<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Fireshark blog</title>
	<atom:link href="http://www.fireshark.org/blog/?feed=rss2" rel="self" type="application/rss+xml" />
	<link>http://www.fireshark.org/blog</link>
	<description>linking the malicious web</description>
	<lastBuildDate>Sat, 29 May 2010 16:23:13 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<item>
		<title>Next version just a bit delayed&#8230;</title>
		<link>http://www.fireshark.org/blog/?p=10</link>
		<comments>http://www.fireshark.org/blog/?p=10#comments</comments>
		<pubDate>Sat, 29 May 2010 16:04:25 +0000</pubDate>
		<dc:creator>Stephan Chenette</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.fireshark.org/blog/?p=10</guid>
		<description><![CDATA[Originally I had planed on completing the next release by end of May, but it&#8217;s looking like it will be more like the end of June now. I introduced more features I want to implement due to the email feedback, Plus i&#8217;m aligning the release  around various security conferences that are all happening later in [...]]]></description>
			<content:encoded><![CDATA[<p>Originally I had planed on completing the next release by end of May, but it&#8217;s looking like it will be more like the end of June now. I introduced more features I want to implement due to the email feedback, Plus i&#8217;m aligning the release  around various security conferences that are all happening later in the summer. Stay tuned@! Please keep on emailing me or if you&#8217;d like comment in this blog. I&#8217;m thinking if the next version has as many downloads as the firt to actuall set up a forum&#8230;.we&#8217;ll see.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.fireshark.org/blog/?feed=rss2&#038;p=10</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Plans for new version (Fireshark 1.1)</title>
		<link>http://www.fireshark.org/blog/?p=8</link>
		<comments>http://www.fireshark.org/blog/?p=8#comments</comments>
		<pubDate>Sat, 24 Apr 2010 15:17:17 +0000</pubDate>
		<dc:creator>Stephan Chenette</dc:creator>
				<category><![CDATA[Announcements]]></category>

		<guid isPermaLink="false">http://www.fireshark.org/blog/?p=8</guid>
		<description><![CDATA[I&#8217;m planing by the end of this month to release a new verision of Fireshark. Here are the proposed changes: Report Log will be in JSON format instead of YAML Included in final output will be an HTML report with a redirection graph and ingress/egress graph (many of you said you&#8217;d prefer it to be [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;m planing by the end of this month to release a new verision of Fireshark. Here are the proposed changes:</p>
<ul>
<li>Report Log will be in JSON format instead of YAML</li>
<li>Included in final output will be an HTML report with a redirection graph and ingress/egress graph (many of you said you&#8217;d prefer it to be auto-generated for you, this should not be a problem &#8211; now you won&#8217;t have to use any PERL scripts if you don&#8217;t want to!)</li>
<li>Current setup requires that you put the data.txt file in your %<em>UserProfile</em>% directory (home directory), I&#8217;m going to make this location configurable via the local interface and the network commandd interface.</li>
<li>A Fireshark instance running on a machine will be able to accept command via a network socket. The format of the commands will be in JSON format.</li>
<li>Include the ability to configure a referral in the options.</li>
<li>Include the ability to configure the user-agent in the options.</li>
<li>Include the HTTP header information in the report log.</li>
<li>Include DOM version of script and static links in reportlog</li>
<li>Although it&#8217;s in my experimentatl version, I might include in this release the ability to dump the eval and document.write statements.</li>
</ul>
<p>Update 4/24/2010</p>
<ul>
<li>Include ability to customize where fireshark stores files and reportlog</li>
</ul>
<p>That&#8217;s it for now, let me know if that list makes sense to all of you. Remember Fireshark was built to be 3/4 of what you neeed. It gets the data, I leave the other 1/4 of  the work up to you. You decide what you want to do with that data, at the same time, I want to make it useful for everyone, so that&#8217;s what I will auto-generate some basic reports, but please email me at feedback@fireshark.org to let me know what other data might be interesting to dump from Firefox to the reportlog for post-processing.</p>
<p>Thanks,<br />
Stephan<br />
P.S I&#8217;m looking for a Fireshark logo, so if there are any of you who are artistic, please send me some proposals and I&#8217;ll credit you in a blog entry for it!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.fireshark.org/blog/?feed=rss2&#038;p=8</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Fireshark 1.0 Pre-release!</title>
		<link>http://www.fireshark.org/blog/?p=4</link>
		<comments>http://www.fireshark.org/blog/?p=4#comments</comments>
		<pubDate>Wed, 21 Apr 2010 18:14:53 +0000</pubDate>
		<dc:creator>Stephan Chenette</dc:creator>
				<category><![CDATA[Announcements]]></category>

		<guid isPermaLink="false">http://www.fireshark.org/blog/?p=4</guid>
		<description><![CDATA[I&#8217;m still stuck in Spain after Blackhat Europe 2010, but I wanted to quickly send out a message to let everyone know that I have posted the pre-release version of Fireshark in the download section. The documentation and a full release will be happening this month as the pre-release has been posted because I wanted [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;m still stuck in Spain after Blackhat Europe 2010, but I wanted to  quickly send out a message to let everyone know that I have posted the pre-release version of Fireshark in the download section. The documentation and a  full release will be happening this month as the pre-release has been  posted because I wanted to make sure to give  the Blackhat attendees something to play with. In the pre-release version I have removed any of the config options and also made it so that you could only use it locally. The full release will have all the intended features, so don&#8217;t worry.  I hope for those of you that  couldn&#8217;t wait for the full documentation that my quick 2-second explanation of how to use Fireshark was  clear. If not, then wait for the videos and full docs coming  in the next few weeks!</p>
<p>As I write this from my hotel room in  Barcelona, waiting to get back to San Diego, I have managed to  check the log files for fireshark.org and I was happily surprised to see  that fireshark.xpi (the plugin file) has had over 10,000 downloads!!  WOW!@</p>
<p>I have had a few interviews with IDG and I&#8217;m sure the press  helped quite a bit in terms of exposure, but this tool has been  something I&#8217;ve wanted to release for quite a while, and I have a lot of  plans for it, both as a localized tool and eventually as something you  can interact with via a web interface&#8230;so stay tuned, lots more to  come! &#8230;OK, time for me to go out and get some more tapas!</p>
<p>Press:<br />
Fireshark plugin decodes the malicious Web (Jeremy Kirk &#8211; IDG)<span><span style="font-family: Default Sans Serif,Verdana,Arial,Helvetica,sans-serif; font-size: x-small;"><a href="https://webmail.websense.com/owa/redir.aspx?C=6e7ed384e6ec457a9dc134caa29fda58&amp;URL=http%3a%2f%2fwww.pcworld.com%2fbusinesscenter%2farticle%2f194314%2ffireshark_plugin_decodes_the_malicious_web.html" target="_blank"><br />
</a></span></span><a href="https://webmail.websense.com/owa/redir.aspx?C=6e7ed384e6ec457a9dc134caa29fda58&amp;URL=http%3a%2f%2fwww.pcworld.com%2fbusinesscenter%2farticle%2f194314%2ffireshark_plugin_decodes_the_malicious_web.html" target="_blank">http://www.pcworld.com/businesscenter/article/194314/fireshark_plugin_decodes_the_malicious_web.html</a><a href="https://webmail.websense.com/owa/redir.aspx?C=6e7ed384e6ec457a9dc134caa29fda58&amp;URL=http%3a%2f%2fwww.pcworld.com%2fbusinesscenter%2farticle%2f194314%2ffireshark_plugin_decodes_the_malicious_web.html" target="_blank"><br />
</a>Mapping the Malicious Web (Rob Lemos &#8211; Technology Review)<br />
<a href="http://www.technologyreview.com/web/24705/">http://www.technologyreview.com/web/24705/</a></p>
<p>Blog mentions:<br />
<a href="http://www.securelist.com/en/blog/2123/BlackHat_Europe_2010_Conference">http://www.securelist.com/en/blog/2123/BlackHat_Europe_2010_Conference</a><br />
<a href="http://www.cupfighter.net/index.php/2010/04/blackhateu-fireshark/">http://www.cupfighter.net/index.php/2010/04/blackhateu-fireshark/</a><br />
<a href="http://securitylabs.websense.com/content/Blogs/3578.aspx">http://securitylabs.websense.com/content/Blogs/3578.aspx</a><br />
<a href="http://www.sectechno.com/2010/04/18/blackhat-europe-fireshark-a-tool-to-link-the-malicious-web/">http://www.sectechno.com/2010/04/18/blackhat-europe-fireshark-a-tool-to-link-the-malicious-web/</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.fireshark.org/blog/?feed=rss2&#038;p=4</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

