg" style="width:50px" border=0 /&gt;
&lt;/a&gt;
&lt;a href="http://www.cert.at/static/downloads/software/bytehist/bytehist.sec01..code.jpg"&gt;
	&lt;img src="http://www.cert.at/static/downloads/software/bytehist/bytehist.sec01..code.jpg" style="width:50px" border=0 /&gt;
&lt;/a&gt;
&lt;a href="http://www.cert.at/static/downloads/software/bytehist/bytehist.sec02..text.jpg"&gt;
	&lt;img src="http://www.cert.at/static/downloads/software/bytehist/bytehist.sec02..text.jpg" style="width:50px" border=0 /&gt;
&lt;/a&gt;
&lt;a href="http://www.cert.at/static/downloads/software/bytehist/bytehist.sec03..rdata.jpg"&gt;
	&lt;img src="http://www.cert.at/static/downloads/software/bytehist/bytehist.sec03..rdata.jpg" style="width:50px" border=0 /&gt;
&lt;/a&gt;
&lt;a href="http://www.cert.at/static/downloads/software/bytehist/bytehist.sec04..data.jpg"&gt;
	&lt;img src="http://www.cert.at/static/downloads/software/bytehist/bytehist.sec04..data.jpg" style="width:50px" border=0 /&gt;
&lt;/a&gt;
&lt;a href="http://www.cert.at/static/downloads/software/bytehist/bytehist.sec05..rsrc.jpg"&gt;
	&lt;img src="http://www.cert.at/static/downloads/software/bytehist/bytehist.sec05..rsrc.jpg" style="width:50px" border=0 /&gt;
&lt;/a&gt;</description>
      <pubDate>Mon, 12 Oct 2009 10:22:43 GMT</pubDate>
      <guid>http://www.cert.at/downloads/software/bytehist_en.html</guid>
      <dc:creator>CERT.at</dc:creator>
      <dc:date>2009-10-12T10:22:43Z</dc:date>
    </item>
    <item>
      <title>(Downloads/Software) - Minibis</title>
      <link>http://www.cert.at/downloads/software/minibis_en.html</link>
      <description>&lt;h1&gt;Minibis&lt;/h1&gt;
Software and tips to easily build up an automated malware analysis station based on a concept introduced in the paper
&lt;a href="../papers/mass_malware_analysis_en.html"&gt;"Mass Malware Analysis: A Do-It-Yourself Kit"&lt;/a&gt;.
&lt;!--more--&gt;

&lt;hr /&gt;

&lt;div style="float:right;text-align:right;"&gt;
	&lt;a class="zip" href="http://www.cert.at/static/downloads/software/minibis/minibis_2_0_29_29.zip"&gt;Download latest version&lt;/a&gt;
&lt;/div&gt;

&lt;h2&gt;Author&lt;/h2&gt;
Christian Wojner

&lt;h2&gt;Language&lt;/h2&gt;
English

&lt;h2&gt;License&lt;/h2&gt;
&lt;a href="http://en.wikipedia.org/wiki/ISC_license"&gt;ISCL&lt;/a&gt;

&lt;table cellpadding=0 cellspacing=0&gt;
	&lt;tr&gt;
		&lt;td&gt;&lt;h2&gt;Releases&lt;/h2&gt;&lt;/a&gt;&lt;/td&gt;
		&lt;td style="padding-left:20px;width:100%;"&gt;&lt;h2&gt;Changes&lt;/h2&gt;&lt;/a&gt;&lt;/td&gt;
		&lt;td style="padding-left:20px;text-align:center;"&gt;&lt;h2&gt;Download&lt;/h2&gt;&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr&gt;
		&lt;td nowrap&gt;2.0 (29/29)&lt;/td&gt;
		&lt;td style="padding-left:20px"&gt;Release 2.0&lt;/td&gt;
		&lt;td style="padding-left:20px;text-align:center;"&gt;
			&lt;a class="zip" href="http://www.cert.at/static/downloads/software/minibis/minibis_2_0_29_29.zip"&gt;&amp;nbsp;&lt;/a&gt;
		&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr&gt;
		&lt;td nowrap&gt;2.0 beta (28/29)&lt;/td&gt;
		&lt;td style="padding-left:20px"&gt;Forceable quit / Recovers from crashes&lt;/td&gt;
		&lt;td style="padding-left:20px;text-align:center;"&gt;
			&lt;a class="zip" href="http://www.cert.at/static/downloads/software/minibis/minibis_2_0_beta_28_29.zip"&gt;&amp;nbsp;&lt;/a&gt;
		&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr&gt;
		&lt;td nowrap&gt;2.0 beta (27/29)&lt;/td&gt;
		&lt;td style="padding-left:20px"&gt;Check Internet connectivity / Exit only if analysis paused&lt;/td&gt;
		&lt;td style="padding-left:20px;text-align:center;"&gt;
			&lt;a class="zip" href="http://www.cert.at/static/downloads/software/minibis/minibis_2_0_beta_27_29.zip"&gt;&amp;nbsp;&lt;/a&gt;
		&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr&gt;
		&lt;td nowrap&gt;2.0 beta (25/29)&lt;/td&gt;
		&lt;td style="padding-left:20px"&gt;-&lt;/td&gt;
		&lt;td style="padding-left:20px;text-align:center;"&gt;
			&lt;a class="zip" href="http://www.cert.at/static/downloads/software/minibis/minibis_2_0_beta_25_29.zip"&gt;&amp;nbsp;&lt;/a&gt;
		&lt;/td&gt;
	&lt;/tr&gt;
&lt;/table&gt;

&lt;hr /&gt;

&lt;h2&gt;Stay Informed!&lt;/h2&gt;
If you are interested in the actual state and the progress of upcoming features you might want to take a look at Minibis'
Twitter channel: &lt;a href="https://twitter.com/CERTat_Minibis"&gt;https://twitter.com/CERTat_Minibis&lt;/a&gt;.

&lt;hr /&gt;

&lt;h2&gt;Table of Contents&lt;/h2&gt;
&lt;ul&gt;
	&lt;li&gt;&lt;a href="#background"&gt;Background&lt;/a&gt;&lt;/li&gt;
	&lt;!--li&gt;&lt;a href="#faq"&gt;FAQ - Frequently Asked Questions&lt;/a&gt;&lt;/li--&gt;
	&lt;li&gt;&lt;a href="#installation"&gt;Installation Guide&lt;/a&gt;&lt;/li&gt;
	&lt;li&gt;&lt;a href="#configuration"&gt;Configuration Guide&lt;/a&gt;&lt;/li&gt;
	&lt;li&gt;&lt;a href="#oneloopcycle"&gt;One Loop-Cycle&lt;/a&gt;&lt;/li&gt;
	&lt;li&gt;&lt;a href="#commontools"&gt;Scripting of Common Tools and Tasks&lt;/a&gt;&lt;/li&gt;
	&lt;li&gt;&lt;a href="#screenshots"&gt;Screenshots&lt;/a&gt;&lt;/li&gt;
	&lt;!--li&gt;&lt;a href="#future"&gt;Future&lt;/a&gt;&lt;/li--&gt;
&lt;/ul&gt;

&lt;hr /&gt;

&lt;a name="background"&gt;&lt;/a&gt;
&lt;h2&gt;Background&lt;/h2&gt;
For detailed information on the underlying concept we recommend you read our paper 
&lt;a href="../papers/mass_malware_analysis_en.html"&gt;"Mass Malware Analysis: A Do-It-Yourself Kit"&lt;/a&gt;.

&lt;!--a name="faq"&gt;&lt;/a&gt;
&lt;h2&gt;FAQ - Frequently Asked Questions&lt;/h2--&gt;

&lt;a name="installation"&gt;&lt;/a&gt;
&lt;h2&gt;Installation Guide&lt;/h2&gt;
As a Minibis installations includes commercial software it is not possible for us to provide a
complete installation-package. The following step-by-step guide will lead you through the configuration
of a typical Minibis environment.

&lt;ol&gt;
	&lt;li&gt;Select the (physical) machine you like to be the home of your Minibis environment.&lt;/li&gt;
	&lt;li&gt;Install the latest version of Ubuntu (32 bit) on it.&lt;/li&gt;
	&lt;li&gt;Install proftpd (via "apt-get install proftpd").&lt;/li&gt;
	&lt;li&gt;Install zip (via "apt-get install zip").&lt;/li&gt;
	&lt;li&gt;Create a user "minibis" and do not forget to give it a password.&lt;/li&gt;  
	&lt;li&gt;Give your own user (the one you will start "minibis-cpr" from) full permissions to the home of "minibis" and verify that you can write to it.&lt;/li&gt;
	&lt;li&gt;Download Minibis and extract it to your desired folder.&lt;/li&gt;
	&lt;li&gt;Install SUN's VirtualBox (via "apt-get install virtualbox").&lt;/li&gt;
	&lt;li&gt;Create a new virtual machine (VM) in it using Windows XP as operating-system. All default settings for the machine and the OS are fine. Decline Autoupdate features when you get asked.&lt;/li&gt;
	&lt;li&gt;Add "minibis" as entry to Windows' hosts-file resolving it to your FTP-server's IP address.&lt;/li&gt;
	&lt;li&gt;Disconnect any (virtual) volumes from the VM (this is necessary to prevent eventual popups like autoplay, new hardware found etc.).&lt;/li&gt;
	&lt;li&gt;Transfer "minibis-cpp.exe" to the VM's Windows desktop.&lt;/li&gt;
	&lt;li&gt;Download your desired monitoring-tools to Linux. (Note: Download the ones that need "real" installation - so do not just copy - directly to Windows and install them.)&lt;/li&gt;
	&lt;li&gt;Disconnect from the network, i.e. by unplugging the network cable!&lt;/li&gt;
	&lt;li&gt;Check out if you can connect to the host ftp-daemon by using the Windows ftp-client.&lt;/li&gt;
	&lt;li&gt;Execute "minibis-cpp.exe" in the VM and answer the firewall question to NOT BLOCK this application.&lt;/li&gt;
	&lt;li&gt;You will be now asked to enter a password. This is the one of the user "minibis".&lt;/li&gt;
	&lt;li&gt;Create a VM-snapshot of this state.&lt;/li&gt;
	&lt;li&gt;Close the VM, using the option to revert to the last taken snapshot.&lt;/li&gt;
	&lt;li&gt;Bring your samples into Linux's filesystem (i.e. by mounting a CD-Rom).&lt;/li&gt;
	&lt;li&gt;Set "minibis-cpr" as executable (chmod +x minibis-cpr) and execute and configure it.&lt;/li&gt;
&lt;/ol&gt;

&lt;a name="configuration"&gt;&lt;/a&gt;
&lt;h2&gt;Configuration Guide&lt;/h2&gt;
The download package includes an example configuration. To use this copy it to Minibis' folder and rename it
to "minibis.pref". Note: Do never alter this file in an editor use Minibis for that. Just click on the 
"Config"-button in the lower left corner in the main-window.

&lt;h3&gt;Buttons behind fields&lt;/h3&gt;
As usual a click on such a button brings up a tiny wizard that provides support in finding the proper value.

&lt;h3&gt;The "check"-button&lt;/h3&gt;
By clicking this button the actual configuration is going to be checked for consistency. Note that in case of
multiple errors each click will always come up with &lt;b&gt;just one&lt;/b&gt; error. So make sure to re-check if you solved
a problem.

&lt;h3&gt;Area "Samples"&lt;/h3&gt;
By using the directory- or the file-entry you can configure a run for multiple samples or just one sample.
In case of directory-mode sub-directories are included as well.

&lt;h3&gt;Area "General"&lt;/h3&gt;
"FTP-Directory" is the path where the log-files will be transferred
to. "Samplename" is the name that will be used for the sample at the
proband. Some malware reacts to specific names, so this is the place
where you can change it. Regarding "Virtual Machine" you can switch
between the actually supported solutions (currently only VirtualBox)
and choose the right virtual machine instance.

&lt;h3&gt;Area "Timeouts"&lt;/h3&gt;
These are &lt;b&gt;the&lt;/b&gt; timeouts from the underlying concept. The extra field for cpp, which holds "10" (seconds) by default
specifies some additional time to wait before quitting monitoring if the sample exited on its own. This enables
continuation of monitoring i.e. if the sample injects itself in another process before doing something evil.

&lt;h3&gt;Area "Solutions for VBox bugs"&lt;/h3&gt;
These are settings that help to prevent processes of VirtualBox from getting stuck. If you already have
other (VBox) virtual machines running you might want to uncheck those. The first checkbox addresses stopping and
the second reverting the VM.

&lt;h3&gt;Area "VM Management"&lt;/h3&gt;
Here you can specify the commands that will be used for the corresponding VM activities. The id of the VM
is addressed by the replacement token %vmid%. Besides that, any of them has a timeout for hangup-prevention.

&lt;h3&gt;Tab "Researcher Scripting"&lt;/h3&gt;
To let you customize the researcher side there are three events (therefore three editor-fields) that can be
scripted using shell-scripting (Linux). Use the replacement token %md5% to specify the actual sample.&lt;br /&gt;
&lt;br /&gt;
For further details when those events exactly happen, see "One Loop-Cycle".
&lt;br /&gt;
You'll find tutorials and examples regarding scripting under "Scripting of Common Tools and Tasks".

&lt;h3&gt;Tab "Proband Scripting"&lt;/h3&gt;
To let you customize the Proband's side there are two events (the two lower editor-fields) that can be
scripted using batch-scripting (Windows).&lt;br /&gt;
The actions scripted for these two events are tied to the two editor-fields above called "Tools to transfer"
and "Results to transfer ([...] to ZIP)". The first ("Tools...") is used to define (name) the tools (files) that will
be copied to the Proband for use in later activities. The second ("Results...") is used to define (name) the files
that will be transferred back from the Proband. 
If the filename is enclosed in square brackets "[...]" the file will get ZIPped into an
archive after it arrives on Researcher.&lt;br /&gt;
&lt;br /&gt;
For further details when those events exactly happen and how the "Tools..." and the "Results..." are handled see
"One Loop-Cycle".
&lt;br /&gt;
More Tutorials and examples regarding scripting can be found under "Scripting of Common Tools and Tasks".

&lt;a name="oneloopcycle"&gt;&lt;/a&gt;
&lt;h2&gt;One Loop-Cycle&lt;/h2&gt;
Assuming that the sample can be executed, this is a chronological list of all actions
that can (some of them are optional) happen. 
It is important to understand that in this list the two components of Minibis
- CPR and CPP - are described as what they really are: one logical entity. 
The tags &lt;i class="r"&gt;(R)&lt;/i&gt; and &lt;i class="p"&gt;(P)&lt;/i&gt; specify the 
location (&lt;i class="r"&gt;(R)&lt;/i&gt;esearcher or &lt;i class="p"&gt;(P)&lt;/i&gt;roband) of the action:&lt;br /&gt;
&lt;ol&gt;
	&lt;li&gt;&lt;i class="r"&gt;(R)&lt;/i&gt;
		Copy sample to FTP-path (config) as samplename (config) with the apropriate suffix according to the
		result of Linux' "file"-command.
	&lt;/li&gt;
	&lt;li&gt;&lt;i class="r"&gt;(R)&lt;/i&gt;
		Execute the actions tied to event "Actions BEFORE Proband gets started" (config).
	&lt;/li&gt;
	&lt;li&gt;&lt;i class="r"&gt;(R)&lt;/i&gt;
		Execute the command declared under "VM Management Start" (config) and wait until the triggerfile "%md5%_start.rdy"
		exists or the timeout for "VM Management Start" occurs.	In case of the latter do the steps 14, 15, 17, 19 and return
		to step 3.
	&lt;/li&gt;
	&lt;li&gt;&lt;i class="p"&gt;(P)&lt;/i&gt;
		Fetch the preference file "minibis.pref" via FTP.
	&lt;/li&gt;
	&lt;li&gt;&lt;i class="p"&gt;(P)&lt;/i&gt;
		Fetch all tools (files) according to "Tools to transfer" (config) via FTP.
	&lt;/li&gt;
	&lt;li&gt;&lt;i class="p"&gt;(P)&lt;/i&gt;
		Transfer back the triggerfile "%md5%_start.rdy" via FTP.
	&lt;/li&gt;
	&lt;li&gt;&lt;i class="r"&gt;(R)&lt;/i&gt;
		Wait until a triggerfile "%md5%_ready.rdy" exists or the timeout for "CPR" (config) occurs.&lt;br /&gt;
		Meanwhile (optionally) execute the actions tied to event "Actions WHILE Proband runs" and optionally
		repeat this every &lt;i&gt;N&lt;/i&gt; seconds (see config field "every").&lt;br /&gt;
		If the timeout occurred then continue with step 14.
	&lt;/li&gt;
	&lt;li&gt;&lt;i class="p"&gt;(P)&lt;/i&gt;
		Execute the actions tied to event "Actions BEFORE sample gets executed" (config).
	&lt;/li&gt;
	&lt;li&gt;&lt;i class="p"&gt;(P)&lt;/i&gt;
		Execute the sample and wait until it exits or the timeout for "CPP" (config) occurs. If the sample
		exited wait until the timeout for "CPP +" occurs.
	&lt;/li&gt;
	&lt;li&gt;&lt;i class="p"&gt;(P)&lt;/i&gt;
		Execute the actions tied to event "Actions AFTER sample exited or time's up" (config).
	&lt;/li&gt;
	&lt;li&gt;&lt;i class="p"&gt;(P)&lt;/i&gt;
		Transfer back all files according to "Results to transfer ([...] to ZIP)" (config) via FTP.
	&lt;/li&gt;
	&lt;li&gt;&lt;i class="p"&gt;(P)&lt;/i&gt;
		Transfer back the triggerfile "%md5%_ready.rdy" via FTP.
	&lt;/li&gt;
	&lt;li&gt;&lt;i class="p"&gt;(P)&lt;/i&gt;
		Exit.
	&lt;/li&gt;
	&lt;li&gt;&lt;i class="r"&gt;(R)&lt;/i&gt;
		Execute the command declared under "VM Management Stop" (config) and wait until it exits or the timeout
		for "VM Management Stop" occurs.
	&lt;/li&gt;
	&lt;li&gt;&lt;i class="r"&gt;(R)&lt;/i&gt;
		Optionally execute "Solutions for VBox bugs" column 1 (config).
	&lt;/li&gt;
	&lt;li&gt;&lt;i class="r"&gt;(R)&lt;/i&gt;
		Execute the actions tied to event "Actions AFTER Proband got stopped" (config).
	&lt;/li&gt;
	&lt;li&gt;&lt;i class="r"&gt;(R)&lt;/i&gt;
		Execute the command declared under "VM Management Revert" (config) and wait until it exits or the timeout
		for "VM Management Revert" occurs.
	&lt;/li&gt;
	&lt;li&gt;&lt;i class="r"&gt;(R)&lt;/i&gt;
		ZIP all files surrounded with [...] according to "Results to transfer ([...] to ZIP)" (config) into the
		archive "%md5%.zip".
	&lt;/li&gt;
	&lt;li&gt;&lt;i class="r"&gt;(R)&lt;/i&gt;
		Optionally execute "Solutions for VBox bugs" column 2 (config).
	&lt;/li&gt;
	&lt;li&gt;&lt;i class="r"&gt;(R)&lt;/i&gt;
		Delete "minibis.pref" and the sample from FTP-folder.
	&lt;/li&gt;
&lt;/ol&gt;

&lt;a name="commontools"&gt;&lt;/a&gt;
&lt;h2&gt;Scripting of Common Tools and Tasks&lt;/h2&gt;
This section gives you example configurations for the integration of widely used monitoring tools into Minibis.

&lt;h3&gt;Sysinternals Process Monitor&lt;/h3&gt;
You can download the latest version of Process Monitor from &lt;a href="http://download.sysinternals.com/Files/ProcessMonitor.zip"&gt;here&lt;/a&gt;.&lt;br /&gt;
Extract the ZIP-file and copy "Procmon.exe" to Minibis' FTP-folder (config).&lt;br /&gt;
&lt;ul&gt;
	&lt;li&gt;Proband Scripting&lt;/li&gt;
	&lt;ul&gt;
		&lt;li&gt;Tools to transfer:&lt;br /&gt;
			&lt;div class="code"&gt;
				Procmon.exe
			&lt;/div&gt;
		&lt;/li&gt;
		&lt;li&gt;Results to transfer ([...] to ZIP):&lt;br /&gt;
			&lt;div class="code"&gt;
				[procmon.pml]&lt;br /&gt;
				procmon.csv
			&lt;/div&gt;
		&lt;/li&gt;
		&lt;li&gt;Actions BEFORE sample gets executed:&lt;br /&gt;
			&lt;div class="code"&gt;
				start Procmon.exe /AcceptEula /quiet /minimized /Backingfile procmon.pml&lt;br /&gt;
				Procmon.exe /AcceptEula /WaitForIdle
			&lt;/div&gt;
		&lt;/li&gt;
		&lt;li&gt;Actions AFTER sample exited or time's up:&lt;br /&gt;
			&lt;div class="code"&gt;
				Procmon.exe /AcceptEula /terminate&lt;br /&gt;
				Procmon.exe /AcceptEula /saveas procmon.csv /openlog procmon.pml
			&lt;/div&gt;
		&lt;/li&gt;
	&lt;/ul&gt;
&lt;/ul&gt;

&lt;h3&gt;WinDump: tcpdump for Windows&lt;/h3&gt;
You can download the latest version of WinDump from &lt;a href="http://www.mirrorservice.org/sites/ftp.wiretapped.net/pub/security/packet-capture/winpcap/windump/install/bin/windump_3_9_5/WinDump.exe"&gt;here&lt;/a&gt;.&lt;br /&gt;
You also need to install WinPcap in the Proband for WinDump to work properly. You can download the latest version of WinDump from &lt;a href="http://www.winpcap.org/install/bin/WinPcap_4_1_1.exe"&gt;here&lt;/a&gt;.&lt;br /&gt;
Copy "WinDump.exe" to Minibis' FTP-folder (config).&lt;br /&gt;
Copy "sleep.exe" (a tool of the Minibis download-package) to Minibis' FTP-folder (config).&lt;br /&gt;
&lt;ul&gt;
	&lt;li&gt;Proband Scripting&lt;/li&gt;
	&lt;ul&gt;
		&lt;li&gt;Tools to transfer:&lt;br /&gt;
			&lt;div class="code"&gt;
				WinDump.exe
				sleep.exe
			&lt;/div&gt;
		&lt;/li&gt;
		&lt;li&gt;Results to transfer ([...] to ZIP):&lt;br /&gt;
			&lt;div class="code"&gt;
				[windump.pcap]&lt;br /&gt;
				windump.txt
			&lt;/div&gt;
		&lt;/li&gt;
		&lt;li&gt;Actions BEFORE sample gets executed:&lt;br /&gt;
			&lt;div class="code"&gt;
				start WinDump.exe -i 1 -w windump.pcap -U -s 0&lt;br /&gt;
				sleep.exe 1
			&lt;/div&gt;
		&lt;/li&gt;
		&lt;li&gt;Actions AFTER sample exited or time's up:&lt;br /&gt;
			&lt;div class="code"&gt;
				taskkill /f /im WinDump.exe&lt;br /&gt;
				WinDump.exe -n -p -r windump.pcap &gt; windump.txt
			&lt;/div&gt;
		&lt;/li&gt;
	&lt;/ul&gt;
&lt;/ul&gt;

&lt;h3&gt;Creating a Screenshot&lt;/h3&gt;
Copy "screenshot.exe" (a tool of the Minibis download-package) to Minibis' FTP-folder (config).&lt;br /&gt;
&lt;ul&gt;
	&lt;li&gt;Proband Scripting&lt;/li&gt;
	&lt;ul&gt;
		&lt;li&gt;Tools to transfer:&lt;br /&gt;
			&lt;div class="code"&gt;
				screenshot.exe
			&lt;/div&gt;
		&lt;/li&gt;
		&lt;li&gt;Results to transfer ([...] to ZIP):&lt;br /&gt;
			&lt;div class="code"&gt;
				screenshot.png
			&lt;/div&gt;
		&lt;/li&gt;
		&lt;li&gt;Actions AFTER sample exited or time's up:&lt;br /&gt;
			&lt;div class="code"&gt;
				screenshot.exe screenshot.png
			&lt;/div&gt;
		&lt;/li&gt;
	&lt;/ul&gt;
&lt;/ul&gt;

&lt;!--h3&gt;Sysinternals Process Monitor&lt;/h3&gt;
You can download the latest version of Process Monitor from &lt;a href="http://download.sysinternals.com/Files/ProcessMonitor.zip"&gt;here&lt;/a&gt;.&lt;br /&gt;
Extract the ZIP-file and copy "Procmon.exe" to Minibis' FTP-folder (config).&lt;br /&gt;
&lt;ul&gt;
	&lt;li&gt;Researcher Scripting&lt;/li&gt;
	&lt;ul&gt;
		&lt;li&gt;Actions BEFORE Proband gets started:&lt;br /&gt;
			&lt;div class="code"&gt;
			&lt;/div&gt;
		&lt;/li&gt;
		&lt;li&gt;Actions WHILE Proband runs:&lt;br /&gt;
			&lt;div class="code"&gt;
			&lt;/div&gt;
		&lt;/li&gt;
		&lt;li&gt;Actions AFTER Proband got stopped:&lt;br /&gt;
			&lt;div class="code"&gt;
			&lt;/div&gt;
		&lt;/li&gt;
	&lt;/ul&gt;
	&lt;li&gt;Proband Scripting&lt;/li&gt;
	&lt;ul&gt;
		&lt;li&gt;Tools to transfer:&lt;br /&gt;
			&lt;div class="code"&gt;
			&lt;/div&gt;
		&lt;/li&gt;
		&lt;li&gt;Results to transfer ([...] to ZIP):&lt;br /&gt;
			&lt;div class="code"&gt;
			&lt;/div&gt;
		&lt;/li&gt;
		&lt;li&gt;Actions BEFORE sample gets executed:&lt;br /&gt;
			&lt;div class="code"&gt;
			&lt;/div&gt;
		&lt;/li&gt;
		&lt;li&gt;Actions AFTER sample exited or time's up:&lt;br /&gt;
			&lt;div class="code"&gt;
			&lt;/div&gt;
		&lt;/li&gt;
	&lt;/ul&gt;
&lt;/ul--&gt;

&lt;a name="screenshots"&gt;&lt;/a&gt;
&lt;h2&gt;Screenshots&lt;/h2&gt;
&lt;a href="http://www.cert.at/static/downloads/software/minibis/MainWindow.png"&gt;
	&lt;img src="http://www.cert.at/static/downloads/software/minibis/MainWindow.png" style="width:50px" border=0 /&gt;
&lt;/a&gt;
&lt;a href="http://www.cert.at/static/downloads/software/minibis/ConfigResearcher.png"&gt;
	&lt;img src="http://www.cert.at/static/downloads/software/minibis/ConfigResearcher.png" style="width:50px" border=0 /&gt;
&lt;/a&gt;
&lt;a href="http://www.cert.at/static/downloads/software/minibis/ConfigProband.png"&gt;
	&lt;img src="http://www.cert.at/static/downloads/software/minibis/ConfigProband.png" style="width:50px" border=0 /&gt;
&lt;/a&gt;

&lt;!--a name="future"&gt;&lt;/a&gt;
&lt;h2&gt;Future&lt;/h2--&gt;</description>
      <pubDate>Tue, 17 Aug 2010 21:02:30 GMT</pubDate>
      <guid>http://www.cert.at/downloads/software/minibis_en.html</guid>
      <dc:creator>CERT.at</dc:creator>
      <dc:date>2010-08-17T21:02:30Z</dc:date>
    </item>
    <item>
      <title>(Downloads/Data) - Conficker Worm</title>
      <link>http://www.cert.at/downloads/data/conficker_en.html</link>
      <description>&lt;h1&gt;Conficker Worm&lt;/h1&gt;
2009/02/09
&lt;p /&gt;
Various files regarding the worm "Conficker".&lt;!--more--&gt;
&lt;p /&gt;
&lt;table style="padding-left:30px;"&gt;
	&lt;tr&gt;
		&lt;td&gt;&lt;a class="zip" href="http://www.cert.at/static/downloads/data/conficker/all_domains.zip"&gt;all domains&lt;/a&gt;&lt;/td&gt;
		&lt;td&gt; ... suitable for block lists (in proxies etc)&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr&gt;
		&lt;td&gt;&lt;a class="zip" href="http://www.cert.at/static/downloads/data/conficker/named.conf.conficker.zip"&gt;DNS named.conf file&lt;/a&gt;&lt;/td&gt;
		&lt;td&gt; ... Bind named.conf file with all conficker domain names&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr&gt;
		&lt;td&gt;&lt;a class="db" href="http://www.cert.at/static/downloads/data/conficker/conficker.db"&gt;sample bind zone file&lt;/a&gt;&lt;/td&gt;
		&lt;td&gt; ... suitable for the named.conf file above.&lt;/td&gt;
	&lt;/tr&gt;
&lt;/table&gt;</description>
      <pubDate>Mon, 12 Oct 2009 10:19:30 GMT</pubDate>
      <guid>http://www.cert.at/downloads/data/conficker_en.html</guid>
      <dc:creator>CERT.at</dc:creator>
      <dc:date>2009-10-12T10:19:30Z</dc:date>
    </item>
    <item>
      <title>(Downloads/Press material) - CERT.at Logo</title>
      <link>http://www.cert.at/downloads/pressmaterial/certatlogo_en.html</link>
      <description>&lt;h1&gt;CERT.at Logo&lt;/h1&gt;
CERT.at-logo in various formats and sizes.&lt;!--more--&gt;
&lt;p /&gt;
&lt;table style="padding-left:30px;"&gt;
	&lt;tr&gt;
		&lt;td&gt;&lt;a class="png" href="http://www.cert.at/static/downloads/certatlogo/cert.at_16.png"&gt;CERT.at-logo as 16x8 PNG-file (0.5 KB)&lt;/a&gt;&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr&gt;
		&lt;td&gt;&lt;a class="png" href="http://www.cert.at/static/downloads/certatlogo/cert.at_32.png"&gt;CERT.at-logo as 32x17 PNG-file (1.1 KB)&lt;/a&gt;&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr&gt;
		&lt;td&gt;&lt;a class="png" href="http://www.cert.at/static/downloads/certatlogo/cert.at_64.png"&gt;CERT.at-logo as 64x34 PNG-file (2.7 KB)&lt;/a&gt;&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr&gt;
		&lt;td&gt;&lt;a class="png" href="http://www.cert.at/static/downloads/certatlogo/cert.at_100.png"&gt;CERT.at-logo as 100x53 PNG-file (4.6 KB)&lt;/a&gt;&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr&gt;
		&lt;td&gt;&lt;a class="png" href="http://www.cert.at/static/downloads/certatlogo/cert.at_128.png"&gt;CERT.at-logo as 128x67 PNG-file (5.6 KB)&lt;/a&gt;&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr&gt;
		&lt;td&gt;&lt;a class="png" href="http://www.cert.at/static/downloads/certatlogo/cert.at_150.png"&gt;CERT.at-logo as 150x79 PNG-file (6.6 KB)&lt;/a&gt;&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr&gt;
		&lt;td&gt;&lt;a class="png" href="http://www.cert.at/static/downloads/certatlogo/cert.at_200.png"&gt;CERT.at-logo as 200x105 PNG-file (8.8 KB)&lt;/a&gt;&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr&gt;
		&lt;td&gt;&lt;a class="png" href="http://www.cert.at/static/downloads/certatlogo/cert.at_256.png"&gt;CERT.at-logo as 256x135 PNG-file (11.4 KB)&lt;/a&gt;&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr&gt;
		&lt;td&gt;&lt;a class="png" href="http://www.cert.at/static/downloads/certatlogo/cert.at_320.png"&gt;CERT.at-logo as 320x168 PNG-file (14.4 KB)&lt;/a&gt;&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr&gt;
		&lt;td&gt;&lt;a class="png" href="http://www.cert.at/static/downloads/certatlogo/cert.at_640.png"&gt;CERT.at-logo as 640x336 PNG-file (29.3 KB)&lt;/a&gt;&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr&gt;
		&lt;td&gt;&lt;a class="png" href="http://www.cert.at/static/downloads/certatlogo/cert.at_800.png"&gt;CERT.at-logo as 800x420 PNG-file (37.8 KB)&lt;/a&gt;&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr&gt;
		&lt;td&gt;&lt;a class="png" href="http://www.cert.at/static/downloads/certatlogo/cert.at_1024.png"&gt;CERT.at-logo as 1024x538 PNG-file (49.2 KB)&lt;/a&gt;&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr&gt;
		&lt;td&gt;&lt;a class="png" href="http://www.cert.at/static/downloads/certatlogo/cert.at_1280.png"&gt;CERT.at-logo as 1280x673 PNG-file (63.8 KB)&lt;/a&gt;&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr&gt;
		&lt;td&gt;&lt;a class="png" href="http://www.cert.at/static/downloads/certatlogo/cert.at_1600.png"&gt;CERT.at-logo as 1600x841 PNG-file (82.2 KB)&lt;/a&gt;&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr&gt;
		&lt;td&gt;&lt;a class="svg" href="http://www.cert.at/static/downloads/certatlogo/cert.at_vektorisiert_inkscape.svg"&gt;CERT.at-logo as vectorized format Inkscape-SVG (17.1 KB)&lt;/a&gt;&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr&gt;
		&lt;td&gt;&lt;a class="svg" href="http://www.cert.at/static/downloads/certatlogo/cert.at_vektorisiert_plain.svg"&gt;CERT.at-logo as vektorized format Plain-SVG (14.6 KB)&lt;/a&gt;&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr&gt;
		&lt;td&gt;&lt;a class="zip" href="http://www.cert.at/static/downloads/certatlogo/cert.at_logos.zip"&gt;all CERT.at-logos as ZIP-archive (311.6 KB)&lt;/a&gt;&lt;/td&gt;
	&lt;/tr&gt;
&lt;/table&gt;</description>
      <pubDate>Mon, 12 Oct 2009 10:17:23 GMT</pubDate>
      <guid>http://www.cert.at/downloads/pressmaterial/certatlogo_en.html</guid>
      <dc:creator>CERT.at</dc:creator>
      <dc:date>2009-10-12T10:17:23Z</dc:date>
    </item>
    <item>
      <title>(Downloads/Press material) - HiRes Teamphotos</title>
      <link>http://www.cert.at/downloads/pressmaterial/hiresteam_en.html</link>
      <description>&lt;h1&gt;HiRes Teamphotos&lt;/h1&gt;
High resolution photographs of the CERT.at teammembers.&lt;!--more--&gt;
&lt;p /&gt;
&lt;table style="padding-left:30px;"&gt;
	&lt;tr &gt;
		&lt;td &gt;&lt;a class="jpg" href="http://www.cert.at/static/downloads/photos/AaronKaplan_hires.jpg"&gt;Leon Aaron Kaplan&lt;/a&gt;&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr &gt;
		&lt;td &gt;&lt;a class="jpg" href="http://www.cert.at/static/downloads/photos/OtmarLendl_hires.jpg"&gt;Otmar Lendl&lt;/a&gt;&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr &gt;
		&lt;td &gt;&lt;a class="jpg" href="http://www.cert.at/static/downloads/photos/RobertSchischka_hires.jpg"&gt;Robert Schischka&lt;/a&gt;&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr &gt;
		&lt;td &gt;&lt;a class="jpg" href="http://www.cert.at/static/downloads/photos/RobertWaldner_hires.jpg"&gt;Robert Waldner&lt;/a&gt;&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr &gt;
		&lt;td &gt;&lt;a class="jpg" href="http://www.cert.at/static/downloads/photos/ChristianWojner_hires.jpg"&gt;Christian Wojner&lt;/a&gt;&lt;/td&gt;
	&lt;/tr&gt;
&lt;/table&gt;</description>
      <pubDate>Mon, 12 Oct 2009 10:21:10 GMT</pubDate>
      <guid>http://www.cert.at/downloads/pressmaterial/hiresteam_en.html</guid>
      <dc:creator>CERT.at</dc:creator>
      <dc:date>2009-10-12T10:21:10Z</dc:date>
    </item>
    <item>
      <title>(About us/Overview) - Overview</title>
      <link>http://www.cert.at/about/missionstatement/content_en.html</link>
      <description>&lt;h1&gt;Overview&lt;/h1&gt;
CERT.at is the Austrian national CERT.
&lt;p /&gt;
CERT.at is the primary contact point for IT-security in a national context. CERT.at will coordinate other CERTs
operating in the area of critical infrastructure or communication infrastructure. We will also provide basic
IT-security information (warnings, alerts, advise) for SMEs.
&lt;p /&gt;
In the case of significant online attacks against Austrian infrastructure, CERT.at will coordinate the reponse by the targeted operators and local security teams.
&lt;p /&gt;
The full description of CERT.at can be found in  &lt;a href='http://www.cert.at/about/rfc2350/rfc2350_en.html'&gt;RFC 2350&lt;/a&gt; format.

&lt;h2&gt;Why?&lt;/h2&gt;
Security needs an holistic approach! IT-systems are increasingly
interconnected and thus interdependent. In order to protect the national
infrastructure, the response to an attack needs to be coordinated
between all stakeholders and operators.</description>
      <pubDate>Thu, 24 Sep 2009 10:18:58 GMT</pubDate>
      <guid>http://www.cert.at/about/missionstatement/content_en.html</guid>
      <dc:creator>CERT.at</dc:creator>
      <dc:date>2009-09-24T10:18:58Z</dc:date>
    </item>
    <item>
      <title>(About us/Charter) - Charter</title>
      <link>http://www.cert.at/about/scope/scope_en.html</link>
      <description>&lt;h1&gt;Charter&lt;/h1&gt;
The purpose of CERT.at is to coordinate security efforts and incident response for IT-security problems on a national level in Austria.
&lt;h2&gt;Constituency&lt;/h2&gt;
The constituency are IT-security teams and local CERTs in Austria.
&lt;p /&gt;
Pro-active and educational material will be provided for SMEs and the general public as well.

&lt;p /&gt;
As part of a cooperation agreement with the &lt;a href="http://www.govcert.gv.at/"&gt;Austrian Government CERT&lt;/a&gt;, CERT.at provices 
resources for incident response in government and crititical infrastructure networks.


&lt;h2&gt;Sponsorship and/or Affiliation&lt;/h2&gt;
CERT.at is an initiative of nic.at, the Austrian domain registry.
&lt;p /&gt;
Funding is provided by nic.at 

&lt;h2&gt;Authority&lt;/h2&gt;
CERT.at's main purpose in incident handling is the coordination of incident response. As such, we only advise local CERTs and have no authority to demand certain actions.
We have indirect authority over AS35492 and are in very close contact with the &lt;a href="https://www.aco.net/cert.html?&amp;L=1"&gt;ACONet CERT&lt;/a&gt;.</description>
      <pubDate>Thu, 07 Jan 2010 15:14:35 GMT</pubDate>
      <guid>http://www.cert.at/about/scope/scope_en.html</guid>
      <dc:creator>CERT.at</dc:creator>
      <dc:date>2010-01-07T15:14:35Z</dc:date>
    </item>
    <item>
      <title>(About us/Policies) - Policies</title>
      <link>http://www.cert.at/about/policies/policies_en.html</link>
      <description>&lt;h1&gt;Policies&lt;/h1&gt;
&lt;h2&gt;Types of Incidents and Level of Support&lt;/h2&gt;
CERT.at is authorized to address all types of computer security incidents which occur, or threaten to occur, in our constituency  and which require cross-organizational coordination.
&lt;p /&gt;
The level of support given by CERT.at will vary depending on the type and severity of the incident or issue, the type of constituent, the size of the user community affected, and CERT.at's resources at the time. Special attention will be give to issues affecting critical infrastructure.
&lt;p /&gt;
Note that no direct support will be given to end users; they are expected to contact their system administrator, network administrator, or department head for assistance. CERT.at will support the latter people.
&lt;p /&gt;
CERT.at is committed to keeping its constituency informed of potential vulnerabilities, and where possible, will inform this community of such vulnerabilities before they are actively exploited.

&lt;h2&gt;Co-operation, Interaction and Disclosure of Information&lt;/h2&gt;
CERT.at will cooperate with other Organisations in the Field of Computer Security. This Cooperation also includes and often requires the exchange of vital information regarding security incidents and vulnerabilities. Nevertheless CERT.at will protect the privacy of their customers, and therefore (under normal circumstances) pass on information in an anonymized way only unless other contractual agreements apply.
&lt;p /&gt;
CERT.at operates under the restrictions imposed by Austrian law. This involves careful handling of personal data as required by Austrian Data Protection law, but it is also possible that - according to Austrian law - CERT.at may be forced to disclose information due to a Court's order.

&lt;h2&gt;Communication and Authentication&lt;/h2&gt;
For normal communication not containing sensitive information CERT.at will use conventional methods like unencrypted e-mail or fax.
&lt;p /&gt;
For secure communication PGP-Encrypted e-mail or telephone will be used. If it is necessary to authenticate a person before communicating, this can be done either through existing webs of trust (e.g. FIRST, TI, …) or by other methods like call-back, mail-back or even face-to-face meeting if necessary.</description>
      <pubDate>Thu, 24 Sep 2009 10:20:30 GMT</pubDate>
      <guid>http://www.cert.at/about/policies/policies_en.html</guid>
      <dc:creator>CERT.at</dc:creator>
      <dc:date>2009-09-24T10:20:30Z</dc:date>
    </item>
    <item>
      <title>(About us/Contact) - Contact</title>
      <link>http://www.cert.at/about/contact/contact_en.html</link>
      <description>&lt;h1&gt;Contact&lt;/h1&gt;
&lt;table&gt;
	&lt;tr&gt;
		&lt;td&gt;CERT.at:&lt;/td&gt;
		&lt;td&gt;Computer Emergency Response Team Austria&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr&gt;
		&lt;td&gt;Address:&lt;/td&gt;
		&lt;td&gt;nic.at&lt;br /&gt;Karlsplatz 1/2/9&lt;br /&gt;A-1010 Vienna&lt;br /&gt;Austria&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr&gt;
		&lt;td&gt;Telephone:&lt;/td&gt;
		&lt;td&gt;+43 1 5056416 78&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr&gt;
		&lt;td&gt;Fax:&lt;/td&gt;&lt;td&gt;+43 1 5056416 79&lt;/td&gt;
	&lt;/tr&gt;
&lt;/table&gt;

&lt;h2&gt;eMail&lt;/h2&gt;
Please report security incidents to &lt;a href="mailto:reports@cert.at"&gt;reports@cert.at&lt;/a&gt;.
&lt;p /&gt;
General inquiries and communication not related to a specific incident should be addressed to 
&lt;a href="mailto:cert@cert.at"&gt;cert@cert.at&lt;/a&gt;.
&lt;p /&gt;
CERT.at is &lt;strong&gt;not a public IT helpdesk&lt;/strong&gt; and will thus refer questions like "is my PC infected" to public web ressources or commercial helpdesks.

&lt;h2&gt;PGP Setup&lt;/h2&gt;
We will sign official communications with the following key:
&lt;pre&gt;
      pub   1024D/5C384328 2008-02-13
            Key fingerprint = 740C 68EC B6B6 2060 48A5  D49A 02FB C1EF 5C38 4328
	    uid                  reports@cert.at (general communication key. For incident reports) 
	    sub   4096g/D7071014 2008-02-13
&lt;/pre&gt;
&lt;p /&gt;
You can also use this key to encrypt mail addressed to us.
&lt;p /&gt;
A keyring of all our keys is located at &lt;a href="http://www.cert.at/static/pgpkeys.asc"&gt;http://www.cert.at/static/pgpkeys.asc&lt;/a&gt;.</description>
      <pubDate>Thu, 24 Sep 2009 10:21:13 GMT</pubDate>
      <guid>http://www.cert.at/about/contact/contact_en.html</guid>
      <dc:creator>CERT.at</dc:creator>
      <dc:date>2009-09-24T10:21:13Z</dc:date>
    </item>
    <item>
      <title>(About us/Team) - Team</title>
      <link>http://www.cert.at/about/team/team_en.html</link>
      <description>&lt;h1&gt;Team&lt;/h1&gt;
&lt;table width="100%" border=0 cellspacing="9" cellpadding="0"&gt;
	&lt;thead&gt;
	&lt;tr&gt;
		&lt;th align=left &gt;Name &lt;/th&gt;
		&lt;th align=left &gt;PGP ID &lt;/th&gt;
		&lt;th align=left width=100% &gt;Fingerprint&lt;/th&gt;
		&lt;th align=left &gt;Pic&lt;/th&gt;
	&lt;/tr&gt;
	&lt;/thead&gt;
	&lt;tbody&gt;
	&lt;tr &gt;
		&lt;td &gt;Leon Aaron Kaplan &lt;/td&gt;
		&lt;td &gt;CDAE4DB6&lt;/td&gt;
		&lt;td &gt;BC3E 553E 102F 214F C59A  4A0C 2D7A 997A CDAE 4DB6&lt;/td&gt;
		&lt;td &gt;&lt;a href="http://www.cert.at/static/downloads/photos/AaronKaplan.jpg"&gt;&lt;img width=50 border=0 src="http://www.cert.at/static/downloads/photos/AaronKaplan.jpg" alt="picture Aaron"/&gt;&lt;/a&gt;&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr &gt;
		&lt;td &gt;Team leader:&lt;br /&gt;Otmar Lendl&lt;/td&gt;
		&lt;td &gt;835E0B34&lt;/td&gt;
		&lt;td &gt;BE4E 1E48 E0F6 6987 181B  0D27 754E 9F02 835E 0B34&lt;/td&gt;
		&lt;td &gt;&lt;a href="http://www.cert.at/static/downloads/photos/OtmarLendl.jpg"&gt;&lt;img width=50 border=0 src="http://www.cert.at/static/downloads/photos/OtmarLendl.jpg" alt="picture Otmar"/&gt;&lt;/a&gt;&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr &gt;
		&lt;td &gt;Robert Schischka &lt;br /&gt;&lt;/td&gt;
		&lt;td &gt;A2FD9DBC&lt;/td&gt;
		&lt;td &gt;9C27 EB2A 901F 95AD 5C3E  3F6A 537D F15D A2FD 9DBC&lt;/td&gt;
		&lt;td &gt;&lt;a href="http://www.cert.at/static/downloads/photos/RobertSchischka.jpg"&gt;&lt;img width=50 border=0 src="http://www.cert.at/static/downloads/photos/RobertSchischka.jpg" alt="picture Robert S"/&gt;&lt;/a&gt;&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr &gt;
		&lt;td &gt;Robert Waldner&lt;/td&gt;
		&lt;td &gt;C33A2BC0&lt;/td&gt;
		&lt;td &gt;401B 4257 4D23 3DFD 8E09  C1B5 B327 48AD C33A 2BC0&lt;/td&gt;
		&lt;td &gt;&lt;a href="http://www.cert.at/static/downloads/photos/RobertWaldner.jpg"&gt;&lt;img width=50 border=0 src="http://www.cert.at/static/downloads/photos/RobertWaldner.jpg" alt="picture Robert W"/&gt;&lt;/a&gt;&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr &gt;
		&lt;td &gt;Christian Wojner&lt;/td&gt;
		&lt;td &gt;770B4617&lt;/td&gt;
		&lt;td &gt;EFB8 1496 3DAA F632 7A89  0F20 6635 B222 770B 4617&lt;/td&gt;
		&lt;td &gt;&lt;a href="http://www.cert.at/static/downloads/photos/ChristianWojner.jpg"&gt;&lt;img width=50 border=0 src="http://www.cert.at/static/downloads/photos/ChristianWojner.jpg" alt="picture Christian"/&gt;&lt;/a&gt;&lt;/td&gt;
	&lt;/tr&gt;
	&lt;/tbody&gt;
&lt;/table&gt;</description>
      <pubDate>Thu, 24 Sep 2009 10:21:49 GMT</pubDate>
      <guid>http://www.cert.at/about/team/team_en.html</guid>
      <dc:creator>CERT.at</dc:creator>
      <dc:date>2009-09-24T10:21:49Z</dc:date>
    </item>
    <item>
      <title>(About us/Partners) - Partners</title>
      <link>http://www.cert.at/about/partners/partners_en.html</link>
      <description>&lt;h1&gt;Partners&lt;/h1&gt;
&lt;table width="100%" border=0 cellspacing="9" cellpadding="0"&gt;
	&lt;tr&gt;
        &lt;td align="center"&gt;
		    &lt;a href="http://www.govcert.gv.at/"&gt;
		    	&lt;img src="http://www.digitales.oesterreich.gv.at/Images/2009/10/17/1856192408.png" width="150" hei
ght="49" border="0" 
		    	     alt="GovCERT Austria" /&gt;
		   	&lt;/a&gt;
       	&lt;/td&gt;
		&lt;td &gt;
		    CERT.at is cooperation partner of the Austrian Government Computer Emergency Response Teams.
		&lt;/td&gt;
	&lt;/tr&gt;

	&lt;tr&gt;
        &lt;td align="center"&gt;
		    &lt;a href="http://www.cert.org/csirts/cert_authorized.html"&gt;
		    	&lt;img src="http://www.cert.org/csirts/images/authorized_seal.gif" width="124" height="124" border="0" 
		    	     alt="Authorized to use CERT(TM) - CERT is a mark owned by Carnegie Mellon University" /&gt;
		   	&lt;/a&gt;
       	&lt;/td&gt;
		&lt;td &gt;CERT.at is approved by &lt;a href="http://www.cert.org"&gt;CERT-CC&lt;/a&gt; - which is the original CERT of Carnegie Mellon University - 
			 as a legitimate Computer Emergency Response Team and therefore being granted the usage of the trademark "CERT".
		&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr&gt;
	    &lt;td align="center"&gt;
			&lt;a href="http://www.trusted-introducer.nl/"&gt;
				&lt;img src="http://www.trusted-introducer.nl/f/TI-accredited.jpg" width="124" border="0" alt="TI logo" /&gt;
		   	&lt;/a&gt;
	   	&lt;/td&gt;
		&lt;td &gt;CERT.at is accredited member of &lt;a href="http://www.trusted-introducer.nl/"&gt;Trusted Introducer&lt;/a&gt;. 
	&lt;/tr&gt;
	&lt;tr&gt;
	    &lt;td align="center"&gt;
			&lt;a href="http://www.first.org/"&gt;
				&lt;img src="http://www.cert.at/static/otherlogos/first.jpg" width="96" border="0" alt="FIRST logo" /&gt;
		   	&lt;/a&gt;
	   	&lt;/td&gt;
		&lt;td &gt;CERT.at is member of &lt;a href="http://www.first.org/"&gt;FIRST&lt;/a&gt;. 
	&lt;/tr&gt;
&lt;/table&gt;</description>
      <pubDate>Thu, 07 Jan 2010 15:13:10 GMT</pubDate>
      <guid>http://www.cert.at/about/partners/partners_en.html</guid>
      <dc:creator>CERT.at</dc:creator>
      <dc:date>2010-01-07T15:13:10Z</dc:date>
    </item>
    <item>
      <title>(About us/RFC 2350) - RFC 2350</title>
      <link>http://www.cert.at/about/rfc2350/rfc2350_en.html</link>
      <description>&lt;h1&gt;RFC 2350&lt;/h1&gt;
&lt;h2&gt;1. Document Information&lt;/h2&gt;
This document contains a description of CERT.at according to RFC 2350. It provides basic information about the CERT, the ways it can be contacted, describes its responsibilities and the services offered.
1.1 Date of Last Update
&lt;p /&gt;
This is version 0.6 as of 2008/06/23. 

&lt;h3&gt;1.2 Distribution List for Notifications&lt;/h3&gt;
There is no distribution list for notifications as of 2008/02.

&lt;h3&gt;1.3 Locations where this Document May Be Found&lt;/h3&gt;
The current version of this document can always be found at http://www.cert.at/about/rfc2350/.
For validation purposes, a GPG signed ASCII version of this document is located at http://www.cert.at/static/rfc2350.txt. The key used for signing is the CERT.at key as listed under &lt;a href="#2.8"&gt;2.8&lt;/a&gt;.

&lt;h2&gt;2. Contact Information&lt;/h2&gt;

&lt;h3&gt;2.1 Name of the Team&lt;/h3&gt;
CERT.at

&lt;h3&gt;2.2 Address&lt;/h3&gt;
CERT Team nic.at Karlsplatz 1/2/9 1010 Wien Austria

&lt;h3&gt;2.3 Time Zone&lt;/h3&gt;
We are located in the central European timezone (CET) which is GMT+0100 (+0200 during day-light saving time).

&lt;h3&gt;2.4 Telephone Number&lt;/h3&gt;
+43 1 5056416 78

&lt;h3&gt;2.5 Facsimile Number&lt;/h3&gt;
+43 1 5056416 79

&lt;h3&gt;2.6 Other Telecommunication&lt;/h3&gt;
None.

&lt;h3&gt;2.7 Electronic Mail Address&lt;/h3&gt;
Please send incident reports to &lt;a href="mailto:reports@cert.at"&gt;reports@cert.at&lt;/a&gt;.
&lt;p /&gt;
Non-incident related mail should be addressed to &lt;a href="mailto:team@cert.at"&gt;team@cert.at&lt;/a&gt;.

&lt;h3&gt;&lt;a name="2.8"&gt;&lt;/a&gt;2.8 Public Keys and Encryption Information&lt;/h3&gt;
CERT.at uses a master signing key to sign all keys used for operational purposes. This trust anchor is:
&lt;pre&gt;
pub   1024D/242EFA2F 2008-02-12 [expires: 2013-02-10]
      Key fingerprint = 0F71 E5DB 5A23 22AE D6A3  5706 A5A2 AC28 242E FA2F
uid                  cert.at master key &amp;lt;cert@cert.at&amp;gt;
sub   4096g/BA63C2F4 2008-02-12 [expires: 2013-02-10]
&lt;/pre&gt;
and can be found on most key-servers. Please do not use this key for communications with us.
&lt;p /&gt;
All official communication by CERT.at will be signed by the current operations key, which is as of 2008/02:
&lt;pre&gt;
pub   1024D/5C384328 2008-02-13
      Key fingerprint = 740C 68EC B6B6 2060 48A5  D49A 02FB C1EF 5C38 4328
uid                  reports@cert.at (general communication key. For incident reports) &amp;lt;reports@cert.at&amp;gt;
sub   4096g/D7071014 2008-02-13
&lt;/pre&gt;
Encrypted communications with CERT.at should use this operational key.
&lt;p /&gt;
All keys (including the keys of individual team members) can be found &lt;a href="http://www.cert.at/static/pgpkeys.asc"&gt;http://www.cert.at/static/pgpkeys.asc&lt;/a&gt;&lt;p /&gt;

&lt;h3&gt;2.9 Team Members&lt;/h3&gt;
The CERT team leader is Otmar Lendl. Other team members, along with their areas of expertise and contact information, are listed in the CERT.at web pages, at &lt;a href='http://www.cert.at/about/team/team_en.html'&gt;Team&lt;/a&gt;.
&lt;p /&gt;
Management, liaison and supervision are provided by Robert Schischka, Technical Manger of &lt;a href="http://www.nic.at"&gt;nic.at&lt;/a&gt;.&lt;p /&gt;

&lt;h3&gt;2.10 Other Information&lt;/h3&gt;

&lt;h3&gt;2.11 Points of Customer Contact&lt;/h3&gt;
The preferred method for contacting CERT.at is via e-mail. For incident reports and related issues please use &lt;a href="mailto:reports@cert.at"&gt;reports@cert.at&lt;/a&gt;. This will create a ticket in our tracking system and alert the human on duty.
&lt;p /&gt;
For general inquiries please send e-mail to &lt;a href="mailto:team@cert.at"&gt;team@cert.at&lt;/a&gt;.
&lt;p /&gt;
If it is not possible (or advisable due to security reasons) to use e-mail, you can reach us via telephone at +43 1 5056416 700.
&lt;p /&gt;
CERT.at's hours of operation are generally restricted to regular business hours.
&lt;p /&gt;
Please use our &lt;a href="/static/form.txt"&gt;incident reporting form&lt;/a&gt; (or if you prefer there is also a &lt;a href="/static/form_de.txt"&gt;german&lt;/a&gt; one).

&lt;h2&gt;3. Charter&lt;/h2&gt;

&lt;h3&gt;3.1 Mission Statement&lt;/h3&gt;
The purpose of CERT.at is to coordinate security efforts and incident response for IT-security problems on a national level in Austria.

&lt;h3&gt;&lt;a name="3.2"&gt;&lt;/a&gt;3.2 Constituency&lt;/h3&gt;
The constituency are IT-security teams and local CERTs in Austria.
&lt;p /&gt;
Pro-active and educational material will be provided for SMEs and the general public as well.

&lt;h3&gt;3.3 Sponsorship and/or Affiliation&lt;/h3&gt;
CERT.at is an initiative of nic.at, the Austrian domain registry.
&lt;p /&gt;
Funding is provided by nic.at 

&lt;h3&gt;3.4 Authority&lt;/h3&gt;
CERT.at's main purpose in incident handling is the coordination of incident response. As such, we only advise local CERTs and have no authority to demand certain actions.
We have indirect authority over AS35492 and are in very close contact with the &lt;a href="https://www.aco.net/cert.html?&amp;L=1"&gt;ACONet CERT&lt;/a&gt;.

&lt;h2&gt;4. Policies&lt;/h2&gt;

&lt;h3&gt;4.1 Types of Incidents and Level of Support&lt;/h3&gt;
CERT.at is authorized to address all types of computer security incidents which occur, or threaten to occur, in our Constituency (see &lt;a href="#3.2"&gt;3.2&lt;/a&gt;) and which require cross-organizational coordination.
&lt;p /&gt;
The level of support given by CERT.at will vary depending on the type and severity of the incident or issue, the type of constituent, the size of the user community affected, and CERT.at's resources at the time. Special attention will be give to issues affecting critical infrastructure.
&lt;p /&gt;
Note that no direct support will be given to end users; they are expected to contact their system administrator, network administrator, or department head for assistance. CERT.at will support the latter people.
&lt;p /&gt;
CERT.at is committed to keeping its constituency informed of potential vulnerabilities, and where possible, will inform this community of such vulnerabilities before they are actively exploited.

&lt;h3&gt;4.2 Co-operation, Interaction and Disclosure of Information&lt;/h3&gt;
CERT.at will cooperate with other Organisations in the Field of Computer Security. This Cooperation also includes and often requires the exchange of vital information regarding security incidents and vulnerabilities. Nevertheless CERT.at will protect the privacy of their customers, and therefore (under normal circumstances) pass on information in an anonymized way only unless other contractual agreements apply.
&lt;p /&gt;
CERT.at operates under the restrictions imposed by Austrian law. This involves careful handling of personal data as required by Austrian Data Protection law, but it is also possible that - according to Austrian law - CERT.at may be forced to disclose information due to a Court's order.

&lt;h3&gt;4.3 Communication and Authentication&lt;/h3&gt;
For normal communication not containing sensitive information CERT.at will use conventional methods like unencrypted e-mail or fax.
&lt;p /&gt;
For secure communication PGP-Encrypted e-mail or telephone will be used. If it is necessary to authenticate a person before communicating, this can be done either through existing webs of trust (e.g. FIRST, TI, …) or by other methods like call-back, mail-back or even face-to-face meeting if necessary.

&lt;h2&gt;5. Services&lt;/h2&gt;

&lt;h3&gt;5.1 Incident Response&lt;/h3&gt;
CERT.at will assist IT-security team in handling the technical and organizational aspects of incidents. In particular, it will provide assistance or advice with respect to the following aspects of incident management:

&lt;h4&gt;5.1.1. Incident Triage&lt;/h4&gt;
&lt;ul&gt;
    &lt;li&gt;
      Determining whether an incident is authentic.
    &lt;/li&gt;
    &lt;li&gt;
      Assessing and prioritizing the incident.
	&lt;/li&gt;
&lt;/ul&gt;
	
&lt;h4&gt;5.1.2. Incident Coordination&lt;/h4&gt;
&lt;ul&gt;
    &lt;li&gt;
      Determine the involved organizations.
    &lt;/li&gt;
    &lt;li&gt;
      Contact the involved organizations to investigate the incident and take the appropriate steps.
    &lt;/li&gt;
    &lt;li&gt;
      Facilitate contact to other parties which can help resolve the incident.
    &lt;/li&gt;
    &lt;li&gt;
      Send reports to other CERTs
	&lt;/li&gt;
&lt;/ul&gt;

&lt;h4&gt;5.1.3. Incident Resolution&lt;/h4&gt;
&lt;ul&gt;
    &lt;li&gt;
      Advise local security teams on appropriate actions.
    &lt;/li&gt;
    &lt;li&gt;
      Follow up on the progress of the concerned local security teams.
    &lt;/li&gt;  
    &lt;li&gt;
      Ask for reports.
    &lt;/li&gt;  
    &lt;li&gt;
      Report back.
     &lt;/li&gt;
&lt;/ul&gt;
&lt;p /&gt;
CERT.at will also collect statistics about incidents within its constituency.

&lt;h3&gt;5.2 Proactive Activities&lt;/h3&gt;
&lt;ul&gt;
    &lt;li&gt;
      CERT.at tries to raise security awareness in its constituency.
    &lt;/li&gt;
    &lt;li&gt;
      Collect contact information of local security teams.
    &lt;/li&gt;
    &lt;li&gt;
      Publish announcements concerning serious security threats.
    &lt;/li&gt;
    &lt;li&gt;
      Observer current trends in technology and distribute relevant knowledge to the constituency.
    &lt;/li&gt;
    &lt;li&gt;
      Provide fora for community building and information exchange within the constituency.
&lt;/ul&gt;

&lt;h2&gt;6. Incident Reporting Forms&lt;/h2&gt;
There are no local forms available yet. If possible, please make use of the Incident Reporting Form of the CERT Coordination Center. The current version is available from: &lt;a href="http://www.cert.org/reporting/incident_form.txt"&gt;http://www.cert.org/reporting/incident_form.txt&lt;/a&gt;.

&lt;h2&gt;7. Disclaimers&lt;/h2&gt;
While every precaution will be taken in the preparation of information, notifications and alerts, CERT.at assumes no responsibility for errors or omissions, or for damages resulting from the use of the information contained within.</description>
      <pubDate>Fri, 18 Sep 2009 14:31:10 GMT</pubDate>
      <guid>http://www.cert.at/about/rfc2350/rfc2350_en.html</guid>
      <dc:creator>CERT.at</dc:creator>
      <dc:date>2009-09-18T14:31:10Z</dc:date>
    </item>
  </channel>
</rss>

