<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Month of Owned Corporations</title>
	<atom:link href="http://emergentchaos.com/archives/2007/04/month-of-owned-corporations.html/feed" rel="self" type="application/rss+xml" />
	<link>http://emergentchaos.com/archives/2007/04/month-of-owned-corporations.html</link>
	<description>The Emergent Chaos Jazz Combo</description>
	<lastBuildDate>Wed, 01 Feb 2012 19:20:40 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Rick Wesson</title>
		<link>http://emergentchaos.com/archives/2007/04/month-of-owned-corporations.html/comment-page-1#comment-3531</link>
		<dc:creator>Rick Wesson</dc:creator>
		<pubDate>Thu, 19 Apr 2007 00:30:06 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=2324#comment-3531</guid>
		<description>Thanks for the questions. I&#039;ll take up the definitions you pointed out. As to hosts that host malware we have a number of sources for malware links including our own spam traps.
We take the binaries of these links and run them in a sandbox that we host on Amazon&#039;s EC2. The sandbox provides us a report which we mine to see if the binary does anything evil. If it does something like contact a IRC c&amp;c we list the source (or host) as a malware source.
there are many other items to define which I&#039;ll work on putting something on our website so there is more transparency in our reporting.
-rick
</description>
		<content:encoded><![CDATA[<p>Thanks for the questions. I&#8217;ll take up the definitions you pointed out. As to hosts that host malware we have a number of sources for malware links including our own spam traps.<br />
We take the binaries of these links and run them in a sandbox that we host on Amazon&#8217;s EC2. The sandbox provides us a report which we mine to see if the binary does anything evil. If it does something like contact a IRC c&#038;c we list the source (or host) as a malware source.<br />
there are many other items to define which I&#8217;ll work on putting something on our website so there is more transparency in our reporting.<br />
-rick</p>
]]></content:encoded>
	</item>
</channel>
</rss>

