<?xml version="1.0" encoding="UTF-8"?><rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
> <channel><title>Comments on: CWSandbox &#8211; automated online malware analysis</title> <atom:link href="http://www.rarst.net/web/cwsandbox/feed/" rel="self" type="application/rss+xml" /><link>http://www.rarst.net/web/cwsandbox/</link> <description>cynical thoughts on software, web, etc</description> <lastBuildDate>Thu, 09 Sep 2010 16:56:51 +0000</lastBuildDate> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.0.1</generator> <item><title>By: Rarst</title><link>http://www.rarst.net/web/cwsandbox/#comment-28556</link> <dc:creator>Rarst</dc:creator> <pubDate>Tue, 03 Aug 2010 04:11:16 +0000</pubDate> <guid
isPermaLink="false">http://www.rarst.net/?p=483#comment-28556</guid> <description>@AnonymousThanks for heads up, hadn&#039;t visited site in a while.</description> <content:encoded><![CDATA[<p>@Anonymous</p><p>Thanks for heads up, hadn&#8217;t visited site in a while.</p> ]]></content:encoded> </item> <item><title>By: Anonymous</title><link>http://www.rarst.net/web/cwsandbox/#comment-28501</link> <dc:creator>Anonymous</dc:creator> <pubDate>Mon, 02 Aug 2010 22:08:03 +0000</pubDate> <guid
isPermaLink="false">http://www.rarst.net/?p=483#comment-28501</guid> <description>The CWSandbox service has moved to http://www.mwanalysis.org/</description> <content:encoded><![CDATA[<p>The CWSandbox service has moved to <a
href="http://www.mwanalysis.org/">http://www.mwanalysis.org/</a></p> ]]></content:encoded> </item> <item><title>By: Rarst</title><link>http://www.rarst.net/web/cwsandbox/#comment-10729</link> <dc:creator>Rarst</dc:creator> <pubDate>Tue, 22 Sep 2009 17:56:07 +0000</pubDate> <guid
isPermaLink="false">http://www.rarst.net/?p=483#comment-10729</guid> <description>@RushIsn&#039;t it nice when some tool does the work for you? Some tasks like setting up proper sandbox are so troublesome that it lose lose - either you don&#039;t start or you spend stupid amount of time building and maintaining it.It&#039;s good there are people who aren&#039;t afraid of latter. :) I&#039;ll go spend some more insane time on my Google Charts plugin.</description> <content:encoded><![CDATA[<p>@Rush</p><p>Isn&#8217;t it nice when some tool does the work for you? Some tasks like setting up proper sandbox are so troublesome that it lose lose &#8211; either you don&#8217;t start or you spend stupid amount of time building and maintaining it.</p><p>It&#8217;s good there are people who aren&#8217;t afraid of latter. :) I&#8217;ll go spend some more insane time on my Google Charts plugin.</p> ]]></content:encoded> </item> <item><title>By: Rush</title><link>http://www.rarst.net/web/cwsandbox/#comment-10718</link> <dc:creator>Rush</dc:creator> <pubDate>Mon, 21 Sep 2009 19:55:44 +0000</pubDate> <guid
isPermaLink="false">http://www.rarst.net/?p=483#comment-10718</guid> <description>This seems to have a lot of potential. I couldnt access it yesterday, but it&#039;s working now.
I have a pretty extensive A/V software and test library with a couple thousand examples, that are great for detection rate testing. I&#039;ve kind of wondered what some of them do, but never really felt like booting them in a naked VM and monitoring the changes. This looks to be a good lazy mans alternative. In the past Ive always had to bring up a test machine and run last 100, reg snapshot, hijack this and what changed. A lot of text to go through, and less than interesting. It will be interesting to do it once or twice and compare results with theirs.
It also seems like if I had a buddy who has problem (and I always do) with an app that keeps crashing on install, that wasn&#039;t necessarily malware, it would be easier to push him the link and have him push me the results, than to have him upload it to me and messing with it myself.
Another good find. Thanks!</description> <content:encoded><![CDATA[<p>This seems to have a lot of potential. I couldnt access it yesterday, but it&#8217;s working now.<br
/> I have a pretty extensive A/V software and test library with a couple thousand examples, that are great for detection rate testing. I&#8217;ve kind of wondered what some of them do, but never really felt like booting them in a naked VM and monitoring the changes. This looks to be a good lazy mans alternative. In the past Ive always had to bring up a test machine and run last 100, reg snapshot, hijack this and what changed. A lot of text to go through, and less than interesting. It will be interesting to do it once or twice and compare results with theirs.<br
/> It also seems like if I had a buddy who has problem (and I always do) with an app that keeps crashing on install, that wasn&#8217;t necessarily malware, it would be easier to push him the link and have him push me the results, than to have him upload it to me and messing with it myself.<br
/> Another good find. Thanks!</p> ]]></content:encoded> </item> <item><title>By: Rarst</title><link>http://www.rarst.net/web/cwsandbox/#comment-10715</link> <dc:creator>Rarst</dc:creator> <pubDate>Mon, 21 Sep 2009 15:44:33 +0000</pubDate> <guid
isPermaLink="false">http://www.rarst.net/?p=483#comment-10715</guid> <description>@TranscontinentalYou are welcome. And with amount of anti-malware stuff I post about it had to click with your thoughts sooner or later. ;)</description> <content:encoded><![CDATA[<p>@Transcontinental</p><p>You are welcome. And with amount of anti-malware stuff I post about it had to click with your thoughts sooner or later. ;)</p> ]]></content:encoded> </item> <item><title>By: Transcontinental</title><link>http://www.rarst.net/web/cwsandbox/#comment-10706</link> <dc:creator>Transcontinental</dc:creator> <pubDate>Mon, 21 Sep 2009 08:40:07 +0000</pubDate> <guid
isPermaLink="false">http://www.rarst.net/?p=483#comment-10706</guid> <description>Now this is most interesting because indeed, the logical brain path of thoughts is that, if tools like Virustotal are great they do deal with installed files, when it seems so obvious that analyzing an install application before actually installing anything is the recommendation!
Thanks Rarst, because your article brings an answer to what have been my thoughts since yesterday, this is odd :)</description> <content:encoded><![CDATA[<p>Now this is most interesting because indeed, the logical brain path of thoughts is that, if tools like Virustotal are great they do deal with installed files, when it seems so obvious that analyzing an install application before actually installing anything is the recommendation!<br
/> Thanks Rarst, because your article brings an answer to what have been my thoughts since yesterday, this is odd :)</p> ]]></content:encoded> </item> </channel> </rss>
<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk
Page Caching using disk (enhanced) (user agent is rejected)
Database Caching 3/10 queries in 0.011 seconds using disk

Served from: www.rarst.net @ 2010-09-10 08:52:33 -->