<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://chinese.honeynet.org" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
 <title>Chinese  Chapter</title>
 <link>http://chinese.honeynet.org/chapters/china</link>
 <description>Chinese Chapter(i.e. The Artemis Project) led by Jianwei Zhuge; Research focus: client honeypot, high-interaction honeypot, malware col and analysis</description>
 <language>en</language>
<item>
 <title>What&#039;s new on PHoneyC (4): Try it out!</title>
 <link>http://chinese.honeynet.org/node/484</link>
 <description>&lt;p&gt;Hi all:&lt;/p&gt;
&lt;p&gt;       I have finished almost all the coding stuff of Project #1, now you can try out the new PHoneyC with shellcode/heapspray detection here:&lt;/p&gt;
&lt;p&gt; &lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://code.google.com/p/phoneyc/source/browse/phoneyc#phoneyc/branches/phoneyc-honeyjs&quot;&gt;http://code.google.com/p/phoneyc/source/browse/phoneyc#phoneyc/branches/phoneyc-honeyjs&lt;/a&gt;&lt;/p&gt;
&lt;p&gt; &lt;/p&gt;
&lt;p&gt;        Please feel free to report any bug or suggestion on shellcode/heapspray detection to me.&lt;/p&gt;
&lt;div class=&quot;og_rss_groups&quot;&gt;&lt;ul class=&quot;links&quot;&gt;&lt;li  class=&quot;first last og_links&quot;&gt;&lt;a href=&quot;/chapters/china&quot; class=&quot;og_links&quot;&gt;Chinese  Chapter&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;</description>
 <group domain="http://chinese.honeynet.org/gsoc/project1" xmlns="http://drupal.org/project/og">GSoC Project #1 - Develop and Improve PhoneyC</group>
 <group domain="http://chinese.honeynet.org/chapters/china" xmlns="http://drupal.org/project/og">Chinese  Chapter</group>
 <category domain="http://chinese.honeynet.org/taxonomy/term/44">gsoc</category>
 <category domain="http://chinese.honeynet.org/taxonomy/term/18">libemu</category>
 <category domain="http://chinese.honeynet.org/taxonomy/term/57">phoneyc</category>
 <category domain="http://chinese.honeynet.org/taxonomy/term/19">shellcode</category>
 <category domain="http://chinese.honeynet.org/taxonomy/term/58">spidermonkey</category>
 <pubDate>Mon, 10 Aug 2009 15:19:38 -0400</pubDate>
 <dc:creator>zhijie.chen</dc:creator>
 <guid isPermaLink="false">484 at http://chinese.honeynet.org</guid>
</item>
<item>
 <title>NtDeviceIoControlFile</title>
 <link>http://chinese.honeynet.org/node/471</link>
 <description>&lt;p&gt;As the console spy is almost finished, the next stage is mainly for network activities. Sebek Win32 version uses TDI hook to get this done. However, since getting driver object in virtualization layer is hard and TDI is TDI is on the path to deprecation, I need to find another way. The best solution seems to be hooking NtDeviceIoControlFile, the API Windows uses to do network related stuff and has been widely mentioned in malware behavior analysis papers. After some days of searching, I encounter a very useful resources today, a master thesis from TTAnalyze team:&lt;/p&gt;
&lt;p&gt; &lt;/p&gt;&lt;div class=&quot;og_rss_groups&quot;&gt;&lt;ul class=&quot;links&quot;&gt;&lt;li  class=&quot;first last og_links&quot;&gt;&lt;a href=&quot;/chapters/china&quot; class=&quot;og_links&quot;&gt;Chinese  Chapter&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;</description>
 <group domain="http://chinese.honeynet.org/gsoc/project3" xmlns="http://drupal.org/project/og">GSoC Project #3 - Qebek: QEMU Based Sebek</group>
 <group domain="http://chinese.honeynet.org/chapters/china" xmlns="http://drupal.org/project/og">Chinese  Chapter</group>
 <category domain="http://chinese.honeynet.org/taxonomy/term/99">qebek windows socket network</category>
 <pubDate>Thu, 30 Jul 2009 12:01:41 -0400</pubDate>
 <dc:creator>chengyu.song</dc:creator>
 <guid isPermaLink="false">471 at http://chinese.honeynet.org</guid>
</item>
<item>
 <title>Chinese Chapter Status Report (Period Apr 2007 to Dec 2008)</title>
 <link>http://chinese.honeynet.org/node/336</link>
 <description>&lt;p&gt;&lt;strong&gt;The Honeynet Project Chinese Chapter Status Report (Period Apr 2007 to Dec 2008)&lt;/strong&gt;&lt;br /&gt;
&lt;strong&gt;&lt;/strong&gt;&lt;br /&gt;
&lt;strong&gt;ORGANIZATION &lt;/strong&gt;&lt;br /&gt;
&lt;strong&gt;&lt;/strong&gt;&lt;br /&gt;
1. Changes in the structure of your organization.&lt;br /&gt;
All members of Chinese Chapter (i.e. The Artemis Project) are still from ERCIS, Institute of Computer Science and Technology, Peking University, China. Although we are seaking for contributors from other organizations.&lt;/p&gt;
&lt;div class=&quot;og_rss_groups&quot;&gt;&lt;ul class=&quot;links&quot;&gt;&lt;li  class=&quot;first last og_links&quot;&gt;&lt;a href=&quot;/chapters/china&quot; class=&quot;og_links&quot;&gt;Chinese  Chapter&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;&lt;p&gt;&lt;a href=&quot;http://chinese.honeynet.org/node/336&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <group domain="http://chinese.honeynet.org/chapters/china" xmlns="http://drupal.org/project/og">Chinese  Chapter</group>
 <pubDate>Wed, 14 Jan 2009 07:35:49 -0500</pubDate>
 <dc:creator>jianwei.zhuge</dc:creator>
 <guid isPermaLink="false">336 at http://chinese.honeynet.org</guid>
</item>
<item>
 <title>About The Honeynet Project</title>
 <link>http://chinese.honeynet.org/about</link>
 <description>&lt;p&gt;Founded in 1999, The Honeynet Project is an international, non-profit (501c3) research organization dedicated to improving the security of the Internet at no cost to the public. With Chapters around the world, our volunteers are firmly committed to the ideals of OpenSource. Our goal, simply put, is to make a difference. We accomplish this goal in the following three ways.  &lt;strong&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;div class=&quot;og_rss_groups&quot;&gt;&lt;ul class=&quot;links&quot;&gt;&lt;li  class=&quot;first last og_links&quot;&gt;&lt;a href=&quot;/chapters/chicago&quot; class=&quot;og_links&quot;&gt;Chicago  Chapter&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;&lt;p&gt;&lt;a href=&quot;http://chinese.honeynet.org/about&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <group domain="http://chinese.honeynet.org/chapters/westpoint" xmlns="http://drupal.org/project/og">West Point Chapter</group>
 <group domain="http://chinese.honeynet.org/chapters/uncc" xmlns="http://drupal.org/project/og">UNCC Chapter</group>
 <group domain="http://chinese.honeynet.org/chapters/unam" xmlns="http://drupal.org/project/og">UNAM Chapter</group>
 <group domain="http://chinese.honeynet.org/chapters/uk" xmlns="http://drupal.org/project/og">UK Chapter</group>
 <group domain="http://chinese.honeynet.org/chapters/taiwan" xmlns="http://drupal.org/project/og">Taiwan Chapter</group>
 <group domain="http://chinese.honeynet.org/chapters/spartandevils" xmlns="http://drupal.org/project/og">Spartan Devils Chapter</group>
 <group domain="http://chinese.honeynet.org/chapters/spain" xmlns="http://drupal.org/project/og">Spanish Chapter</group>
 <group domain="http://chinese.honeynet.org/chapters/singapore" xmlns="http://drupal.org/project/og">Singapore Chapter</group>
 <group domain="http://chinese.honeynet.org/chapters/portugal" xmlns="http://drupal.org/project/og">Portuguese Chapter</group>
 <group domain="http://chinese.honeynet.org/chapters/philippines" xmlns="http://drupal.org/project/og">Philippines Chapter</group>
 <group domain="http://chinese.honeynet.org/chapters/pakistan" xmlns="http://drupal.org/project/og">Pakistan Chapter</group>
 <group domain="http://chinese.honeynet.org/chapters/orangecounty" xmlns="http://drupal.org/project/og">Orange County  Chapter</group>
 <group domain="http://chinese.honeynet.org/chapters/norway" xmlns="http://drupal.org/project/og">Norwegian Chapter</group>
 <group domain="http://chinese.honeynet.org/chapters/newzealand" xmlns="http://drupal.org/project/og">New Zealand Chapter</group>
 <group domain="http://chinese.honeynet.org/chapters/mexico" xmlns="http://drupal.org/project/og">Mexican Chapter</group>
 <group domain="http://chinese.honeynet.org/chapters/malaysia" xmlns="http://drupal.org/project/og">Malaysian Chapter</group>
 <group domain="http://chinese.honeynet.org/chapters/hongkong" xmlns="http://drupal.org/project/og">Hong Kong Chapter</group>
 <group domain="http://chinese.honeynet.org/chapters/hawaii" xmlns="http://drupal.org/project/og">Hawaiin Chapter</group>
 <group domain="http://chinese.honeynet.org/chapters/global" xmlns="http://drupal.org/project/og">Global Chapter</group>
 <group domain="http://chinese.honeynet.org/chapters/giraffe" xmlns="http://drupal.org/project/og">Giraffe Chapter</group>
 <group domain="http://chinese.honeynet.org/chapters/germany" xmlns="http://drupal.org/project/og">German Chapter</group>
 <group domain="http://chinese.honeynet.org/chapters/france" xmlns="http://drupal.org/project/og">French  Chapter</group>
 <group domain="http://chinese.honeynet.org/chapters/czech" xmlns="http://drupal.org/project/og">Czech Chapter</group>
 <group domain="http://chinese.honeynet.org/chapters/malaysia2" xmlns="http://drupal.org/project/og">CyberSecurity Malaysia Chapter</group>
 <group domain="http://chinese.honeynet.org/chapters/china" xmlns="http://drupal.org/project/og">Chinese  Chapter</group>
 <group domain="http://chinese.honeynet.org/chapters/canada" xmlns="http://drupal.org/project/og">Canadian Chapter</group>
 <group domain="http://chinese.honeynet.org/chapters/brazil" xmlns="http://drupal.org/project/og">Brazilian  Chapter</group>
 <group domain="http://chinese.honeynet.org/chapters/australia" xmlns="http://drupal.org/project/og">Australian  Chapter</group>
 <group domain="http://chinese.honeynet.org/chapters/alaska" xmlns="http://drupal.org/project/og">Alaskan  Chapter</group>
 <group domain="http://chinese.honeynet.org/chapters/chicago" xmlns="http://drupal.org/project/og">Chicago  Chapter</group>
 <pubDate>Sun, 10 Aug 2008 20:54:48 -0400</pubDate>
 <dc:creator>drupal</dc:creator>
 <guid isPermaLink="false">67 at http://chinese.honeynet.org</guid>
</item>
</channel>
</rss>
