<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Infosanity&#039;s Blog &#187; honeypot</title>
	<atom:link href="http://blog.infosanity.co.uk/category/honeypot/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.infosanity.co.uk</link>
	<description>Offensive and Defensive IT Security</description>
	<lastBuildDate>Sun, 28 Feb 2010 12:43:31 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<cloud domain='blog.infosanity.co.uk' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://www.gravatar.com/blavatar/f0350d3bea8a050ccac1e7c2b067d03b?s=96&#038;d=http://s2.wp.com/i/buttonw-com.png</url>
		<title>Infosanity&#039;s Blog &#187; honeypot</title>
		<link>http://blog.infosanity.co.uk</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://blog.infosanity.co.uk/osd.xml" title="Infosanity&#039;s Blog" />
	<atom:link rel='hub' href='http://blog.infosanity.co.uk/?pushpress=hub'/>
		<item>
		<title>Building Dionaea</title>
		<link>http://blog.infosanity.co.uk/2010/01/26/building-dionaea/</link>
		<comments>http://blog.infosanity.co.uk/2010/01/26/building-dionaea/#comments</comments>
		<pubDate>Tue, 26 Jan 2010 19:26:55 +0000</pubDate>
		<dc:creator>Andrew Waite</dc:creator>
				<category><![CDATA[Dionaea]]></category>
		<category><![CDATA[honeypot]]></category>

		<guid isPermaLink="false">http://infosanity.wordpress.com/?p=456</guid>
		<description><![CDATA[As part of a new and improved environment I've just finished building up a new Dionaea system. Despite the ease at which I found the install of my original system I received a lot a feedback that others had a fair amount of difficulty during system build. So this time around I decided to pay closer attention to by progress to try and assist others going through the same process.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.infosanity.co.uk&blog=8614004&post=456&subd=infosanity&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>As part of a new and improved environment I&#8217;ve just finished building up a new Dionaea system. Despite the ease at which I found the install of my <a title="InfoSanity: Starting with Dionaea" href="http://infosanity.wordpress.com/2009/11/09/starting-with-dionaea/">original system</a> I received a lot a feedback that others had a fair amount of difficulty during system build. So this time around I decided to pay closer attention to by progress to try and assist others going through the same process.</p>
<p>Unfortunately I&#8217;m not sure I&#8217;m going to be able to offer as many pearls of wisdom as I originally hoped as my install went relatively smoothly. Only real problem I hit was that after following Markus&#8217; (good documentation) my build didn&#8217;t correctly link to libemu. Bottom line, keep an eye on the output of <em>./configure</em> when building Dionaea. In my case the parameters passed to the configure script didn&#8217;t match my system so needed to be modified accordingly.</p>
<p>On the off chance that it&#8217;s of use to others (or I forget my past failures and need a memory aid) my modified ./configure command is below:</p>
<pre>./configure --with-lcfg-include=/opt/dionaea/include/ \
--with-lcfg-lib=/opt/dionaea/lib/liblcfg/ \
--with-python=/opt/dionaea/bin/python3.1 \
--with-cython-dir=/usr/bin \
--with-udns-include=/opt/dionaea/include/ \
--with-udns-lib=/opt/dionaea/lib/ \
--with-emu-include=/opt/dionaea/include/ \
--with-emu-lib=/opt/dionaea/libemu/ \
--with-gc-include=/usr/include/gc \
--with-ev-include=/opt/dionaea/include \
--with-ev-lib=/opt/dionaea/lib \
--with-nl-include=/opt/dionaea/include \
--with-nl-lib=/opt/dionaea/lib/ \
--with-curl-config=/opt/dionaea/bin/ \
--with-pcap-include=/opt/dionaea/include \
--with-pcap-lib=/opt/dionaea/lib/ \
--with-glib=/opt/dionaea
</pre>
<p>&#8211; Andrew Waite</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/infosanity.wordpress.com/456/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/infosanity.wordpress.com/456/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/infosanity.wordpress.com/456/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/infosanity.wordpress.com/456/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/infosanity.wordpress.com/456/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/infosanity.wordpress.com/456/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/infosanity.wordpress.com/456/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/infosanity.wordpress.com/456/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/infosanity.wordpress.com/456/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/infosanity.wordpress.com/456/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.infosanity.co.uk&blog=8614004&post=456&subd=infosanity&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.infosanity.co.uk/2010/01/26/building-dionaea/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/78c9d658d90cad982bfc9af08a2ff8dd?s=96&#38;d=http%3A%2F%2Fa.wordpress.com%2Fi%2Fmu.gif&#38;r=G" medium="image">
			<media:title type="html">Infosanity</media:title>
		</media:content>
	</item>
		<item>
		<title>Starting with HoneyD</title>
		<link>http://blog.infosanity.co.uk/2010/01/19/starting-with-honeyd/</link>
		<comments>http://blog.infosanity.co.uk/2010/01/19/starting-with-honeyd/#comments</comments>
		<pubDate>Tue, 19 Jan 2010 20:59:37 +0000</pubDate>
		<dc:creator>Andrew Waite</dc:creator>
				<category><![CDATA[honeypot]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[lab]]></category>
		<category><![CDATA[tool-kit]]></category>

		<guid isPermaLink="false">http://infosanity.wordpress.com/?p=440</guid>
		<description><![CDATA[Since reading Virtual Honeypots I've been wanting to implement a HoneyD system, developed by Niels Provos. From it's own site, HoneyD is a small daemon that creates virtual hosts on a network. The hosts can be configured to run arbitrary services, and their personality can be adapted so that they appear to be running certain operating systems. Honeyd enables a single host to claim multiple addresses - I have tested up to 65536 - on a LAN for network simulation. Honeyd improves cyber security by providing mechanisms for threat detection and assessment. It also deters adversaries by hiding real systems in the middle of virtual systems.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.infosanity.co.uk&blog=8614004&post=440&subd=infosanity&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>Since reading <a title="InfoSanity: Review Virtual Honeypots" href="http://infosanity.wordpress.com/2010/01/10/book-review-virtual-honeypots/">Virtual Honeypots</a> I&#8217;ve been wanting to implement a <a title="HoneyD" href="http://www.honeyd.org/">HoneyD</a> system, developed by Niels Provos. From it&#8217;s own site, HoneyD is:</p>
<blockquote><p>a small daemon that creates virtual hosts on a network.  The hosts can be configured to run arbitrary services, and their personality can be adapted so that they appear to be running certain operating systems.  Honeyd enables a single host to claim multiple addresses &#8211; I have tested up to 65536 &#8211; on a LAN for network simulation.  Honeyd improves <a href="http://www.citi.umich.edu/u/provos/cybersecurity/">cyber security</a> by providing mechanisms for threat detection and assessment.  It also deters adversaries by hiding real systems in the middle of virtual systems.</p></blockquote>
<p>My <a title="@infosanity honeyd frustration" href="http://twitter.com/Infosanity/status/7797778327">initial experience</a> getting HoneyD running was frustration to say the least. Going with Debian to provide a stable OS, the install process should have been as simple as <em>apt-get install honeyd</em>. While keeping upto date with a Debian system can sometimes be difficult, the honeyd package is as current as it gets with version 1.5c.</p>
<p>For reasons that I can&#8217;t explain, this didn&#8217;t work first (or second) time so I reverted to compiling from source. The process could have been worse, only real stumbling block I hit was a naming clash within Debian&#8217;s package names. HoneyD requires the &#8216;dumb network&#8217; package <a title="Libdnet" href="http://libdnet.sourceforge.net/">libdnet</a>, but if you <em>apt-get install libdnet </em>you get Debian&#8217;s DECnet libraries. On Debian and deriviates you need libdumbnet1.</p>
<p>HoneyD&#8217;s configuration has the ability to get <strong>very</strong> complex depending on what you are looking to achieve. Thankfully a sample configuration is provided that includes examples of some of the most common configuration directives. Once you&#8217;ve got a config sorted (the sample works perfectly for testing), starting the honeyd is simple: <em>honeyd -f /path/to/config-file</em>. There are plenty of other runtime options available, but I haven&#8217;t had time to fully experiment with all of them; check the <a title="HoneyD man page" href="http://www.citi.umich.edu/u/provos/honeyd/honeyd-man.pdf">honeyd man</a> pages for more information.</p>
<p>As well as emulating hosts and network topologies, HoneyD can be configured to run what it terms &#8217;subsystems&#8217;. Basically this are scripts that can be used to provide additional functionality on the emulated systems for an attacker/user to interact with. Some basic (and not so basic) subsystems are included with HoneyD. Some additional service emulation scripts that have been contributed to the HoneyD project can be found <a title="HoneyD Service scripts" href="http://www.honeyd.org/contrib.php">here</a>. As part of the configuration, HoneyD can also pass specified IP/Ports through to live systems, either more indepth/specialised honeypot system or a full &#8216;real&#8217; system to combine low and high interaction honeypot.</p>
<p>I&#8217;m still bearly scratching the surface of what HoneyD is capable of, and haven&#8217;t yet transfered my system to a live network to generate any statistics, but from my reading, research and experimentation I have high expectations.</p>
<p>&#8211; Andrew Waite</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/infosanity.wordpress.com/440/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/infosanity.wordpress.com/440/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/infosanity.wordpress.com/440/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/infosanity.wordpress.com/440/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/infosanity.wordpress.com/440/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/infosanity.wordpress.com/440/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/infosanity.wordpress.com/440/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/infosanity.wordpress.com/440/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/infosanity.wordpress.com/440/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/infosanity.wordpress.com/440/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.infosanity.co.uk&blog=8614004&post=440&subd=infosanity&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.infosanity.co.uk/2010/01/19/starting-with-honeyd/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/78c9d658d90cad982bfc9af08a2ff8dd?s=96&#38;d=http%3A%2F%2Fa.wordpress.com%2Fi%2Fmu.gif&#38;r=G" medium="image">
			<media:title type="html">Infosanity</media:title>
		</media:content>
	</item>
		<item>
		<title>Book Review: Virtual Honeypots</title>
		<link>http://blog.infosanity.co.uk/2010/01/10/book-review-virtual-honeypots/</link>
		<comments>http://blog.infosanity.co.uk/2010/01/10/book-review-virtual-honeypots/#comments</comments>
		<pubDate>Sun, 10 Jan 2010 13:36:11 +0000</pubDate>
		<dc:creator>Andrew Waite</dc:creator>
				<category><![CDATA[honeypot]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[malware]]></category>

		<guid isPermaLink="false">http://infosanity.wordpress.com/?p=417</guid>
		<description><![CDATA[It took longer than I had wanted, but I have just finished reading through Virtual Honeypots: From Botnet Tracking to Intrusion Detection. The book is written by Niels Provos, creator of HoneyD (among other things) and Thorsten Holz. Given the authors I had high expectation when the delivery came through, thankfully it didn't disappoint.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.infosanity.co.uk&blog=8614004&post=417&subd=infosanity&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://infosanity.files.wordpress.com/2010/01/virtual-honeypots-front-cover1.jpg"><img class="alignright size-medium wp-image-420" title="Virtual Honeypots-Front cover" src="http://infosanity.files.wordpress.com/2010/01/virtual-honeypots-front-cover1.jpg?w=226&#038;h=300" alt="" width="226" height="300" /></a>It took longer than I had wanted, but I have just finished reading through <a title="Amazon: Virtual Honeypots" href="http://www.amazon.co.uk/Virtual-Honeypots-Tracking-Intrusion-Detection/dp/0321336321/">Virtual Honeypots: From Botnet Tracking to Intrusion Detection.</a> The book is written by <a title="Neils Provos" href="http://www.citi.umich.edu/u/provos/">Niels Provos</a>, creator of HoneyD (among other things) and <a title="Thorsten Holz" href="http://honeyblog.org/">Thorsten Holz</a>.</p>
<p>Given the authors I had high expectation when the delivery came through, thankfully it didn&#8217;t disappoint. Unsurprisingly the first chapter provides an overview of honypotting in general, covering high and low interaction systems over both physical and virtual systems, additionally the chapter introduces some core tools for your toolkit.</p>
<p>The next two chapters cover both high and low interaction honeypots respectively. I really liked the coverage of hi-int honeypots, it was this idea that drew me towards honeypots in the first place the idea of watching an attacker carefully exploit and utilise a dummy system always appealed. The material provided gives a great foundation for starting with a high interaction honeypot and some best practice advice for how to do so securely and safely. While I have read many reports and case studies that involved honeypots I have had difficulty finding in depth setup information and advice, leaving high interaction honeypots feeling a bit like black magic. The author&#8217;s information cuts through all the mystery allowing the reader to get a firm understanding of the topic. Likewise the discussion of low-interaction honeypots was equally well covered, although as I&#8217;ve spent some time with low-int systems in the past this chapter was more of a refresher than providing unknown information as I had found with the hi-int section.</p>
<p>Given that Neils is one of the books authors, it shouldn&#8217;t be too much of a surprise that <a title="Honeyd.org" href="http://www.honeyd.org/">HoneyD</a> is covered in depth. For me, this was the most useful section of the book. As honeyd is one of the older publicly available low-int systems I had mistakenly assumed that one of the newer systems would provide more functionality, after reading through the material and regularly going &#8216;ooh&#8217; out loud honeyd is now firmly at the top of my &#8216;need to implement&#8217; list.</p>
<p>The book also covers honeypot systems that are designed for specialised purposes. For malware collection, the authors mainly focus on <a title="Nepenthes" href="http://nepenthes.carnivore.it/">Nepenthes</a>, but also touch on <a title="HoneyTrap" href="http://honeytrap.carnivore.it/">Honeytrap</a> among others. This was the only section that I found to be slightly dated, as the Nepenthes&#8217; newly released sprirtual successor <a title="Dionaea" href="http://dionaea.carnivore.it/">Dionaea</a> was not covered. But as the fundamental material is very well explained, Nepenthes is still a very functional system and the inherent similarities between Nepenthes and Dionaea the material still useful regardless so the chapter still provides an excellent foundation if you&#8217;re wanting to start collecting malware.</p>
<p>An interesting chapter covers the idea of hybrid honeypots, which is the idea of using low-int systems to monitor and handle the bulk of traffic, while forwarding anything unknown or unusual to a high-int system for more indepth analysis of the attack traffic. Unfortunately at this point openly available hybrid systems are limited, with the more functional systems being kept closed by the researchers and companies that build them (but I have just found <a title="HoneyBrid" href="https://www.honeynet.org/node/430">Honeybrid</a> while looking for a good link for hybrid systems which I wasn&#8217;t aware of. Looks promising&#8230;)</p>
<p>The last chapter covering honeypot systems looks at client-side honeypots, designed to look for client-side attacks. As client-side attacks have become more prominent over the last few years this is an evolving area of research, but as the attack vector is newer than traditional attacks, the honeypot systems aren&#8217;t as mature as more traditional systems. This isn&#8217;t an area that I&#8217;m experienced with so I can&#8217;t comment too much on the systems detailed by the authors, but they cover several honeyclient systems in great detail, and I&#8217;m intending to use the chapter as a foundation for implementing the systems and techniques proposed.</p>
<p>As well as detailing the use of honeypot systems, the authors also provide a brilliant discussion of ways that attackers (or users) can determine that they are interacting with a honeypot system. While the detailed descriptions for ways to identify a honeypot system is interesting and important from a theoretical standpoint, from previous experience running honeypot systems there are more than enough attackers and automated threats that blindly assume the system is legitimate to still enable honeypots to provide plenty of benefit to the honeypot administrators.</p>
<p>The book finishes up with an fairly detailed discussion of both tracking botnets using the information gathered from honeypot systems (this chapter is available as a sample PDF download from thanks to InformIT, <a href="http://www.informit.com/store/product.aspx?isbn=0321336321">here</a>) and analysing the malware sample reports provided by CWSandbox. While both chapters are useful in he context of honeypot systems I didn&#8217;t think there was enough room to provide the reader with anything beyond a general overview of the topics, which if you were interested in the topic enough to purchase the book, then the reader will likely already have a similar level of understanding to the information provided.</p>
<p>There is also a chapter covering case studies of actual incidents that were captured by the books authors during their research. I&#8217;ve always been a fan of case studies, so enjoyed this chapter, it definitely helps whet the appetite to implement the technologies covered by the book.</p>
<p>Overall I really enjoyed the book, if you&#8217;re interested in systems and network monitoring, honeypots or malware then this book should probably be on your bookshelf.</p>
<p>&#8211;<a title="Bio - Andrew Waite" href="http://infosanity.wordpress.com/about/bio-andrew-waite/">Andrew Waite</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/infosanity.wordpress.com/417/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/infosanity.wordpress.com/417/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/infosanity.wordpress.com/417/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/infosanity.wordpress.com/417/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/infosanity.wordpress.com/417/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/infosanity.wordpress.com/417/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/infosanity.wordpress.com/417/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/infosanity.wordpress.com/417/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/infosanity.wordpress.com/417/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/infosanity.wordpress.com/417/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.infosanity.co.uk&blog=8614004&post=417&subd=infosanity&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.infosanity.co.uk/2010/01/10/book-review-virtual-honeypots/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/78c9d658d90cad982bfc9af08a2ff8dd?s=96&#38;d=http%3A%2F%2Fa.wordpress.com%2Fi%2Fmu.gif&#38;r=G" medium="image">
			<media:title type="html">Infosanity</media:title>
		</media:content>

		<media:content url="http://infosanity.files.wordpress.com/2010/01/virtual-honeypots-front-cover1.jpg?w=226" medium="image">
			<media:title type="html">Virtual Honeypots-Front cover</media:title>
		</media:content>
	</item>
		<item>
		<title>2009: A review</title>
		<link>http://blog.infosanity.co.uk/2009/12/17/2009-a-review/</link>
		<comments>http://blog.infosanity.co.uk/2009/12/17/2009-a-review/#comments</comments>
		<pubDate>Thu, 17 Dec 2009 14:52:53 +0000</pubDate>
		<dc:creator>Andrew Waite</dc:creator>
				<category><![CDATA[honeypot]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[lab]]></category>
		<category><![CDATA[presentation]]></category>

		<guid isPermaLink="false">http://infosanity.wordpress.com/?p=409</guid>
		<description><![CDATA[Well, the year is nearly over and it seems everyone is in a reflective mode so I thought I'd join in. And I'm glad I did, didn't really just how turbulent year I've had.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.infosanity.co.uk&blog=8614004&post=409&subd=infosanity&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>Well, the year is nearly over and it seems everyone is in a reflective mode so I thought I&#8217;d join in. And I&#8217;m glad I did, didn&#8217;t really just how turbulent year I&#8217;ve had. I&#8217;d better (on pain of death) start with the none technical, as it is around 12 months since I got engaged to my long-time girlfriend.</p>
<p><strong>Back to the technical</strong>: The InfoSanity blog went live in February with the <a title="InfoSanity: Welcome" href="http://infosanity.wordpress.com/2009/02/16/welcome/">first post</a>. Originally I was far from confident that I would be able to keep up blogging as I had a &#8216;fear&#8217; of social media and web2.0, but nearly a year on I&#8217;m still here and despite some peaks and troughs posting articles regularly. I&#8217;ve found it a great platform for getting ideas out of my head and into practice, hopefully I&#8217;ve managed to be of benefit to others in the process.</p>
<p><strong>Lab environment</strong>: February was also when I purchased the server for my <a title="InfoSanity: Virtual Lab" href="http://infosanity.wordpress.com/2009/02/16/lab-environment/">virtual lab</a> environment. This has got be the best buy of the year, providing a solid framework for testing and experimenting with everything else I have done this year. Lab environments also seem to be one of the areas that gathers a lot of interest from others, the two posts discussing configuration of <a title="InfoSanity: Virtual Networks" href="http://infosanity.wordpress.com/2009/10/12/virtual-lab-machines/">virtual networks</a> and <a title="InfoSanity: Virtual lab machines" href="http://infosanity.wordpress.com/2009/10/12/virtual-lab-machines/">guest systems</a> were InfoSanity&#8217;s most popular posts this year by a good margin. In the process of improving my lab environment I also read Thomas Wilhelm&#8217;s <a title="Amazon: Wilhelm's professional penetration testing" href="http://www.amazon.com/dp/1597494259?tag=thedigitalcon-20&amp;camp=14573&amp;creative=327641&amp;linkCode=as1&amp;creativeASIN=1597494259&amp;adid=0Y8HGFCTQD5BSDGWY1YF&amp;">Professional Penetration Testing</a> book and reviewed it for the <a title="Ethical Hacker Network - Book Review" href="http://www.ethicalhacker.net/content/view/277/1/">Ethical Hacker Network</a>, for which I&#8217;m indebted to Don for organising.</p>
<p><strong>Wireless: </strong>Included in my long list of purchases this year was an <a title="InfoSanity: Alfa Wireless" href="http://infosanity.wordpress.com/2009/04/12/new-alfa-wireless-equipment/">Alfa AWUS036H</a> wireless card and a <a title="InfoSanity: GPS reciever" href="http://infosanity.wordpress.com/2009/07/02/bu-353-gps-reciever/">BU-353 GPS Reciever</a>. This resulted in a basic attempt to write a <a title="Kismet2gmapstatic" href="http://infosanity.wordpress.com/2009/07/05/kismet2gmapstatic-updated-versions/">utility</a> to create maps from the results of wardriving with Kismet, whilst the short development time of the project was enjoyable it was promptly shelved once people introduced me to Jabra&#8217;s excellent <a title="giskismet" href="http://my-trac.assembla.com/giskismet/">giskismet</a>. It also resulted in the creation of the still to be field-tested, James Bond-esque <a title="InfoSanity: WarWalking case" href="http://infosanity.wordpress.com/2009/07/23/war-walking-case/">warwalking case</a>.</p>
<p><strong>Honeypots: </strong>Whilst I had had Nepenthes honeypot system running before the turn of the year, I hadn&#8217;t really worked with it in earnest until the <a title="InfoSanity: Honeypotting with Nepenthes" href="http://infosanity.wordpress.com/2009/04/12/honeypotting-with-nepenthes/">first post</a> on the subject in February, and subsequent <a title="InfoSanity: Nepenthes Statistics" href="http://infosanity.wordpress.com/2009/05/17/submissions2stats-py/">statistic utilities</a>. These posts also became the topic for my first experience with public speaking, for local (and rapidly expanding) technical group, <a title="SuperMondays" href="http://www.supermondays.org/">SuperMondays</a>. As the technology has improved the honeypot system has recently been migrated over to Nepenthes&#8217; spiritual successor <a title="InfoSanity: Dionaea" href="http://infosanity.wordpress.com/2009/11/09/starting-with-dionaea/">Dionaea</a>. Over the year I have also had the pleasure and privilege of talking with <a title="@commonism" href="http://twitter.com/commonism">Markus Koetter</a> (lead dev of Nepenthes and Dionaea) and Lukas Rist (lead dev of <a title="Glastopf" href="http://glastopf.org/index.php">Glastopf</a>), these guys *really* know their stuff.</p>
<p><strong>Public Speaking: </strong>As mentioned above I gave my first public talk for SuperMondays, discussing Nepenthes honeypots and the information that can be gathered from them. Unfortunately (or thankfully) there is only limited footage available for the session as the camera&#8217;s battery ran out of juice. My second session was for a group of Northumbria University&#8217;s Forensics and Ethical Hacking students as an &#8216;expert speaker&#8217;, and I still think they mistook me for someone else. This time a recording was available thanks to a couple of the students, full review and audio available <a title="InfoSanity: UNN speaker session" href="http://infosanity.wordpress.com/2009/11/18/expert-speaker-session-at-northumbria-university/">here</a>. My public speaking is still far from perfect, coming out at a rapid fire pace, but I&#8217;m over my initial dread and actually quite enjoy it. Hopefully they&#8217;ll be additional opportunities in the future.</p>
<p><strong>Friends and Contacts: </strong>Throughout the year I have ended up in contact with some excellent and interesting people; from real-world network events like SuperMondays and Cloudcamp, old school discussions in forums (<a title="EH-Net" href="http://www.ethicalhacker.net/">EH-Net</a>) and IRC channels, to the &#8216;2.0&#8242; of Twitter (<a title="@infosanity" href="http://twitter.com/infosanity">@infosanity</a> btw). Along with good debates and discussions I&#8217;d also like to think I&#8217;ve made some good friendships, too many people to name (and most wouldn&#8217;t want to be associated <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' />  ) but you know who you are.</p>
<p>So that&#8217;s the year in brief, couple of smaller activities along the way, from investigating <a title="Slowloris" href="http://infosanity.wordpress.com/2009/06/18/denial-of-service-with-slowloris/">newly released attack vectors</a> to trying my hand at <a title="InfoSanity: Lock Picking" href="http://infosanity.wordpress.com/2009/07/11/starting-out-with-physical-security/">lock picking</a>. In hindsight it has been one hell of a year, and with some of the side projects in the pipeline I&#8217;m expecting 2010 to be even better. Onwards and upwards.</p>
<p>&#8211; Andrew Waite</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/infosanity.wordpress.com/409/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/infosanity.wordpress.com/409/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/infosanity.wordpress.com/409/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/infosanity.wordpress.com/409/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/infosanity.wordpress.com/409/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/infosanity.wordpress.com/409/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/infosanity.wordpress.com/409/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/infosanity.wordpress.com/409/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/infosanity.wordpress.com/409/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/infosanity.wordpress.com/409/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.infosanity.co.uk&blog=8614004&post=409&subd=infosanity&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.infosanity.co.uk/2009/12/17/2009-a-review/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/78c9d658d90cad982bfc9af08a2ff8dd?s=96&#38;d=http%3A%2F%2Fa.wordpress.com%2Fi%2Fmu.gif&#38;r=G" medium="image">
			<media:title type="html">Infosanity</media:title>
		</media:content>
	</item>
		<item>
		<title>Fuzzy hashing, memory carving and malware identification</title>
		<link>http://blog.infosanity.co.uk/2009/12/15/fuzzy-hashing-memory-carving-and-malware-identification/</link>
		<comments>http://blog.infosanity.co.uk/2009/12/15/fuzzy-hashing-memory-carving-and-malware-identification/#comments</comments>
		<pubDate>Tue, 15 Dec 2009 21:26:31 +0000</pubDate>
		<dc:creator>Andrew Waite</dc:creator>
				<category><![CDATA[forensics]]></category>
		<category><![CDATA[honeypot]]></category>
		<category><![CDATA[incident response]]></category>
		<category><![CDATA[lab]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[tool-kit]]></category>

		<guid isPermaLink="false">http://infosanity.wordpress.com/?p=399</guid>
		<description><![CDATA[I've recently been involved in a couple of discussions for different ways for identifying malware. One of the possibilities that has been brought up a couple of times is fuzzy hashing, intended to locate files based on similarities to known files.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.infosanity.co.uk&blog=8614004&post=399&subd=infosanity&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve recently been involved in a couple of discussions for different ways for identifying malware. One of the possibilities that has been brought up a couple of times is fuzzy hashing, intended to locate files based on similarities to known files. I must admit that I don&#8217;t fully understand the maths and logic behind creating fuzzy hash signatures or comparing them. If you&#8217;re curious Dustin Hurlbut has released a <a title="Hurlbut: Fuzzy hashing for investigators" href="http://www.accessdata.com/downloads/media/Fuzzy_Hashing_for_Investigators.pdf">paper on the subject,</a> Hurlbut&#8217;s abstract does a better job of explaining the general idea behind fuzzy hashing.</p>
<blockquote><p>Fuzzy hashing allows the discovery of potentially incriminating documents that may not be located using traditional hashing methods. The use of the fuzzy hash is much like the fuzzy logic search; it is looking for documents that are similar but not exactly the same, called homologous files. Homologous files have identical strings of binary data; however they are not exact duplicates. An example would be two identical word processor documents, with a new paragraph added in the middle of one. To locate homologous files, they must be hashed traditionally in segments to identify the strings of identical data.</p></blockquote>
<p>I have previously experimented with a tool called ssdeep, which implements the theory behind fuzzy hashing. To use ssdeep to find files similar to known malicious files you can run ssdeep against the known samples to generate a signature hash, then run ssdeep against the files you are searching, comparing with the previously generated sample.</p>
<p>One scenarios I&#8217;ve used ssdeep for in the past is to try and group malware samples collected by malware honeypot systems based on functionality. In my attempts I haven&#8217;t found this to be a promising line of research, as different malware can typically have the same and similar functionality most of the samples showed a high level of comparison whether actually related or not.</p>
<p>Another scenario that I had developed was running ssdeep against a clean WinXP install with a malicious binary. In the tests I had run I haven&#8217;t found this to be a useful process, given the disk capacity available to modern systems running ssdeep against a large HDD can be a time consuming process. It can also generate a good number of false positives when run against the OS.</p>
<p>After recently reading Leon van der Eijk&#8217;s post on <a title="Leon's memory carving article" href="http://lvdeijk.wordpress.com/2009/11/17/carving-malware-from-live-memory/">malware carving</a> I have been mulling a method for combining techniques to improve fuzzy hashing&#8217;s ability to identify malicious files, while reducing the number of false positives and workload required for an investigator. The theory was that, while any unexpected files on a system are not desirable, if they aren&#8217;t running in memory then they are less threatening than those that are active.</p>
<p>To test the theory I infected an XP SP2 victim with a sample of Blaster that had been harvested by <a title="InfoSanity: Dionaea" href="http://infosanity.wordpress.com/category/dionaea/">my Dionaea honeypot</a> and dumped the RAM following Leon&#8217;s methodology. Once the image was dissected by foremost I ran ssdeep against extracted resources. Ssdeep successfully identified the malicious files with a 100% comparison to the maliciuos sample. So far so good.</p>
<p>With my previous experience with ssdeep I ran a control test, repeating the procedure against the dumped memory of a completely clean install. Unsurprisingly the comparison did not find a similar 100% match, however it did falsely flag several files and artifacts with a 90%+ comparison so there is still a significant risk of false positives.</p>
<p>From the process I have learnt a fair deal (reading and understanding Leon&#8217;s methodolgy was no comparison to putting it into practice) but don&#8217;t intend to utilise the methods and techniques attempted in real-world scenarios any time soon. Similar, and likely faster, results can be achieved by following Leon&#8217;s process completely and running the files carved by Foremost against an anti-virus scan.</p>
<p>Being able to test scenarios similar to this was the main reason for me to build up the my test and development lab which I have described previously. In particular, if I had run the investigation on physical hardware I would likely not have rebuilt the environment for the control test with a clean system, losing the additional data for comparison, virtualisation snap shots made re-running the scenario trivial.</p>
<p>&#8211;Andrew Waite</p>
<p>P.S. Big thanks to Leon for writing up the memory capture and carving process used as a foundation for testing this scenario.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/infosanity.wordpress.com/399/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/infosanity.wordpress.com/399/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/infosanity.wordpress.com/399/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/infosanity.wordpress.com/399/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/infosanity.wordpress.com/399/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/infosanity.wordpress.com/399/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/infosanity.wordpress.com/399/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/infosanity.wordpress.com/399/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/infosanity.wordpress.com/399/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/infosanity.wordpress.com/399/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.infosanity.co.uk&blog=8614004&post=399&subd=infosanity&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.infosanity.co.uk/2009/12/15/fuzzy-hashing-memory-carving-and-malware-identification/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/78c9d658d90cad982bfc9af08a2ff8dd?s=96&#38;d=http%3A%2F%2Fa.wordpress.com%2Fi%2Fmu.gif&#38;r=G" medium="image">
			<media:title type="html">Infosanity</media:title>
		</media:content>
	</item>
		<item>
		<title>Analysis: Honeypot Datasets</title>
		<link>http://blog.infosanity.co.uk/2009/12/10/analysis-honeypot-datasets/</link>
		<comments>http://blog.infosanity.co.uk/2009/12/10/analysis-honeypot-datasets/#comments</comments>
		<pubDate>Thu, 10 Dec 2009 20:12:20 +0000</pubDate>
		<dc:creator>Andrew Waite</dc:creator>
				<category><![CDATA[Dionaea]]></category>
		<category><![CDATA[honeypot]]></category>
		<category><![CDATA[malware]]></category>

		<guid isPermaLink="false">http://infosanity.wordpress.com/?p=393</guid>
		<description><![CDATA[Earlier this week Markus released two anonymised data sets from live Dionaea installations. The full write-up and data sets can be found on the newly migrated carnivore.it news feed here. Perhaps unsurprisingly I couldn't help but run the data through my statistics scripts to get a quick idea of  what was seen by the sensors. <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.infosanity.co.uk&blog=8614004&post=393&subd=infosanity&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>Earlier this week Markus released two anonymised data sets from live Dionaea installations. The full write-up and data sets can be found on the newly migrated carnivore.it news feed <a title="Post_it_yourself: anonymised data" href="http://carnivore.it/2009/12/08/post_it_yourself">here</a>. Perhaps unsurprisingly I couldn&#8217;t help but run the data through my <a title="InfoSanity: mimic-nepstats.py" href="http://infosanity.wordpress.com/2009/11/10/mimic-nepstats-py/">statistics scripts</a> to get a quick idea of  what was seen by the sensors.</p>
<p>This caused some immediate problems, before the data was released Markus had contacted me to point out/complain that the performance from my script is ideal. Performance wasn&#8217;t an issue I had encountered, but the database from the sensor I run is ~1MB, the smaller of the released data sets is ~300MB, with the larger being 4.1GB. I immediately tried to rectify the problem and am proud to report,&#8230;</p>
<p>I failed miserably. I had tried to move some of the counting and loops from the python code and migrate to more complex SQL queries, working on the theory that working with large datasets should be more efficient within databases as they are designed for working with sets of data. Theory was proved false, actually increasing run-time by about 20%, so I won&#8217;t be releasing the changes. Good job I&#8217;ve never claimed to be a developer. All this being said, the script still crunches through the raw data in 30seconds and 3minutes respectively.</p>
<p>Without further ado, the Berlin data-set:</p>
<blockquote><p>Statistics engine written by Andrew Waite &#8211; www.infosanity.co.uk</p>
<p>Number of submissions: 2726<br />
Number of unique samples: 133<br />
Number of unique source IPs: 639</p>
<p>First sample seen: 2009-11-05 12:02:48.104760<br />
Last sample seen: 2009-12-07 11:13:55.930130<br />
SystemrRunning: 31 days, 23:11:07.825370<br />
Average daily submissions: 87.935483871</p>
<p>Most recent submissions:<br />
2009-12-07 11:13:55.930130, 10.48.60.253, http://zonetech.info/61.exe, ae8705a7b4bf8c13e5d8214d374e6c34<br />
2009-12-07 11:12:59.389940, 10.13.103.23, ftp://1:1@10.101.229.251:61751/ssms.exe, 14a09a48ad23fe0ea5a180bee8cb750a<br />
2009-12-07 11:10:27.296370, 10.13.103.23, tftp://10.13.103.23/ssms.exe, df51e3310ef609e908a6b487a28ac068<br />
2009-12-07 10:55:24.607140, 10.183.36.128, tftp://10.183.36.128/ssms.exe, df51e3310ef609e908a6b487a28ac068<br />
2009-12-07 10:43:48.872170, 10.183.36.128, ftp://1:1@10.20.216.112:53971/ssms.exe, 14a09a48ad23fe0ea5a180bee8cb750a</p></blockquote>
<p>And Paris:</p>
<blockquote><p>Statistics engine written by Andrew Waite &#8211; www.infosanity.co.uk</p>
<p>Number of submissions: 749518<br />
Number of unique samples: 2064<br />
Number of unique source IPs: 30808</p>
<p>First sample seen: 2009-11-30 03:10:24.591650<br />
Last sample seen: 2009-12-07 08:46:23.657530<br />
SystemrRunning: 7 days, 5:35:59.065880<br />
Average daily submissions: 107074.0</p>
<p>Most recent submissions:<br />
2009-12-07 08:46:23.657530, 10.46.210.146, http://10.9.0.30:3682/udqk, d45895e3980c96b077cb4ed8dc163db8<br />
2009-12-07 08:46:20.985190, 10.98.174.44, http://10.200.78.235:2708/lzhffhai, 94e689d7d6bc7c769d09a59066727497<br />
2009-12-07 08:46:21.000540, 10.204.219.219, http://10.38.56.49:6968/tyhxqm, 908f7f11efb709acac525c03839dc9e5<br />
2009-12-07 08:46:18.398500, 10.174.62.175, http://10.108.210.203:3058/pghux, ed12bcac6439a640056b4795d22608da<br />
2009-12-07 08:46:15.753080, 10.39.96.46, http://10.132.244.66:3255/dhti, 94e689d7d6bc7c769d09a59066727497</p></blockquote>
<p>Still need to dig further into the data, they&#8217;ll be another post in the making if I uncover anything interesting&#8230;</p>
<p>&#8211; Andrew Waite</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/infosanity.wordpress.com/393/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/infosanity.wordpress.com/393/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/infosanity.wordpress.com/393/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/infosanity.wordpress.com/393/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/infosanity.wordpress.com/393/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/infosanity.wordpress.com/393/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/infosanity.wordpress.com/393/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/infosanity.wordpress.com/393/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/infosanity.wordpress.com/393/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/infosanity.wordpress.com/393/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.infosanity.co.uk&blog=8614004&post=393&subd=infosanity&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.infosanity.co.uk/2009/12/10/analysis-honeypot-datasets/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/78c9d658d90cad982bfc9af08a2ff8dd?s=96&#38;d=http%3A%2F%2Fa.wordpress.com%2Fi%2Fmu.gif&#38;r=G" medium="image">
			<media:title type="html">Infosanity</media:title>
		</media:content>
	</item>
		<item>
		<title>Starting out with Glastopf</title>
		<link>http://blog.infosanity.co.uk/2009/12/01/starting-out-with-glastopf/</link>
		<comments>http://blog.infosanity.co.uk/2009/12/01/starting-out-with-glastopf/#comments</comments>
		<pubDate>Tue, 01 Dec 2009 19:22:00 +0000</pubDate>
		<dc:creator>Andrew Waite</dc:creator>
				<category><![CDATA[honeypot]]></category>
		<category><![CDATA[webappsec]]></category>

		<guid isPermaLink="false">http://infosanity.wordpress.com/?p=389</guid>
		<description><![CDATA[I've been lax in writing up my initial experience with Glastopf. For those new to Glastopf, initially created by Lukas Rist as part of the Google summer of code program in collaboration with the Honeynet Project and Thorsten Holz. <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.infosanity.co.uk&blog=8614004&post=389&subd=infosanity&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve been lax in writing up my initial experience with <a title="Glastopf Home Page" href="http://glastopf.org/index.php">Glastopf</a>. For those new to Glastopf, initially created by Lukas Rist as part of the Google summer of code program in collaboration with the Honeynet Project and Thorsten Holz.</p>
<p>I must admit that I found the installation of Glastopf to be a complete nightmare. Although this is mostly due to my systems lack of some of the Python pre-requisites that I needed to compile from source, which in turn had other unmet pre-requisites, which in turn&#8230; you get the idea. But I did manage to get my install complete eventually, and have learnt a few things in the process, so it can&#8217;t be all bad.</p>
<p>At this point I also need to thank the guys from the #glastopf irc channel on freenode. The advice and suggestions provided made the job much easier than it could have been, and simplified my initial testing of the system once working.</p>
<p>My Glastopf system has been running a couple of weeks and I&#8217;m starting to take a closer look logs being recorded. I&#8217;m not entirely sure what I was expecting as a result of the install, I must confess to being a little disappointed so far, but as I&#8217;m no expert in the realm of web applications the findings may mean more to those with more insight.</p>
<p>Overall I have logged several scans for various resources, I&#8217;m assuming looking for vulnerabilities in installed services. Nothing too unexpected for example scans for Roundcube mail or phpMyAdmin installations.</p>
<p>I have also found some links to inocious, legitimate online resources. Again I am no expert with web attacks (one of my motivations for installing a web honeypot in the first place was to learn more about them), but I am assuming that this was to test the effect of a particular attack vector before providing host systems with malicious URLs in the logs for an unsuccessful attack. If anyone knows I&#8217;m wrong, or can provide a better explanation I&#8217;d appreciate a heads up.</p>
<p>With this installation the InfoSanity honeytrap environment is slowly expanding to show a wider and more indepth understanding of live attack vectors targetting production systems.</p>
<p>&#8211; Andrew Waite</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/infosanity.wordpress.com/389/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/infosanity.wordpress.com/389/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/infosanity.wordpress.com/389/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/infosanity.wordpress.com/389/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/infosanity.wordpress.com/389/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/infosanity.wordpress.com/389/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/infosanity.wordpress.com/389/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/infosanity.wordpress.com/389/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/infosanity.wordpress.com/389/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/infosanity.wordpress.com/389/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.infosanity.co.uk&blog=8614004&post=389&subd=infosanity&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.infosanity.co.uk/2009/12/01/starting-out-with-glastopf/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/78c9d658d90cad982bfc9af08a2ff8dd?s=96&#38;d=http%3A%2F%2Fa.wordpress.com%2Fi%2Fmu.gif&#38;r=G" medium="image">
			<media:title type="html">Infosanity</media:title>
		</media:content>
	</item>
		<item>
		<title>New dionaea statistics script</title>
		<link>http://blog.infosanity.co.uk/2009/12/01/new-dionaea-statistics-script/</link>
		<comments>http://blog.infosanity.co.uk/2009/12/01/new-dionaea-statistics-script/#comments</comments>
		<pubDate>Tue, 01 Dec 2009 18:22:48 +0000</pubDate>
		<dc:creator>Andrew Waite</dc:creator>
				<category><![CDATA[Dionaea]]></category>
		<category><![CDATA[honeypot]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[python]]></category>

		<guid isPermaLink="false">http://infosanity.wordpress.com/?p=384</guid>
		<description><![CDATA[Following on from my work with gathering statistics from the Honeypot systems that I run I have released a limited alpha of a new script/tool that I am working on. The tool provides access to common result sets from the sqlite database, without the requirement for remembering the database architecture  and entering lengthy SQL statements by hand.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.infosanity.co.uk&blog=8614004&post=384&subd=infosanity&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>Following on from my work with gathering statistics from the Honeypot systems that I run I have released a limited alpha of a new script/tool that I am working on. The tool provides access to common result sets from the sqlite database, without the requirement for remembering the database architecture  and entering lengthy SQL statements by hand.</p>
<p>Disclaimer first: the tool doesn&#8217;t do anything outrageously new, and most of the SQL queries have been borrowed from <a title="Carnivore.it Logging post" href="http://carnivore.it/2009/11/06/dionaea_sql_logging">Markus&#8217; post</a> on SQL logging with Dionaea when the feature was first introduced. However I have found the script makes my analysis of the honeypot logs simpler and quicker, and I&#8217;ve a positive reaction from a limited few that have had a copy of the script before this post. Hopefully it will be of use others.</p>
<p>Usage is relatively simple, shown below:</p>
<blockquote><p>Dionaea database query collection<br />
Author: Andrew Waite &#8211; www.InfoSanity.co.uk</p>
<p>Inspiration from carnivore.it article:</p>
<p>http://carnivore.it/2009/11/06/dionaea_sql_logging</p>
<p>Usage:<br />
/path/to/python dionaea-sqlquery.py &#8211;query #<br />
Where # is:<br />
1:      Port Attack Frequency<br />
2:      Attacks over a day<br />
3:      Popular Malware Downloads<br />
4:      Busy Attackers<br />
5:      Popular Download Locations<br />
6:      Connections in last 24 hours</p></blockquote>
<p>The script can be found <a title="dionaea-sqlquery.py Version 0.2" href="http://www.infosanity.co.uk/resources/scripts/dionaea/dionaea-sqlquery-0_2.py">here</a>. There is still a good level of work to be undertaken to tidy up the output, potentially allowing for output in different formats, and I also want to add additional and more complex queries as time progresses. If you have any success,  failure, comments or suggests please let me know.</p>
<p>&#8211; Andrew Waite</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/infosanity.wordpress.com/384/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/infosanity.wordpress.com/384/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/infosanity.wordpress.com/384/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/infosanity.wordpress.com/384/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/infosanity.wordpress.com/384/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/infosanity.wordpress.com/384/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/infosanity.wordpress.com/384/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/infosanity.wordpress.com/384/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/infosanity.wordpress.com/384/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/infosanity.wordpress.com/384/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.infosanity.co.uk&blog=8614004&post=384&subd=infosanity&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.infosanity.co.uk/2009/12/01/new-dionaea-statistics-script/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/78c9d658d90cad982bfc9af08a2ff8dd?s=96&#38;d=http%3A%2F%2Fa.wordpress.com%2Fi%2Fmu.gif&#38;r=G" medium="image">
			<media:title type="html">Infosanity</media:title>
		</media:content>
	</item>
		<item>
		<title>Expert speaker session at Northumbria University</title>
		<link>http://blog.infosanity.co.uk/2009/11/18/expert-speaker-session-at-northumbria-university/</link>
		<comments>http://blog.infosanity.co.uk/2009/11/18/expert-speaker-session-at-northumbria-university/#comments</comments>
		<pubDate>Wed, 18 Nov 2009 14:19:33 +0000</pubDate>
		<dc:creator>Andrew Waite</dc:creator>
				<category><![CDATA[honeypot]]></category>
		<category><![CDATA[incident response]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[presentation]]></category>

		<guid isPermaLink="false">http://infosanity.wordpress.com/?p=364</guid>
		<description><![CDATA[Last week I had the pleasure of being asked to speak at Northumbria University, presenting to students of the Computer Forensics and Ethical Hacking for Computer Security programmes. As I graduated from Northumbria a few years ago it was interesting to come back to see some familiar faces and have a look at how the [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.infosanity.co.uk&blog=8614004&post=364&subd=infosanity&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>Last week I had the pleasure of being asked to speak at <a title="Northumbria University" href="http://www.northumbria.ac.uk/">Northumbria University</a>, presenting to students of the <a title="UNN Computing Forensics" href="http://www.northumbria.ac.uk/programmespecs/BScHonsComputerForensics/">Computer Forensics</a> and <a title="UNN: Ethical Hacking" href="http://www.northumbria.ac.uk/programmespecs/1319541/">Ethical Hacking for Computer Security</a> programmes. As I graduated from Northumbria a few years ago it was interesting to come back to see some familiar faces and have a look at how the facilities had developed.</p>
<p>Despite the nerves of having to speak in front of a crowd I really enjoyed the event, especially as the other speakers were excellent and I enjoyed their sessions. The event kicked off with Dave Kennedy, a soon to retire member of Durham Police&#8217;s computer crime unit. Dave&#8217;s talked about his personal experience with a couple of high profile cases, explaining some of the groundwork and behind the scenes activity that isn&#8217;t known to the general public. I found the information interesting; but also disturbing, given the nature of the material that is handled by Dave and his department I can safely state that I wouldn&#8217;t want to have much experience in the area.</p>
<p>Next up was Phil Byrne, an internal auditor for HM Revenue and Customs (HMRC). For those that don&#8217;t know, HMRC were/are at the centre of one of the UK&#8217;s largest data loss stories in 2007 after CDs containing approximately 25 million child benefit records were sent, unencrypted, by standard post and did not reach their intended destination (some backstory <a title="BBC News: HMRC data loss" href="http://news.bbc.co.uk/1/hi/7104945.stm">here</a>). Phil talked openly about the incident, discussing both the incident itself and the changes made in response. One of Phil&#8217;s comments has stayed with me (if I&#8217;m mis-quoting someone let me know):</p>
<blockquote><p>If you put people into the process, something will go wrong at some time</p></blockquote>
<p>Third to the stand was Gary Witts, owner of a manage services company specialising in on-line backups. The talk was very indepth and had some interesting content, but from my perspective I felt it was more of a sales pitch than a technical discussion of the secure backup&#8217;s place within a security standing.</p>
<p>I took the fourth and final slot of the day, which left me with the unenviable position of being between around 100 students and the pub, which didn&#8217;t help my usual rapid-fire presentation style. My presentation took a different focus from the previous sessions, discussing some of the real-world security incidents that can regularly be encountered, and some advice on handling the incidents in question. I also discussed my findings from <a title="InfoSanity: Honeypot" href="http://infosanity.wordpress.com/category/honeypot/">honeypot</a> systems, introducing a less common method for monitoring an environment for malicious activity. Assuming the feedback I&#8217;ve recieved is genuine the presentation seems to have been well-recieved.</p>
<p>From a student&#8217;s perspective; <a title="tmac.co.uk" href="http://tmacuk.co.uk/">Tom</a> was in the audience and has been writing up his take on the event in a series of <a title="Tmacuk's site" href="http://tmacuk.co.uk/">blog postings</a>. Tom also recorded the talks, for any one interested a direct link to my session is available <a title="InfoSanity - UNN Presentation audio" href="http://www.infosanity.co.uk/resources/presentations/Infosanity-UNN-20091111.wma">here</a>.</p>
<p>&#8211; <a title="Bio - Andrew Waite" href="http://infosanity.wordpress.com/about/bio-andrew-waite/">Andrew Waite</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/infosanity.wordpress.com/364/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/infosanity.wordpress.com/364/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/infosanity.wordpress.com/364/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/infosanity.wordpress.com/364/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/infosanity.wordpress.com/364/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/infosanity.wordpress.com/364/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/infosanity.wordpress.com/364/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/infosanity.wordpress.com/364/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/infosanity.wordpress.com/364/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/infosanity.wordpress.com/364/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.infosanity.co.uk&blog=8614004&post=364&subd=infosanity&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.infosanity.co.uk/2009/11/18/expert-speaker-session-at-northumbria-university/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
<enclosure url="http://www.infosanity.co.uk/resources/presentations/Infosanity-UNN-20091111.wma" length="11871444" type="audio/x-ms-wma" />
	
		<media:content url="http://1.gravatar.com/avatar/78c9d658d90cad982bfc9af08a2ff8dd?s=96&#38;d=http%3A%2F%2Fa.wordpress.com%2Fi%2Fmu.gif&#38;r=G" medium="image">
			<media:title type="html">Infosanity</media:title>
		</media:content>
	</item>
		<item>
		<title>mimic-nepstats.py</title>
		<link>http://blog.infosanity.co.uk/2009/11/10/mimic-nepstats-py/</link>
		<comments>http://blog.infosanity.co.uk/2009/11/10/mimic-nepstats-py/#comments</comments>
		<pubDate>Tue, 10 Nov 2009 21:06:16 +0000</pubDate>
		<dc:creator>Andrew Waite</dc:creator>
				<category><![CDATA[Dionaea]]></category>
		<category><![CDATA[honeypot]]></category>
		<category><![CDATA[tool-kit]]></category>

		<guid isPermaLink="false">http://infosanity.wordpress.com/?p=358</guid>
		<description><![CDATA[As I discussed in my last post about Dionaea I am really impressed with the improvements to logging capabilities over Nepenthes. I&#8217;ve now had a Dionaea system online for ~24hours, which while it isn&#8217;t enough data to draw any meaningful statistics, it has provided enough data to work on some new tools. I had been [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.infosanity.co.uk&blog=8614004&post=358&subd=infosanity&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>As I discussed in my <a title="InfoSanity: Starting with Dionaea" href="http://infosanity.wordpress.com/2009/11/09/starting-with-dionaea/">last post</a> about Dionaea I am really impressed with the improvements to logging capabilities over Nepenthes. I&#8217;ve now had a Dionaea system online for ~24hours, which while it isn&#8217;t enough data to draw any meaningful statistics, it has provided enough data to work on some new tools. I had been intending to extend my Nepenthes tools to parse the logs and enter data into a database for additional and simpler analysis. This was promptly squashed with the migration to Dionaea, but the theory has proven to be a good one as Dionaea&#8217;s default logging to an SQLite database has made development much quicker and easier.</p>
<p>To get a feel for the new system, and to keep my capabilities up to speed, I&#8217;ve spent this evening writing a script to provide the same information for a Dionaea system that my <a title="Infosanity: Nepenthes Statistics" href="http://infosanity.wordpress.com/2009/11/09/last-nepenthes-statistics/">Nepenthes statistics script</a> provided previously. As usual, the script can be found over at InfoSanity, <a title="InfoSanity: mimic-nepstats.py script" href="http://www.infosanity.co.uk/resources/scripts/dionaea/mimic-nepstats.py">here</a>. An initial set of results from my system is below for an example:</p>
<blockquote><p>
Statistics engine written by Andrew Waite &#8211; www.infosanity.co.uk</p>
<p>Number of submissions: 11<br />
Number of unique samples: 10<br />
Number of unique source IPs: 8</p>
<p>First sample seen: 2009-11-09 14:19:15.518382<br />
Last sample seen: 2009-11-10 18:35:28.235052<br />
SystemrRunning: 1 day, 4:16:12.716670<br />
Average daily submissions: 11.0</p>
<p>Most recent submissions:<br />
2009-11-10 18:35:28.235052, 195.90.106.212, emulate://, a4dde6f9e4feb8a539974022cff5f92c<br />
2009-11-10 16:23:12.925538, 195.93.135.67, tftp://195.93.135.67/ssms.exe, 1d419d615dbe5a238bbaa569b3829a23<br />
2009-11-10 16:00:14.846435, 195.170.57.28, tftp://195.170.57.28/ssms.exe, fd28c5e1c38caa35bf5e1987e6167f4c<br />
2009-11-10 15:39:48.598303, 195.46.34.91, http://zonetech.info/61.exe, beee7a74712b2e3c84182c1bf18750ae<br />
2009-11-10 13:00:29.916721, 195.95.170.138, emulate://, ddf1259a8fcef0776054460ebdf3cae4</p></blockquote>
<p>&#8211; <a title="Bio - Andrew Waite" href="http://infosanity.wordpress.com/about/bio-andrew-waite/">Andrew Waite</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/infosanity.wordpress.com/358/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/infosanity.wordpress.com/358/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/infosanity.wordpress.com/358/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/infosanity.wordpress.com/358/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/infosanity.wordpress.com/358/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/infosanity.wordpress.com/358/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/infosanity.wordpress.com/358/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/infosanity.wordpress.com/358/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/infosanity.wordpress.com/358/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/infosanity.wordpress.com/358/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.infosanity.co.uk&blog=8614004&post=358&subd=infosanity&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.infosanity.co.uk/2009/11/10/mimic-nepstats-py/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/78c9d658d90cad982bfc9af08a2ff8dd?s=96&#38;d=http%3A%2F%2Fa.wordpress.com%2Fi%2Fmu.gif&#38;r=G" medium="image">
			<media:title type="html">Infosanity</media:title>
		</media:content>
	</item>
	</channel>
</rss>