<?xml version="1.0" encoding="utf-8" ?>

<rss version="2.0" 
   xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
   xmlns:admin="http://webns.net/mvcb/"
   xmlns:dc="http://purl.org/dc/elements/1.1/"
   xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
   xmlns:wfw="http://wellformedweb.org/CommentAPI/"
   xmlns:content="http://purl.org/rss/1.0/modules/content/"
   xmlns:creativeCommons="http://backend.userland.com/creativeCommonsRssModule">
<channel>
    <title>honeyblog - honeynets</title>
    <link>http://honeyblog.org/</link>
    <description>A blog on honeypots, honeynets, and more...</description>
    <dc:language>en</dc:language>
    <generator>Serendipity 1.3.1-1 - http://www.s9y.org/</generator>
    <managingEditor>thorsten.holz@gmail.com</managingEditor>
<pubDate>Tue, 26 Apr 2011 21:06:18 GMT</pubDate>

    <image>
        <url>http://honeyblog.org/templates/default/img/s9y_banner_small.png</url>
        <title>RSS: honeyblog - honeynets - A blog on honeypots, honeynets, and more...</title>
        <link>http://honeyblog.org/</link>
        <width>100</width>
        <height>21</height>
    </image>

<item>
    <title>2011 Honeynet Project Security Workshop Slides + Videos</title>
    <link>http://honeyblog.org/archives/65-2011-Honeynet-Project-Security-Workshop-Slides-+-Videos.html</link>
            <category>honeynets</category>
            <category>malware</category>
    
    <comments>http://honeyblog.org/archives/65-2011-Honeynet-Project-Security-Workshop-Slides-+-Videos.html#comments</comments>
    <wfw:comment>http://honeyblog.org/wfwcomment.php?cid=65</wfw:comment>

    <wfw:commentRss>http://honeyblog.org/rss.php?version=2.0&amp;type=comments&amp;cid=65</wfw:commentRss>
    

    <author>nospam@example.com (Thorsten Holz)</author>
    <content:encoded>
    The slides and videos from the 2011 Honeynet Project Security Workshop (Paris) are now available! You can get the material from &lt;a onclick=&quot;javascript: pageTracker._trackPageview(&#039;/extlink/www.honeynet.org/SecurityWorkshops/2011_Paris&#039;);&quot;  href=&quot;http://www.honeynet.org/SecurityWorkshops/2011_Paris&quot;&gt;http://www.honeynet.org/SecurityWorkshops/2011_Paris&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
About the workshop:&lt;blockquote&gt;The workshop brought together experts in the field of information security from around the world to share the latest advances in security research. Our members covered topics such as new honeyclients, mobile malware, new reversing techniques, VOIP attacks and even social behavior of attackers. And besides the presentation, Felix Leder and Mark Schloesser from our Giraffe chapter and Guillaume Arcas from our French chapter put up some hands on exercises that allowed participants to test their skillz.&lt;/blockquote&gt;&lt;br /&gt;
 
    </content:encoded>

    <pubDate>Tue, 26 Apr 2011 23:06:18 +0200</pubDate>
    <guid isPermaLink="false">http://honeyblog.org/archives/65-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by-sa/3.0/</creativeCommons:license>
</item>
<item>
    <title>Chaosradio Express #155</title>
    <link>http://honeyblog.org/archives/60-Chaosradio-Express-155.html</link>
            <category>admin</category>
            <category>honeynets</category>
            <category>malware</category>
    
    <comments>http://honeyblog.org/archives/60-Chaosradio-Express-155.html#comments</comments>
    <wfw:comment>http://honeyblog.org/wfwcomment.php?cid=60</wfw:comment>

    <wfw:commentRss>http://honeyblog.org/rss.php?version=2.0&amp;type=comments&amp;cid=60</wfw:commentRss>
    

    <author>nospam@example.com (Thorsten Holz)</author>
    <content:encoded>
    Recently I recorded a longer podcast together with &lt;a onclick=&quot;javascript: pageTracker._trackPageview(&#039;/extlink/tim.geekheim.de/&#039;);&quot;  href=&quot;http://tim.geekheim.de/&quot;&gt;Tim Pritlove&lt;/a&gt; on malware and botnets. It was published a few days ago as &lt;a onclick=&quot;javascript: pageTracker._trackPageview(&#039;/extlink/chaosradio.ccc.de/cre155.html&#039;);&quot;  href=&quot;http://chaosradio.ccc.de/cre155.html&quot;&gt;Chaosradio Express #155&lt;/a&gt;. The podcast is in German and lasts for about 2.5 hours. The podcast is available at &lt;a onclick=&quot;javascript: pageTracker._trackPageview(&#039;/extlink/chaosradio.ccc.de/cre155.html&#039;);&quot;  href=&quot;http://chaosradio.ccc.de/cre155.html&quot;&gt;http://chaosradio.ccc.de/cre155.html&lt;/a&gt; and you can also get it via &lt;a onclick=&quot;javascript: pageTracker._trackPageview(&#039;/extlink/itunes.apple.com/de/podcast/chaosradio-express/id135057227&#039;);&quot;  href=&quot;http://itunes.apple.com/de/podcast/chaosradio-express/id135057227&quot;&gt;iTunes&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
Here the German description:&lt;br /&gt;
&lt;blockquote&gt;Malware hat sich in den letzten 10 Jahren von einem Forschungsfeld zu einer globalen Bedrohung der internationalen Dateninfrastruktur entwickelt. Botnetze stellen dabei die bedauerliche Krönung der kriminellen Aktivitäten dar und es erfordert einen großen Aufwand, diesen Systemen nachzugehen und sie wieder auszuschalten. Trotz eines fortwährenden Katz- und Mausspielchens gelingt es den Sicherheitsforschern immer wieder, große Botnetze vom Netz zu nehmen. Im Gespräch mit Tim Pritlove erläutert Thorsten Holz Geschichte und technische Hintergründe zu Malware und Botnetzen.&lt;br /&gt;
&lt;br /&gt;
Themen: wie sich Malware über die Zeit vom Experiment zum Werkzeug von Kriminellen entwickelt hat; welche Sicherheitslücken ausgenutzt werden; welche Methoden Betriebssysteme haben, sich gegen Malware zu wehren; das Layer-8-Problem; die Antiviren-Industrie; was Microsoft für seine Sicherheit getan hat; Botnetze und Spam und andere Formen der Monetarisierung; wie sich Botnetze gegen Aufklärung schützen; wie man ein Botnetz ausforscht, austrickst und lahmlegt; Botnetze aufspüren mit Honeypots; Botnetze in Behörden und Botschaften; Kommunikation und Kollaboration von Securitygruppen; technische und moralische Probleme beim Herunterfahren eines Botnets; Kooperation mit ISPs; Botnetzbekämpfung vs. Zensurinfrastruktur; Botnetze und der Mac; Konzepte für sichere Betriebssysteme; Security Usability; Automatisierte Malware Analyse.&lt;/blockquote&gt;&lt;br /&gt;
 
    </content:encoded>

    <pubDate>Thu, 10 Jun 2010 18:07:40 +0200</pubDate>
    <guid isPermaLink="false">http://honeyblog.org/archives/60-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by-sa/3.0/</creativeCommons:license>
</item>
<item>
    <title>Challenge 4 of the Forensic Challenge 2010 - VoIP</title>
    <link>http://honeyblog.org/archives/59-Challenge-4-of-the-Forensic-Challenge-2010-VoIP.html</link>
            <category>honeynets</category>
    
    <comments>http://honeyblog.org/archives/59-Challenge-4-of-the-Forensic-Challenge-2010-VoIP.html#comments</comments>
    <wfw:comment>http://honeyblog.org/wfwcomment.php?cid=59</wfw:comment>

    <wfw:commentRss>http://honeyblog.org/rss.php?version=2.0&amp;type=comments&amp;cid=59</wfw:commentRss>
    

    <author>nospam@example.com (Thorsten Holz)</author>
    <content:encoded>
    Quick blog posting about the &lt;a onclick=&quot;javascript: pageTracker._trackPageview(&#039;/extlink/honeynet.org/challenges/2010_4_voip&#039;);&quot;  href=&quot;http://honeynet.org/challenges/2010_4_voip&quot;&gt;new forensic challenge&lt;/a&gt; by the Honeynet Project:&lt;br /&gt;
&lt;br /&gt;
&lt;blockquote&gt;Challenge 4 - VoIP - (provided by Ben Reardon from the Australian and Sjur Eivind Usken from Norwegian Chapter) takes you into the world of voice communications on the Internet. VoIP with SIP is becoming the de-facto standard for voice communication on the Internet. As this technology becomes more common, malicious parties have more opportunities and stronger motives to take control of these systems to conduct nefarious activities. This Challenge is designed to examine and explore some of attributes of the SIP and RTP protocols. Enjoy the challenge.&lt;/blockquote&gt;&lt;br /&gt;
&lt;br /&gt;
You can find all info at &lt;a onclick=&quot;javascript: pageTracker._trackPageview(&#039;/extlink/honeynet.org/challenges/2010_4_voip&#039;);&quot;  href=&quot;http://honeynet.org/challenges/2010_4_voip&quot;&gt;http://honeynet.org/challenges/2010_4_voip&lt;/a&gt;. Submission deadline is June 30th 2010 - thus you still have some time to work on the challenge. You can win books, for example a signed copy of &quot;&lt;a onclick=&quot;javascript: pageTracker._trackPageview(&#039;/extlink/www.amazon.com/gp/product/0321336321&#039;);&quot;  href=&quot;http://www.amazon.com/gp/product/0321336321&quot;&gt;Virtual Honeypots: From Botnet Tracking to Intrusion Detection&lt;/a&gt;&quot; by Niels and me. 
    </content:encoded>

    <pubDate>Thu, 10 Jun 2010 16:38:56 +0200</pubDate>
    <guid isPermaLink="false">http://honeyblog.org/archives/59-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by-sa/3.0/</creativeCommons:license>
</item>
<item>
    <title>Call for Papers: LEET'10</title>
    <link>http://honeyblog.org/archives/49-Call-for-Papers-LEET10.html</link>
            <category>admin</category>
            <category>honeynets</category>
            <category>malware</category>
            <category>paper</category>
    
    <comments>http://honeyblog.org/archives/49-Call-for-Papers-LEET10.html#comments</comments>
    <wfw:comment>http://honeyblog.org/wfwcomment.php?cid=49</wfw:comment>

    <wfw:commentRss>http://honeyblog.org/rss.php?version=2.0&amp;type=comments&amp;cid=49</wfw:commentRss>
    

    <author>nospam@example.com (Thorsten Holz)</author>
    <content:encoded>
    The submissions deadline for the 3rd USENIX Workshop on Large-Scale Exploits and Emergent Threats (&lt;a onclick=&quot;javascript: pageTracker._trackPageview(&#039;/extlink/www.usenix.org/events/leet10/&#039;);&quot;  href=&quot;http://www.usenix.org/events/leet10/&quot;&gt;LEET &#039;10&lt;/a&gt;) is quickly approaching. Please submit your work by Thursday, February 25, 2010, 11:59 p.m. PST. The full call for papers is available at &lt;a onclick=&quot;javascript: pageTracker._trackPageview(&#039;/extlink/www.usenix.org/events/leet10/cfp/&#039;);&quot;  href=&quot;http://www.usenix.org/events/leet10/cfp/&quot;&gt;http://www.usenix.org/events/leet10/cfp/&lt;/a&gt;, see an overview below:&lt;br /&gt;
&lt;blockquote&gt;&lt;b&gt;Topics&lt;/b&gt;&lt;br /&gt;
Now in its third year, LEET continues to provide a unique forum for the discussion of threats to the confidentiality of our data, the integrity of digital transactions, and the dependability of the technologies we increasingly rely on. We encourage submissions of papers that focus on the malicious activities themselves (e.g., reconnaissance, exploitation, privilege escalation, rootkit installation, attack), our responses as defenders (e.g., prevention, detection, and mitigation), or the social, political, and economic goals driving these malicious activities and the legal and ethical codes guiding our defensive responses.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Overview&lt;/b&gt;&lt;br /&gt;
Information technology (IT) adds $2 trillion annually to the US economy alone. While these technologies have enabled significant global economic growth, they have become rich targets for malicious activity. The US Federal Bureau of Investigation (FBI) indicated that cyber crime reached an all-time high in 2008; cyber crime now ranks as the FBI&#039;s third highest priority, behind such dramatic threats as counter-terrorism and counter-espionage. Much of this malicious activity is driven by economic incentives, but recently we have seen the emergence of highly visible, politically motivated attacks. While the motivations for malicious behavior and the technical mechanisms that enable them remain rich areas of research, it is clear that today our global society is faced with a wide range of cyber criminal activities: spam, phishing, denial of service, click fraud, etc.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Workshop Format&lt;/b&gt;&lt;br /&gt;
LEET aims to be a true workshop, with the twin goals of fostering the development of preliminary work and helping to unify the broad community of researchers and practitioners who focus on worms, bots, spam, spyware, phishing, DDoS, and the ever-increasing palette of large-scale Internet-based threats. Intriguing preliminary results and thought-provoking ideas will be strongly favored; papers will be selected for their potential to stimulate discussion in the workshop. Each author will have 15 minutes to present his or her work, followed by 15 minutes of discussion with the workshop participants.&lt;/blockquote&gt;&lt;br /&gt;
 
    </content:encoded>

    <pubDate>Mon, 25 Jan 2010 09:03:00 +0100</pubDate>
    <guid isPermaLink="false">http://honeyblog.org/archives/49-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by-sa/3.0/</creativeCommons:license>
</item>
<item>
    <title>&quot;Studying Aspects of the Underground Economy&quot;</title>
    <link>http://honeyblog.org/archives/48-Studying-Aspects-of-the-Underground-Economy.html</link>
            <category>honeynets</category>
            <category>malware</category>
            <category>paper</category>
    
    <comments>http://honeyblog.org/archives/48-Studying-Aspects-of-the-Underground-Economy.html#comments</comments>
    <wfw:comment>http://honeyblog.org/wfwcomment.php?cid=48</wfw:comment>

    <wfw:commentRss>http://honeyblog.org/rss.php?version=2.0&amp;type=comments&amp;cid=48</wfw:commentRss>
    

    <author>nospam@example.com (Thorsten Holz)</author>
    <content:encoded>
    Today I gave a  &lt;a onclick=&quot;javascript: pageTracker._trackPageview(&#039;/extlink/www.icsi.berkeley.edu/cgi-bin/events/event.pl?ID=000563&#039;);&quot;  href=&quot;http://www.icsi.berkeley.edu/cgi-bin/events/event.pl?ID=000563&quot;&gt;talk&lt;/a&gt; at the International Computer Science Institute (&lt;a onclick=&quot;javascript: pageTracker._trackPageview(&#039;/extlink/www.icsi.berkeley.edu/about/index.html&#039;);&quot;  href=&quot;http://www.icsi.berkeley.edu/about/index.html&quot;&gt;ICSI&lt;/a&gt;) that focussed on some of the research I did in the past year. The slides are now &lt;a href=&quot;http://honeyblog.org/junkyard/presentations/10_underground-economy_ICSI.pdf&quot;&gt;available&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Abstract&lt;/b&gt;:&lt;br /&gt;
With the growing digital economy, it comes as no surprise that criminal activities in digital business have lead to a digital underground economy. Because it is such a fast-moving field, tracking and understanding this underground economy is difficult and most information in this area is vague. In this talk, we discuss several approaches to study the structure of these underground markets. In particular, we present a method with which it is possible to directly analyze the amount of data harvested through keylogger-based attacks in a highly automated fashion. Based on real-world data, we can get a glimpse into the digital underground economy. However, many open questions remain that will be discussed in the last part of the talk.&lt;br /&gt;
&lt;br /&gt;
You can get the slides at &lt;a href=&quot;http://honeyblog.org/junkyard/presentations/10_underground-economy_ICSI.pdf&quot;&gt;http:///honeyblog.org/junkyard/presentations/10_underground-economy_ICSI.pdf&lt;/a&gt;.&lt;br /&gt;
 
    </content:encoded>

    <pubDate>Wed, 20 Jan 2010 06:53:00 +0100</pubDate>
    <guid isPermaLink="false">http://honeyblog.org/archives/48-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by-sa/3.0/</creativeCommons:license>
</item>
<item>
    <title>Challenge 1 posted - Signed books as prizes!</title>
    <link>http://honeyblog.org/archives/46-Challenge-1-posted-Signed-books-as-prizes!.html</link>
            <category>honeynets</category>
            <category>malware</category>
    
    <comments>http://honeyblog.org/archives/46-Challenge-1-posted-Signed-books-as-prizes!.html#comments</comments>
    <wfw:comment>http://honeyblog.org/wfwcomment.php?cid=46</wfw:comment>

    <wfw:commentRss>http://honeyblog.org/rss.php?version=2.0&amp;type=comments&amp;cid=46</wfw:commentRss>
    

    <author>nospam@example.com (Thorsten Holz)</author>
    <content:encoded>
    The first challenge of the Honeynet Forensic Challenge 2010 has been posted at &lt;a onclick=&quot;javascript: pageTracker._trackPageview(&#039;/extlink/honeynet.org/node/504&#039;);&quot;  href=&quot;http://honeynet.org/node/504&quot;&gt;http://honeynet.org/node/504&lt;/a&gt;. The task is to analyze a packet capture that was collected by a honeypot. Analyze and answer the following questions:&lt;br /&gt;
&lt;ol&gt;&lt;li&gt;Which systems (i.e. IP addresses) are involved? (2pts)&lt;/li&gt;&lt;li&gt;What can you find out about the attacking host (e.g., where is it located)? (2pts) &lt;/li&gt;&lt;li&gt;How many TCP sessions are contained in the dump file? (2pts)&lt;/li&gt;&lt;li&gt;How long did it take to perform the attack? (2pts)&lt;/li&gt;&lt;li&gt;Which operating system was targeted by the attack? And which service? Which vulnerability? (6pts) &lt;/li&gt;&lt;li&gt;Can you sketch an overview of the general actions performed by the attacker? (6pts) &lt;/li&gt;&lt;li&gt;What specific vulnerability was attacked? (2pts) &lt;/li&gt;&lt;li&gt;What actions does the shellcode perform? Pls list the shellcode. (8pts) &lt;/li&gt;&lt;li&gt;Do you think a Honeypot was used to pose as a vulnerable victim? Why? (6pts) &lt;/li&gt;&lt;li&gt;Was there malware involved? Whats the name of the malware? (We are not looking for a detailed malware analysis for this challenge) (2pts) &lt;/li&gt;&lt;li&gt;Do you think this is a manual or an automated attack? Why? (2pts) &lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;
Get the pcap at &lt;a onclick=&quot;javascript: pageTracker._trackPageview(&#039;/extlink/honeynet.org/files/attack-trace.pcap_.gz&#039;);&quot;  href=&quot;http://honeynet.org/files/attack-trace.pcap_.gz&quot;&gt;http://honeynet.org/files/attack-trace.pcap_.gz&lt;/a&gt;, they were provided together with the questions by Tillmann Werner. Deadline for submissions is Monday, February 1st 2010 at 17:00 EST. There will be some small prizes, among them signed copies of our book &quot;&lt;a onclick=&quot;javascript: pageTracker._trackPageview(&#039;/extlink/www.amazon.com/gp/product/0321336321?ie=UTF8&amp;amp;amp;tag=honeyblogorg-20&amp;amp;amp;linkCode=as2&amp;amp;amp;camp=1789&amp;amp;amp;creative=9325&amp;amp;amp;creativeASIN=0321336321&#039;);&quot;  href=&quot;http://www.amazon.com/gp/product/0321336321?ie=UTF8&amp;amp;tag=honeyblogorg-20&amp;amp;linkCode=as2&amp;amp;camp=1789&amp;amp;creative=9325&amp;amp;creativeASIN=0321336321&quot;&gt;Virtual Honeypots: From Botnet Tracking to Intrusion Detection&lt;/a&gt;&quot;. Full information is available at &lt;a onclick=&quot;javascript: pageTracker._trackPageview(&#039;/extlink/honeynet.org/node/504&#039;);&quot;  href=&quot;http://honeynet.org/node/504&quot;&gt;http://honeynet.org/node/504&lt;/a&gt;.&lt;br /&gt;
 
    </content:encoded>

    <pubDate>Mon, 18 Jan 2010 08:56:00 +0100</pubDate>
    <guid isPermaLink="false">http://honeyblog.org/archives/46-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by-sa/3.0/</creativeCommons:license>
</item>
<item>
    <title>Honeynet Project Forensic Challenge 2010</title>
    <link>http://honeyblog.org/archives/45-Honeynet-Project-Forensic-Challenge-2010.html</link>
            <category>honeynets</category>
    
    <comments>http://honeyblog.org/archives/45-Honeynet-Project-Forensic-Challenge-2010.html#comments</comments>
    <wfw:comment>http://honeyblog.org/wfwcomment.php?cid=45</wfw:comment>

    <wfw:commentRss>http://honeyblog.org/rss.php?version=2.0&amp;type=comments&amp;cid=45</wfw:commentRss>
    

    <author>nospam@example.com (Thorsten Holz)</author>
    <content:encoded>
    Finally, after several years without any &lt;a onclick=&quot;javascript: pageTracker._trackPageview(&#039;/extlink/www.honeynet.org/challenges&#039;);&quot;  href=&quot;http://www.honeynet.org/challenges&quot;&gt;Honeynet Project Challenges&lt;/a&gt;, there will finally be new &lt;a onclick=&quot;javascript: pageTracker._trackPageview(&#039;/extlink/honeynet.org/node/503&#039;);&quot;  href=&quot;https://honeynet.org/node/503&quot;&gt;Forensic Challenges&lt;/a&gt; starting next Monday (January 18th, 2010). Here is the official announcement:&lt;br /&gt;
&lt;blockquote&gt;I am very happy to announce the Honeynet Project Forensic Challenge 2010. The purpose of the Forensic Challenges is to take learning one step farther. Instead of having the Honeynet Project analyze attacks and share their findings, Forensic Challenges give the security community the opportunity to analyze attacks and &lt;a onclick=&quot;javascript: pageTracker._trackPageview(&#039;/extlink/honeynet.org/papers&#039;);&quot;  href=&quot;http://honeynet.org/papers&quot;&gt;share their findings&lt;/a&gt;. In the end, individuals and organizations not only learn about threats, but also learn how to analyze them. Even better, individuals can access the write-ups from other individuals, and learn about new tools and techniques for analyzing attacks. Best of all, the attacks of the Forensic Challenge are attacks encountered in the wild, real hacks, provided by our members.&lt;br /&gt;
It has been several years since we provided Forensic Challenges and with the Forensic Challenge 2010, we will provide desperately needed upgrades. The Forensic Challenge 2010 will include a mixture of server-side attacks on the latest operating systems and services, attacks on client-side attacks that emerged in the past few years, attacks on VoiP systems, web applications, etc. At the end of challenge, we will provide a sample solution created by our members using the &lt;a onclick=&quot;javascript: pageTracker._trackPageview(&#039;/extlink/honeynet.org/project&#039;);&quot;  href=&quot;http://honeynet.org/project&quot;&gt;state-of-the-art tools&lt;/a&gt; that are publicly available, such as libemu and dionaea.&lt;br /&gt;
The first challenge (of several for 2010) will be posted on our &lt;a onclick=&quot;javascript: pageTracker._trackPageview(&#039;/extlink/honeynet.org/challenges&#039;);&quot;  href=&quot;http://honeynet.org/challenges&quot;&gt;Forensic Challenges web site&lt;/a&gt; on Monday, January 18th 2010. We will be open to submissions for about two weeks and announce the winners by February 15th 2010. This year, we will also award the top three submissions with prizes! Please check the web site on Monday, January 18th 2010 for further details….&lt;br /&gt;
&lt;br /&gt;
Christian Seifert&lt;/blockquote&gt;&lt;br /&gt;
Full details will be published at &lt;a onclick=&quot;javascript: pageTracker._trackPageview(&#039;/extlink/honeynet.org/challenges&#039;);&quot;  href=&quot;http://honeynet.org/challenges&quot;&gt;http://honeynet.org/challenges&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
&lt;em&gt;Update&lt;/em&gt;: The date was apparently wrong, I corrected it from January 15th to January 18th. 
    </content:encoded>

    <pubDate>Tue, 12 Jan 2010 20:22:00 +0100</pubDate>
    <guid isPermaLink="false">http://honeyblog.org/archives/45-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by-sa/3.0/</creativeCommons:license>
</item>
<item>
    <title>Know Your Tools: Use Picviz to Find Attacks </title>
    <link>http://honeyblog.org/archives/40-Know-Your-Tools-Use-Picviz-to-Find-Attacks.html</link>
            <category>honeynets</category>
    
    <comments>http://honeyblog.org/archives/40-Know-Your-Tools-Use-Picviz-to-Find-Attacks.html#comments</comments>
    <wfw:comment>http://honeyblog.org/wfwcomment.php?cid=40</wfw:comment>

    <wfw:commentRss>http://honeyblog.org/rss.php?version=2.0&amp;type=comments&amp;cid=40</wfw:commentRss>
    

    <author>nospam@example.com (Thorsten Holz)</author>
    <content:encoded>
    A new series of papers is available from the Honeynet Project: &quot;Know Your Tools&quot; deals with specific types of honeypots and explains how to use them. The first paper in this series deals with &lt;a onclick=&quot;javascript: pageTracker._trackPageview(&#039;/extlink/www.wallinfire.net/picviz&#039;);&quot;  href=&quot;http://www.wallinfire.net/picviz&quot;&gt;Picviz&lt;/a&gt;, a tool to visualize data based on parallel coordinates plots. &lt;br /&gt;
&lt;blockquote&gt;Picviz is a parallel coordinates plotter which enables easy scripting from various input (tcpdump, syslog, iptables logs, apache logs, etc..) to visualize data and discover interesting aspects of that data quickly. Picviz uncovers previously hidden data that is difficult to identify with traditional analysis methods.&lt;/blockquote&gt;&lt;br /&gt;
The paper is available at &lt;a onclick=&quot;javascript: pageTracker._trackPageview(&#039;/extlink/www.honeynet.org/node/499&#039;);&quot;  href=&quot;http://www.honeynet.org/node/499&quot;&gt;http://www.honeynet.org/node/499&quot;&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Abstract&lt;/b&gt;:&lt;br /&gt;
This document explains how Picviz can be used to spot attacks. We will use three examples in this paper; analysis of ssh connection logs, demonstration of the graphical interface on network data generated by a port scanner and the use of Picviz command line to discover attacks towards an Apache web server. Picviz can handle large amounts of data, as illustrated by the last example in which two years of raw Apache access logs are analyzed. We will show how we can find attacks that previously have been hidden and discover them in a very short time!&lt;br /&gt;
We hope Picviz will make you more efficient in analyzing any kind of log files, including network traffic, and able to spot abnormalities even with large dataset.&lt;br /&gt;
&lt;br /&gt;
 
    </content:encoded>

    <pubDate>Thu, 26 Nov 2009 11:59:00 +0100</pubDate>
    <guid isPermaLink="false">http://honeyblog.org/archives/40-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by-sa/3.0/</creativeCommons:license>
</item>
<item>
    <title>GSoC'09: Glastopf</title>
    <link>http://honeyblog.org/archives/38-GSoC09-Glastopf.html</link>
            <category>honeynets</category>
    
    <comments>http://honeyblog.org/archives/38-GSoC09-Glastopf.html#comments</comments>
    <wfw:comment>http://honeyblog.org/wfwcomment.php?cid=38</wfw:comment>

    <wfw:commentRss>http://honeyblog.org/rss.php?version=2.0&amp;type=comments&amp;cid=38</wfw:commentRss>
    

    <author>nospam@example.com (Thorsten Holz)</author>
    <content:encoded>
    Here an announcement regarding the end of GSoC&#039;09:&lt;br /&gt;
&lt;br /&gt;
Web sites are hacked all the time. Web application, database, and cross-site scripting vulnerabilities expose a large attack surface that can be exploited to, among others, deface the web site, send spam, convert web site into bots, and serve drive-by-download attacks. &lt;a onclick=&quot;javascript: pageTracker._trackPageview(&#039;/extlink/glastopf.org/&#039;);&quot;  href=&quot;http://glastopf.org/&quot;&gt;Glastopf&lt;/a&gt; is a low-interaction honeypot that emulates a vulnerable web server hosting many web pages and web applications with thousands of vulnerabilities. Glastopf is easy to setup and once indexed by search engines, attacks will pour in by the thousands daily. Glastopf has been developed as part of the &lt;a onclick=&quot;javascript: pageTracker._trackPageview(&#039;/extlink/code.google.com/soc/&#039;);&quot;  href=&quot;http://code.google.com/soc/&quot;&gt;2009 Google of Summer Code&lt;/a&gt; by student &lt;a onclick=&quot;javascript: pageTracker._trackPageview(&#039;/extlink/glasblog.1durch0.de/&#039;);&quot;  href=&quot;http://glasblog.1durch0.de/&quot;&gt;Lukas Rist&lt;/a&gt; (and mentored by me). It can be downloaded from the Glastopf trac site at &lt;a onclick=&quot;javascript: pageTracker._trackPageview(&#039;/extlink/trac.glastopf.org/trac&#039;);&quot;  href=&quot;http://trac.glastopf.org/trac&quot;&gt;http://trac.glastopf.org/trac&lt;/a&gt;. More information on Glastopf can be found on the project site at &lt;a onclick=&quot;javascript: pageTracker._trackPageview(&#039;/extlink/glastopf.org/&#039;);&quot;  href=&quot;http://glastopf.org/&quot;&gt;http://glastopf.org/&lt;/a&gt;. 
    </content:encoded>

    <pubDate>Fri, 23 Oct 2009 11:17:00 +0200</pubDate>
    <guid isPermaLink="false">http://honeyblog.org/archives/38-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by-sa/3.0/</creativeCommons:license>
</item>
<item>
    <title>&quot;Towards Proactive Spam Filtering&quot;</title>
    <link>http://honeyblog.org/archives/32-Towards-Proactive-Spam-Filtering.html</link>
            <category>honeynets</category>
            <category>malware</category>
            <category>paper</category>
    
    <comments>http://honeyblog.org/archives/32-Towards-Proactive-Spam-Filtering.html#comments</comments>
    <wfw:comment>http://honeyblog.org/wfwcomment.php?cid=32</wfw:comment>

    <wfw:commentRss>http://honeyblog.org/rss.php?version=2.0&amp;type=comments&amp;cid=32</wfw:commentRss>
    

    <author>nospam@example.com (Thorsten Holz)</author>
    <content:encoded>
    &lt;a class=&#039;serendipity_image_link&#039; href=&#039;http://honeyblog.org/uploads/paper/wordclouds/spam-wc.jpg&#039; onclick=&quot;F1 = window.open(&#039;/uploads/paper/wordclouds/spam-wc.jpg&#039;,&#039;Zoom&#039;,&#039;height=530,width=993,top=192.5,left=231,toolbar=no,menubar=no,location=no,resize=1,resizable=1,scrollbars=yes&#039;); return false;&quot;&gt;&lt;!-- s9ymdb:14 --&gt;&lt;img class=&quot;serendipity_image_left&quot; width=&quot;110&quot; height=&quot;58&quot; style=&quot;float: left; border: 0px; padding-left: 5px; padding-right: 5px;&quot; src=&quot;http://honeyblog.org/uploads/paper/wordclouds/spam-wc.serendipityThumb.jpg&quot; alt=&quot;&quot;  /&gt;&lt;/a&gt;A common technique employed by spammers is to send spam mails with the help of botnets. In a typical setting, the spammer uses so called &lt;em&gt;template-based spamming&lt;/em&gt;: the attacker sends the bots a spam template that describes the structure of the spam message to be sent. Furthermore, the attacker sends meta-data like recipient list, subject list, and a list of URLs that are used to ﬁll in variables in the template. The bots then construct an email based on the template and the meta-data, and send this email to the targets. As a result, the actual work of handling the SMTP communication is moved from the control server to the bots. Nowadays this technique is used by most large spam botnets, like Waledac, Bobax, Rustock, Cutwail, and a lot of the other major spam botnets as Joe Stewart explained &lt;a onclick=&quot;javascript: pageTracker._trackPageview(&#039;/extlink/secureworks.com/research/threats/botnets2009/&#039;);&quot;  href=&quot;http://secureworks.com/research/threats/botnets2009/&quot;&gt;in detail&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
Since spammers nowadays use such a tactic, we can also collect spam mails in a more efficient way: Instead of waiting at the end-user&#039;s mailboxes or spamtraps for mail messages to arrive and then decide whether or not this is spam, we directly interact with the servers that are used to send spam messages. The basic idea is that we execute spambots, i.e., malicious software dedicated to sending spam emails, in a controlled (honeypot) environment and collect all email messages sent by the bots. This enables us to &lt;em&gt;directly&lt;/em&gt; interfere with botnet control servers to collect &lt;em&gt;current&lt;/em&gt; spam messages sent by a speciﬁc botnet. &lt;br /&gt;
&lt;br /&gt;
We describe this idea in more detail in a short paper that was published at &lt;a onclick=&quot;javascript: pageTracker._trackPageview(&#039;/extlink/security.dico.unimi.it/dimva2009/&#039;);&quot;  href=&quot;http://security.dico.unimi.it/dimva2009/&quot;&gt;DIMVA&#039;09&lt;/a&gt;. The paper is also &lt;a href=&quot;http://honeyblog.org/junkyard/paper/proactive-spam-short-dimva09.pdf&quot;&gt;available&lt;/a&gt; on this blog.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Abstract&lt;/b&gt;: With increasing security measures in network services, remote exploitation is getting harder. As a result, attackers concentrate on more reliable attack vectors like email: victims are infected using either malicious attachments or links leading to malicious websites. Therefore eﬃcient ﬁltering and blocking methods for spam messages are needed. Unfortunately, most spam ﬁltering solutions proposed so far are reactive, they require a large amount of both ham and spam messages to eﬃciently generate rules to diﬀerentiate between both. In this paper, we introduce a more proactive approach that allows us to directly collect spam message by interacting with the spam botnet controllers. We are able to observe current spam runs and obtain a copy of latest spam messages in a fast and eﬃcient way. Based on the collected information we are able to generate templates that represent a concise summary of a spam run. The collected data can then be used to improve current spam ﬁltering techniques and develop new venues to eﬃciently ﬁlter mails.  
    </content:encoded>

    <pubDate>Fri, 31 Jul 2009 12:08:00 +0200</pubDate>
    <guid isPermaLink="false">http://honeyblog.org/archives/32-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by-sa/3.0/</creativeCommons:license>
</item>
<item>
    <title>GSoC'09: Some Updates for Glastopf</title>
    <link>http://honeyblog.org/archives/31-GSoC09-Some-Updates-for-Glastopf.html</link>
            <category>honeynets</category>
    
    <comments>http://honeyblog.org/archives/31-GSoC09-Some-Updates-for-Glastopf.html#comments</comments>
    <wfw:comment>http://honeyblog.org/wfwcomment.php?cid=31</wfw:comment>

    <wfw:commentRss>http://honeyblog.org/rss.php?version=2.0&amp;type=comments&amp;cid=31</wfw:commentRss>
    

    <author>nospam@example.com (Thorsten Holz)</author>
    <content:encoded>
    Today Lukas &lt;a onclick=&quot;javascript: pageTracker._trackPageview(&#039;/extlink/trac.1durch0.de/trac/changeset/176&#039;);&quot;  href=&quot;http://trac.1durch0.de/trac/changeset/176&quot;&gt;commited&lt;/a&gt; some major changes to &lt;a onclick=&quot;javascript: pageTracker._trackPageview(&#039;/extlink/glastopf.1durch0.de/&#039;);&quot;  href=&quot;http://glastopf.1durch0.de/&quot;&gt;glastopf&lt;/a&gt;, his &lt;a onclick=&quot;javascript: pageTracker._trackPageview(&#039;/extlink/code.google.com/soc/&#039;);&quot;  href=&quot;http://code.google.com/soc/&quot;&gt;Google Summer of Code&lt;/a&gt; project. The goal of glastopf is to learn more about attacks against web applications, mainly by attracting &lt;a onclick=&quot;javascript: pageTracker._trackPageview(&#039;/extlink/en.wikipedia.org/wiki/Remote_File_Inclusion&#039;);&quot;  href=&quot;http://en.wikipedia.org/wiki/Remote_File_Inclusion&quot;&gt;remote file inclusion&lt;/a&gt; attacks. The new version now features a new parser that should be able to handle more attacks and respond in a more flexible way. Furthermore, the connection to a central database was improved and the daemon now also drops privileges after starting up. &lt;a class=&#039;serendipity_image_link&#039; href=&#039;http://honeyblog.org/uploads/stuff/glastopf.png&#039; onclick=&quot;F1 = window.open(&#039;/uploads/stuff/glastopf.png&#039;,&#039;Zoom&#039;,&#039;height=98,width=219,top=408.5,left=618,toolbar=no,menubar=no,location=no,resize=1,resizable=1,scrollbars=yes&#039;); return false;&quot;&gt;&lt;!-- s9ymdb:17 --&gt;&lt;img class=&quot;serendipity_image_left&quot; width=&quot;110&quot; height=&quot;45&quot; style=&quot;float: left; border: 0px; padding-left: 5px; padding-right: 5px;&quot; src=&quot;http://honeyblog.org/uploads/stuff/glastopf.serendipityThumb.png&quot; alt=&quot;&quot;  /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
The software is constantly collecting information and in the next couple of weeks more analysis tools will be implemented to also process the collected data. The current glastopf implementation logs status messages to &lt;a onclick=&quot;javascript: pageTracker._trackPageview(&#039;/extlink/twitter.com/glastopf&#039;);&quot;  href=&quot;http://twitter.com/glastopf&quot;&gt;Twitter&lt;/a&gt;: &quot;&lt;a onclick=&quot;javascript: pageTracker._trackPageview(&#039;/extlink/twitter.com/glastopf/status/2745366420&#039;);&quot;  href=&quot;http://twitter.com/glastopf/status/2745366420&quot;&gt;Got 142 attacks in the last 30 minutes!&lt;/a&gt;&quot;. More than 13,000 IP addresses were observed and thousands of requests processed.&lt;br /&gt;
 
    </content:encoded>

    <pubDate>Mon, 20 Jul 2009 23:28:00 +0200</pubDate>
    <guid isPermaLink="false">http://honeyblog.org/archives/31-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by-sa/3.0/</creativeCommons:license>
</item>
<item>
    <title>GSoC Update</title>
    <link>http://honeyblog.org/archives/27-GSoC-Update.html</link>
            <category>honeynets</category>
    
    <comments>http://honeyblog.org/archives/27-GSoC-Update.html#comments</comments>
    <wfw:comment>http://honeyblog.org/wfwcomment.php?cid=27</wfw:comment>

    <wfw:commentRss>http://honeyblog.org/rss.php?version=2.0&amp;type=comments&amp;cid=27</wfw:commentRss>
    

    <author>nospam@example.com (Thorsten Holz)</author>
    <content:encoded>
    Yesterday the results of Google Summer of Code (GSoC) were released and the Honeynet Project will mentor nine students during the summer who work on different projects: &lt;a onclick=&quot;javascript: pageTracker._trackPageview(&#039;/extlink/socghop.appspot.com/org/home/google/gsoc2009/honeynet&#039;);&quot;  href=&quot;http://socghop.appspot.com/org/home/google/gsoc2009/honeynet&quot;&gt;http://socghop.appspot.com/org/home/google/gsoc2009/honeynet&lt;/a&gt;. More information is also available at the &lt;a onclick=&quot;javascript: pageTracker._trackPageview(&#039;/extlink/www.honeynet.org/gsoc&#039;);&quot;  href=&quot;http://www.honeynet.org/gsoc&quot;&gt;Honeynet Project GSoC site&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
I&#039;m happy to mentor &lt;a onclick=&quot;javascript: pageTracker._trackPageview(&#039;/extlink/glasblog.1durch0.de/&#039;);&quot;  href=&quot;http://glasblog.1durch0.de/&quot;&gt;Lukas Rist&lt;/a&gt;, who will work on &lt;a onclick=&quot;javascript: pageTracker._trackPageview(&#039;/extlink/glastopf.1durch0.de/&#039;);&quot;  href=&quot;http://glastopf.1durch0.de/&quot;&gt;Glastopf&lt;/a&gt;. The goal of the project is to learn more about attacks by emulating vulnerabilities in web applications (&quot;We have two goals: First, collecting and analyzing data and second, trying to inform compromised web page owner. Actually we are mainly collecting Remote File Inclusion attacks, but others will follow.&quot;). The source code is available at &lt;a onclick=&quot;javascript: pageTracker._trackPageview(&#039;/extlink/trac.1durch0.de/trac&#039;);&quot;  href=&quot;http://trac.1durch0.de/trac&quot;&gt;http://trac.1durch0.de/trac&lt;/a&gt; and will be improver during the GSoC period.&lt;br /&gt;
 
    </content:encoded>

    <pubDate>Tue, 21 Apr 2009 16:00:00 +0200</pubDate>
    <guid isPermaLink="false">http://honeyblog.org/archives/27-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by-sa/3.0/</creativeCommons:license>
</item>
<item>
    <title>LEET'09 Taking Place Soon</title>
    <link>http://honeyblog.org/archives/25-LEET09-Taking-Place-Soon.html</link>
            <category>honeynets</category>
            <category>malware</category>
            <category>paper</category>
    
    <comments>http://honeyblog.org/archives/25-LEET09-Taking-Place-Soon.html#comments</comments>
    <wfw:comment>http://honeyblog.org/wfwcomment.php?cid=25</wfw:comment>

    <wfw:commentRss>http://honeyblog.org/rss.php?version=2.0&amp;type=comments&amp;cid=25</wfw:commentRss>
    

    <author>nospam@example.com (Thorsten Holz)</author>
    <content:encoded>
    Join us at the 2nd USENIX Workshop on Large-Scale Exploits and Emergent Threats: Botnets, Spyware, Worms, and More (&lt;a onclick=&quot;javascript: pageTracker._trackPageview(&#039;/extlink/www.usenix.org/events/leet09/&#039;);&quot;  href=&quot;http://www.usenix.org/events/leet09/&quot;&gt;LEET&#039;09&lt;/a&gt;), which will take place in Boston, MA, on April 21, 2009. LEET &#039;09 will focus on the underlying mechanisms used to compromise and control hosts, the large-scale &quot;applications&quot; being perpetrated upon this framework, and the social and economic networks driving these threats. Sessions include Malware Analysis, Ethics in Botnet Research, Malware Behavior, and more.&lt;br /&gt;
&lt;br /&gt;
The full program is available at &lt;a onclick=&quot;javascript: pageTracker._trackPageview(&#039;/extlink/www.usenix.org/events/leet09/tech/&#039;);&quot;  href=&quot;http://www.usenix.org/events/leet09/tech/&quot;&gt;http://www.usenix.org/events/leet09/tech/&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
LEET &#039;09 will also include a session for Work-in-Progress reports. We encourage you to submit an abstract or proposal for a 5-minute presentation on your preliminary work to leet09wips@usenix.org.&lt;br /&gt;
&lt;br /&gt;
Connect with the broad community of researchers and practitioners who focus on worms, bots, spam, spyware, phishing, DDoS, and the ever-increasing palette of large-scale Internet-based threats in fostering the development of preliminary work in this diverse area and stimulating discussion of thought-provoking ideas.&lt;br /&gt;
&lt;br /&gt;
Find out more and register today at &lt;a onclick=&quot;javascript: pageTracker._trackPageview(&#039;/extlink/www.usenix.org/leet09/&#039;);&quot;  href=&quot;http://www.usenix.org/leet09/&quot;&gt;http://www.usenix.org/leet09/&lt;/a&gt;&lt;br /&gt;
 
    </content:encoded>

    <pubDate>Tue, 07 Apr 2009 08:38:00 +0200</pubDate>
    <guid isPermaLink="false">http://honeyblog.org/archives/25-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by-sa/3.0/</creativeCommons:license>
</item>
<item>
    <title>Google Summer of Code 2009</title>
    <link>http://honeyblog.org/archives/23-Google-Summer-of-Code-2009.html</link>
            <category>honeynets</category>
    
    <comments>http://honeyblog.org/archives/23-Google-Summer-of-Code-2009.html#comments</comments>
    <wfw:comment>http://honeyblog.org/wfwcomment.php?cid=23</wfw:comment>

    <wfw:commentRss>http://honeyblog.org/rss.php?version=2.0&amp;type=comments&amp;cid=23</wfw:commentRss>
    

    <author>nospam@example.com (Thorsten Holz)</author>
    <content:encoded>
    The Honeynet Project was selected for this year&#039;s &lt;a onclick=&quot;javascript: pageTracker._trackPageview(&#039;/extlink/socghop.appspot.com/&#039;);&quot;  href=&quot;http://socghop.appspot.com/&quot;&gt;Google Summer of Code&lt;/a&gt;. If you are a student and interested in participating  in the program, please take a look at &lt;a onclick=&quot;javascript: pageTracker._trackPageview(&#039;/extlink/www.honeynet.org/gsoc&#039;);&quot;  href=&quot;http://www.honeynet.org/gsoc&quot;&gt;http://www.honeynet.org/gsoc&lt;/a&gt;. There you will find all information about the projects related to the Honeynet Project. Google will begin accepting applications from students beginning today, thus you need to be quick... 
    </content:encoded>

    <pubDate>Mon, 23 Mar 2009 14:14:00 +0100</pubDate>
    <guid isPermaLink="false">http://honeyblog.org/archives/23-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by-sa/3.0/</creativeCommons:license>
</item>
<item>
    <title>Learning more about RFI Attacks</title>
    <link>http://honeyblog.org/archives/22-Learning-more-about-RFI-Attacks.html</link>
            <category>honeynets</category>
    
    <comments>http://honeyblog.org/archives/22-Learning-more-about-RFI-Attacks.html#comments</comments>
    <wfw:comment>http://honeyblog.org/wfwcomment.php?cid=22</wfw:comment>

    <wfw:commentRss>http://honeyblog.org/rss.php?version=2.0&amp;type=comments&amp;cid=22</wfw:commentRss>
    

    <author>nospam@example.com (Thorsten Holz)</author>
    <content:encoded>
    As part of the work at our &lt;a onclick=&quot;javascript: pageTracker._trackPageview(&#039;/extlink/pi1.informatik.uni-mannheim.de/&#039;);&quot;  href=&quot;http://pi1.informatik.uni-mannheim.de/&quot;&gt;lab&lt;/a&gt; we started to work on methods to learn more about remote file inclusion (RFI) attacks. The Internet Storm Center has developed a web-based honeypot which is available in a &lt;a onclick=&quot;javascript: pageTracker._trackPageview(&#039;/extlink/sites.google.com/site/webhoneypotsite/&#039;);&quot;  href=&quot;http://sites.google.com/site/webhoneypotsite/&quot;&gt;beta version&lt;/a&gt;. This honeypot can be used to collect information about different kinds of attacks, but requires the participant to install and maintain a honeypot on his own. For example, it is possible to deploy this honeypot on a &lt;a onclick=&quot;javascript: pageTracker._trackPageview(&#039;/extlink/hype-free.blogspot.com/2009/03/installing-webhoneypot-on-openwrt.html&#039;);&quot;  href=&quot;http://hype-free.blogspot.com/2009/03/installing-webhoneypot-on-openwrt.html&quot;&gt;OpenWrt router&lt;/a&gt;. &lt;br /&gt;
Since we are aiming only at RFI attacks, an easier approach is to redirect incoming malicious request to a central honeypot which then aggregates the information. Jan already &lt;a onclick=&quot;javascript: pageTracker._trackPageview(&#039;/extlink/zeroq.kulando.de/post/2009/03/10/collecting-rfi-data&#039;);&quot;  href=&quot;http://zeroq.kulando.de/post/2009/03/10/collecting-rfi-data&quot;&gt;blogged about this idea&lt;/a&gt;, this posting is meant to spread the word.&lt;br /&gt;
&lt;br /&gt;
You can help us by using the following &lt;a onclick=&quot;javascript: pageTracker._trackPageview(&#039;/extlink/httpd.apache.org/docs/trunk/howto/htaccess.html&#039;);&quot;  href=&quot;http://httpd.apache.org/docs/trunk/howto/htaccess.html&quot;&gt;.htaccess&lt;/a&gt; file on your web server:&lt;br /&gt;
&lt;pre&gt;Options +FollowSymlinks
RewriteEngine on
RewriteCond %{QUERY_STRING} (.+=http:\/\/.+)
RewriteRule ^(.+)$ http://link.informatik.uni-mannheim.de/$1?%1 [R,NC] &lt;/pre&gt;The script checks if the incoming request looks like an RFI attack (RewriteCond) and then redirects this request to one of our honeypots (RewriteRule). Please let us know if you have any questions or ideas.&lt;br /&gt;
 
    </content:encoded>

    <pubDate>Sat, 21 Mar 2009 10:59:00 +0100</pubDate>
    <guid isPermaLink="false">http://honeyblog.org/archives/22-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by-sa/3.0/</creativeCommons:license>
</item>

</channel>
</rss>
