<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>UK Honeynet Project</title>
	<atom:link href="http://www.ukhoneynet.org/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ukhoneynet.org</link>
	<description>News and information from the UK Honeynet Project</description>
	<lastBuildDate>Tue, 04 Dec 2012 20:44:29 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
		<item>
		<title>UK Honeynet Project Chapter Annual Status Report For 2011/2012</title>
		<link>http://www.ukhoneynet.org/2012/12/04/uk-honeynet-project-chapter-annual-status-report-for-20112012/</link>
		<comments>http://www.ukhoneynet.org/2012/12/04/uk-honeynet-project-chapter-annual-status-report-for-20112012/#comments</comments>
		<pubDate>Tue, 04 Dec 2012 18:41:58 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Admin]]></category>
		<category><![CDATA[UK News]]></category>
		<category><![CDATA[Annual Chapter Report]]></category>

		<guid isPermaLink="false">http://www.ukhoneynet.org/?p=427</guid>
		<description><![CDATA[As part of membership requirements, each year, all chapters of the Honeynet Project must post annual reports that detail what their chapter members have been working on during that period. The reporting period got a bit mixed up recently, so this is the UK Chapter&#8217;s annual report for both 2011 and 2012. You can find [...]]]></description>
				<content:encoded><![CDATA[<p>As part of membership requirements, each year, all chapters of the <a href="http://www.honeynet.org">Honeynet Project</a> must post annual reports that detail what their chapter members have been working on during that period. The reporting period got a bit mixed up recently, so this is the UK Chapter&#8217;s annual report for both 2011 and 2012. You can find the status reports for <a href="http://www.honeynet.org/og">other Chapters</a> on the main <a href="http://www.honeynet.org">Honeynet Project website</a>.</p>
<h2>ORGANIZATION</h2>
<p>Current UK Chapter members are:</p>
<p><strong>David Watson</strong> &#8211; Full member, Chapter Lead, <a href="http://www.honeynet.org">Honeynet Project</a> Chief Research Officer<br />
<strong>Arthur Clune </strong>- Full member<br />
<strong>Jamie Riden</strong> &#8211; Full member<br />
<strong>Steve Mumford</strong> &#8211; Alumni member</p>
<p>As you may have noticed from the lack of recent updates to our UK Chapter blog, during this period our members have either mostly been involved in activities under the core <a href="http://www.honeynet.org">Honeynet Project</a>, rather than UK-specific chapter activities, or have been busy with personal/professional lives so have had limited time to contribute here. That has unfortunately reduced public facing UK Chapter activity to lowest point in many years.</p>
<p>We have had a number of membership inquiries during this period, and potentially could increase our chapter membership, but to be honest, we have avoided bringing in new UK Chapter members whilst UK activity levels were low and no-one had the time to adequately support new members. Hopefully that situation will improve in 2013 and we&#8217;ll see increased UK Chapter output once again.</p>
<h2>DEPLOYMENTS</h2>
<p>During this period we have had a mix of honeynet technologies deployed. Some have been part of long term data collection efforts, whilst others have been shorter term deployments &#8211; often for testing of new tools.</p>
<p>Long term deployments:</p>
<p>1) <strong>[David]</strong> Our version 1 <a href="http://www.ukhoneynet.org/20120322_Honeynet_Project_David_Watson_HonEeeBox_Public.pdf">HonEeeBox</a> pre-packaged (<a href="http://nepenthes.carnivore.it">Nepenthes</a>) low interaction sensor project was active at the start of this reporting period, but has since switched over to the version 2 <a href="http://www.ukhoneynet.org/20120322_Honeynet_Project_David_Watson_HonEeeBox_Public.pdf">HonEeeBox</a> system. Although the version 1 system is no longer being maintained, Just for reference purposes, two of the original <a href="http://www.ukhoneynet.org/20120322_Honeynet_Project_David_Watson_HonEeeBox_Public.pdf">HonEeeBox</a> v1 sensors are still running and the total amount of data collected to date by the old system is:</p>
<p>Sensors: 43 </p>
<p>Total Attacks: 2,401,582 </p>
<p>Total Attacker IPs: 36,632 </p>
<p>Total Victim IPs: 214 </p>
<p>Total MD5sums: 4,665 </p>
<p>Total malicious binary size: 559 Mbytes</p>
<p>2) <strong>[David]</strong> Like the v1 <a href="http://nepenthes.carnivore.it">Nepenthes</a> based <a href="http://www.ukhoneynet.org/20120322_Honeynet_Project_David_Watson_HonEeeBox_Public.pdf">HonEeeBoxes</a>, the first releases of the <a href="http://dionaea.carnivore.it">Dionaea</a> powered <a href="http://www.ukhoneynet.org/20120322_Honeynet_Project_David_Watson_HonEeeBox_Public.pdf">HonEeeBox</a> v2 system still initially submitted data to a submit_http backend, which was developed during <a href="http://www.honeynet.org/gsoc2011/slot2">GSoC 2011</a>. We have run a honey cloud hosted instance of that old backend, plus a couple of sensors for most of this period. The data has only been retained for historical purposes.</p>
<p>3) <strong>[David]</strong> Later v2 <a href="http://dionaea.carnivore.it">Dionaea</a> based <a href="http://www.ukhoneynet.org/20120322_Honeynet_Project_David_Watson_HonEeeBox_Public.pdf">HonEeeBoxes</a> were <a href="https://redmine.honeynet.org/projects/hpfeeds/wiki">HPFeeds</a>-enabled, and we have been submitting data to the <a href="http://www.honeynet.org">Honeynet Project&#8217;s</a> shared <a href="http://hpfeeds.honeycloud.net">HPFeeds</a> system from multiple physical and virtual sensors since it went live. These are a mix of Asus EeePC based physical <a href="http://www.ukhoneynet.org/20120322_Honeynet_Project_David_Watson_HonEeeBox_Public.pdf">HonEeeBoxes</a> on domestic ADSL/FTTC lines, or cloud provider hosted VM instances. Current rough volumes of <a href="http://dionaea.carnivore.it">Dionaea</a> events captured through <a href="http://hpfeeds.honeycloud.net">HPFeeds</a>vto date are:</p>
<p>Sensors: 44 </p>
<p>Total Attacks: 14,552,708 </p>
<p>Total Attacker IPs:  300,451 </p>
<p>Total Victim IPs: 2,410 </p>
<p>Total MD5sums: 7,865 </p>
<p>Total malicious binary size: 2.6 Gbytes</p>
<p>Data and binary samples collected from each of the above systems were shared with the <a href="http://www.shadowserver.org">Shadowserver Foundation</a> and <a href="http://www.virustotal.com">VirusTotal</a>, for automated AV and sandbox analysis, and hopefully eventual remediation of infected hosts. Enriched data has has also been logged locally in an instance of the <a href="http://www.honeynet.org/gsoc/slot4">GSoC 2012</a> HonEeeBox backend project, that we hope to continue developing with the student Gyoergy in 2013. Longer term we hope to be able to expand the number of sensors to 100+ and release public visualizations of these attacks.</p>
<p>4) Jamie has recently deployed a couple of local <a href="https://redmine.honeynet.org/projects/hpfeeds/wiki">HPFeeds</a>-enabled <a href="http://dionaea.carnivore.it">Dionaea</a> sensors too, which are also feeding the main <a href="http://www.honeynet.org">Honeynet Project</a> shared <a href="http://hpfeeds.honeycloud.net">HPFeeds</a> instance.</p>
<p>5) During the start of this period David was still running a legacy <a href="http://www.ukhoneynet.org/2007/12/03/global-distributed-honeynet-talk-at-pacsec07/">Global Distributed Honeynet (GDH2)</a> high interaction sensor node on a domestic DSL connection (since disabled). That included a <a href="https://projects.honeynet.org/honeywall/">Honeywall</a> plus a mix of low and high interaction honeypots, mostly on Linux.</p>
<p>6) At points during this period,  David ran a mix of <a href="https://projects.honeynet.org/capture-hpc">Capture-HPC</a> high interaction client honeypots, <a href="http://www.honeyspider.org">HoneySpiderNetwork</a> low/high interaction client honeypots, and <a href="http://code.google.com/p/phoneyc/">PhoneyC</a> and <a href="http://buffer.github.com/thug/">Thug</a> low interaction client honeypots.</p>
<p>7) David has helped provide the infrastructure used by other Project members in various botnet related studies and takedown activities. More information about these activities will hopefully eventually be made public.</p>
<h2>RESEARCH AND DEVELOPMENT</h2>
<p>During this period we built or worked on the following tools:</p>
<p>1) <strong>[David]</strong> <a href="http://www.ukhoneynet.org/20120322_Honeynet_Project_David_Watson_HonEeeBox_Public.pdf">HonEeeBox</a> pre-packaged low interaction honeypot sensor system and associated back/front ends. We hope to continue this development work in 2013, increasing the number of sensors, adding low interaction SSH honeypot capabilities through <a href="http://code.google.com/p/kippo/">Kippo</a>, adding options for centralized monitoring and management, and perhaps including proxy/client honeypot elements too. </p>
<p>2) David and Arthur were mentors for GSoC 2011/2012 on <a href="http://www.ukhoneynet.org/20120322_Honeynet_Project_David_Watson_HonEeeBox_Public.pdf">HonEeeBox</a> backend and front end development, which we also hope to continue in the future, eventually releasing a public Django/JS based user interface to replace the previous private ExtJS based <a href="http://www.ukhoneynet.org/20120322_Honeynet_Project_David_Watson_HonEeeBox_Public.pdf">HonEeeBox</a> v1 prototype interface.</p>
<p>3) Minor support for our <a href="https://projects.honeynet.org/honeysnap/">Honeysnap</a> tool, when end user requests or bug reports were received.</p>
<p>4) We have tried to provide suggestions for improving some existing tolls or adding new features to new projects, such as the excellent <a href="http://www.honeynet.org/og">Cuckoo Sandbox</a> or aging <a href="https://projects.honeynet.org/honeywall/">Honeywall</a> system.</p>
<p>For our current R&#038;D activities:</p>
<p>1) David built a number of data visualization tools based on <a href="http://processing.org">Processing.org</a>, but didn&#8217;t get around to publicly releasing them. He very much hopes to rectify this failing in 2013 <img src='http://www.ukhoneynet.org/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </p>
<p>2) Arthur is currently working on a pastebin scraping system, which will hopefully generate some interesting data for future analysis.</p>
<p>3) David has recently been working on spam pots with <a href="http://www.cert.br/">CERT.BR</a> and the <a href="http://www.shadowserver.org"> Shadowserver Foundation</a>, which will become part of a larger scale distributed honeypot effort in 2013.</p>
<p>4) David has some ideas for next generation honeynet data capture systems and is currently exploring them. Will eventually share concepts and prototypes with members then the public at a suitable point.</p>
<p>5) Earlier in 2012 David ported the <a href="http://www.ukhoneynet.org/20120322_Honeynet_Project_David_Watson_HonEeeBox_Public.pdf">HonEeeBox</a> system to the <a href="http://www.raspberrypi.org">Raspberry Pi</a> platform, to potentially provide another very low cost means of potentially distributing low interaction honeypot sensor systems. He will attempt to blog this information and release a disk image here in the next few days. Apologies to anyone waiting to use it for the delay! <img src='http://www.ukhoneynet.org/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </p>
<p>In general, we are still interested in large scale distributed honeynet sensor deployments and the tools necessary to store/manage/automate/visualize collected data. We would also like to see the ongoing development of high interaction honeypot technologies, or next generation alternatives for gathering such data. We&#8217;d like to continue to collaborate with anyone interested in the same goals, and to perhaps also run some more UK-focused future activities too.</p>
<h2>FINDINGS</h2>
<p>Unfortunately nothing to be shared with the public at this time except the observation that running public internet facing low interaction honeypots to detect network spreading malware generally only results in a lot of Conficker samples!</p>
<h2>PAPERS, PRESENTATIONS AND COMMUNITY ENGAGEMENTS</h2>
<p>Since last chapter status report, recent speaking engagements for David were:</p>
<p><strong>September 2010</strong> &#8211; Hands-on honeynet training classes for <a href="http://2010.cert.org.cn/program_FIRST_TC_2010.html">CNCERT/CC</a> and <a href="http://www.first.org/events/colloquia/beijing2010/">FIRST TC</a>, Beijing CN<br />
<strong>September 2010</strong> &#8211; Whats New In Honeynets presentation <a href="http://2010.cert.org.cn/program_FIRST_TC_2010.html">CNCERT/CC</a> and <a href="http://www.first.org/events/colloquia/beijing2010/">FIRST TC</a>, Beijing CN<br />
<strong>November 2010</strong> &#8211; <a href="http://www.govcert.nl/symposium/">GovCERT.NL security symposium</a>, Rotterdam NL<br />
<strong>December 2010 </strong>- 2 weeks of teaching hands-on honeynet classes, giving presentations, attending meetings, etc in Tokyo for <a href="http://www.ntt-cert.org/index-en.html">NTT CERT</a>, NTT, Hitachi, <a href="http://www.nca.gr.jp/2010/event/index.html">Nippon CSIRT Association (NCA)</a>, SECOND group, JP CERT, various national ISPs, etc.<br />
<strong>January 2011</strong> &#8211; BBC <a href="http://www.bbc.co.uk/news/technology-16754276">NewsNight Cyber Attacks</a><br />
<strong>March 2011</strong> &#8211; <a href="http://www.honeynet.org">Honeynet Project</a> <a href="http://www.honeynet.org/SecurityWorkshops/2011_Paris">annual workshop Paris</a> FR. Public R&#038;D overview presentation, private P1 research, GSoC, HonEeeBox and Shadowserver presentations/sessions.<br />
<strong>March 2011 &#8211; October 2011</strong> &#8211; Organisational administrator for <a href="http://www.honeynet.org">Honeynet Project</a> <a href="http://www.honeynet.org/gsoc2011">Google Summer of Code 2011</a> and student project mentor.<br />
<strong>June 2011</strong> &#8211;  <a href="https://www.ria.ee/cert-estonia/">CERT.EE Security Symposium</a>, Tallin, EE.<br />
<strong>October 2011</strong> &#8211;  <a href="http://code.google.com/soc/">Google Summer of Code Mentor&#8217;s Summit</a>, Google CA.<br />
<strong>February 2012</strong> &#8211;  <a href="http://www.shadowserver.org">Shadowserver Foundation</a> annual workshop, San Jose, CA. Presentation on Honeynet R&#038;D and GSoC.<br />
<strong>March 2012</strong> &#8211; <a href="http://www.honeynet.org">Honeynet Project</a> <a href="http://www.honeynet.org/SecurityWorkshops/2012_SF_Bay_Area">annual workshop</a> Facebook, CA. Public hands-on honeynet training class, public R&#038;D overview presentation, private P1 research, GSoC and HonEeeBox presentations/sessions.<br />
<strong>March 2012 &#8211; October 2012</strong> &#8211; Organisational administrator for <a href="http://www.honeynet.org">Honeynet Project</a> <a href="http://www.honeynet.org/gsoc">Google Summer of Code 2012</a> and student project mentor<br />
<strong>June 2012</strong> &#8211;   <a href="https://www.ria.ee/cert-estonia/">CERT.EE Security Symposium</a>, Tallinn, EE. Presentation on recent honeynet R&#038;D.<br />
<strong>September 2012</strong> &#8211; conference at Interpol, Lyon, FR.<br />
<strong>October 2012 </strong>-  <a href="http://code.google.com/soc/">Google Summer of Code</a> Mentor&#8217;s Summit, Google CA.</p>
<p>David will be teaching a 2 days hands-on honeynets class at the Honeynet Project&#8217;s <a href="http://dubai2013.honeynet.org">next annual workshop in Dubai</a> (which should be another great international event if you are interested in the cutting edge of honeynet R&#038;D, so please check it out!), along with hopefully leading discussions again during private workshop events on honeynet R&#038;D, GSoC and HonEeeBox, amongst others.</p>
<p>UK Chapter members have also attended UK-specific industry events such as Infosec UK and JANET meetings. Jamie presented at OWASP Birmingham in September and OWASP Edinburgh in November.</p>
<p>We continue to be active on both internal and external IRC and email, although UK-specific blogging activity has been poor. Chapter members have been involved in various <a href="http://www.honeynet.org">Honeynet Project</a> committee mailing lists, such as annual workshop organization, membership committee and infrastructure support. Members also individually participate in various other open or closed info-sec vetted communities too.</p>
<h2>GOALS</h2>
<p>Since most activity by UK Chapter members was general <a href="http://www.honeynet.org">Honeynet Project</a> activity, we would like to continue to remain active members but also try to increase UK-specific activity.</p>
<p>We would like to see the recent GSoC work on HonEeeBox sensor back/front ends result in a public UI release.</p>
<p>We would like to release some interesting visualisations of existing data sets, then try and engage the wider infosec and data visualisation communities on how best to improve them. We may try and run a series of public Data Visualisation challenges in 2013.</p>
<h2>MISC ACTIVITIES</h2>
<p>Other activities that our Chapter members have been involved in during this period:</p>
<p>David was a Director of the <a href="http://www.honeynet.org">Honeynet Project</a> in 2011 and remains the Chief Research Officer (CRO). Involvement with various fund raising efforts and proposals (some under NDA), some of which resulted in additional financial support for the <a href="http://www.honeynet.org">Honeynet Project</a>&#8216;s annual workshops in 2012 and 2013, and some of which are ongoing.</p>
<p>David collaborated on a <a href="http://www.epsrc.ac.uk/funding/grants/network/networks/Pages/default.aspx">EPSRC</a> network proposal with Queens University Belfast Information Security Centre.</p>
<h2>MENTORING</h2>
<p>David was a GSoC student project mentor in 2011 and 2012 (and GSoC Org admin), Jamie was a student project mentor in 2010 and 2012. Arthur was a GSoC student project mentor in 2012 and helped with student selection in 2011.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ukhoneynet.org/2012/12/04/uk-honeynet-project-chapter-annual-status-report-for-20112012/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>GSOC 2012 project</title>
		<link>http://www.ukhoneynet.org/2012/11/12/gsoc-2012-project/</link>
		<comments>http://www.ukhoneynet.org/2012/11/12/gsoc-2012-project/#comments</comments>
		<pubDate>Mon, 12 Nov 2012 12:07:50 +0000</pubDate>
		<dc:creator>arthur</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.ukhoneynet.org/?p=424</guid>
		<description><![CDATA[As part of the Google Summer of Code, the UK Honynet project ran a project working with Gyöergy Kohut from the University of Dortmund to produce a web front end for Honeeebox. it went well: Gyöergy produced a Java backend which took events and stored them in a PostgreSQL database plus a web front end [...]]]></description>
				<content:encoded><![CDATA[<p>As part of the Google Summer of Code, the UK Honynet project ran a project working with Gyöergy Kohut from the University of Dortmund to produce a web front end for Honeeebox. it went well: Gyöergy produced a Java backend which took events and stored them in a PostgreSQL database plus a web front end based on Django and Javascript.</p>
<p>The GSOC project has now finished, but we&#8217;re continuing to work on the project.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ukhoneynet.org/2012/11/12/gsoc-2012-project/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Returning to life</title>
		<link>http://www.ukhoneynet.org/2011/02/20/returning-to-life/</link>
		<comments>http://www.ukhoneynet.org/2011/02/20/returning-to-life/#comments</comments>
		<pubDate>Sun, 20 Feb 2011 21:27:11 +0000</pubDate>
		<dc:creator>arthur</dc:creator>
				<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://www.ukhoneynet.org/?p=416</guid>
		<description><![CDATA[There&#8217;s been a long hiatus in blogging on this site. We&#8217;ve not stopped working, just blogging. We&#8217;ll aim to have content on here a little more regularly from now on but with a slight change of emphasis. Up till now we&#8217;ve only posted notes on things we were doing ourselves. Now we&#8217;ll broaden it out [...]]]></description>
				<content:encoded><![CDATA[<p>There&#8217;s been a long hiatus in blogging on this site. We&#8217;ve not stopped working, just blogging. We&#8217;ll aim to have content on here a little more regularly from now on but with a slight change of emphasis. Up till now we&#8217;ve only posted notes on things we were doing ourselves. Now we&#8217;ll broaden it out a little to include general commentary on the InfoSec world and current news.</p>
<p>Hopefully this will both make this site a more general resource but also allow us to blog more frequently. Tools aren&#8217;t updated that often (and some that are we can&#8217;t blog about) but the joy of InfoSec is that there is always something new happening.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ukhoneynet.org/2011/02/20/returning-to-life/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Compiling Capture-HPC on VMWare Server 1.0.6</title>
		<link>http://www.ukhoneynet.org/2008/07/28/compiling-capture-hpc-on-vmware-server-106/</link>
		<comments>http://www.ukhoneynet.org/2008/07/28/compiling-capture-hpc-on-vmware-server-106/#comments</comments>
		<pubDate>Mon, 28 Jul 2008 16:00:25 +0000</pubDate>
		<dc:creator>david</dc:creator>
				<category><![CDATA[HOWTO]]></category>

		<guid isPermaLink="false">http://www.ukhoneynet.org/2008/07/28/compiling-capture-hpc-on-vmware-server-106/</guid>
		<description><![CDATA[We often use Capture-HPC as a high interaction client honeypot for analyzing suspect URLs, but getting it up and running on a new platform can sometimes be a somewhat frustrating and time consuming process. I&#8217;ve recently had to repeat the build process on the latest version of VMWare Server (release 1.0.6 build-91891) running on Ubuntu [...]]]></description>
				<content:encoded><![CDATA[<p>We often use <a href="https://projects.honeynet.org/capture-hpc">Capture-HPC</a> as a high interaction client honeypot for analyzing suspect URLs, but getting it up and running on a new platform can sometimes be a somewhat frustrating and time consuming process. I&#8217;ve recently had to repeat the build process on the latest version of VMWare Server (release 1.0.6 build-91891) running on Ubuntu Gutsy, so in case this saves anyone else some pain, this is what I had to do to make it work:</p>
<p>1) Download the <a href="https://projects.honeynet.org/capture-hpc/wiki/Releases">latest sources</a> (at the time of writing this was capture-server-2.1.0-300-src.zip)</p>
<p>2) Extract the latest sources</p>
<pre>unzip capture-server-2.1.0-300-src.zip
cd capture-server-2.1.0-300-src
</pre>
<p>3) Ensure the necessary build dependencies were installed</p>
<pre>sudo aptitude update ; sudo aptitude install ant ant-optional sun-java6-jdk sun-java6-bin sun-java6-jre
sudo install VMWare-Server-1.0.6-build-91891</pre>
<p>4) Set the correct environment variables</p>
<pre>  JAVA_HOME=/usr/lib/jvm/java-6-sun-1.6.0.03/ ; export JAVA_HOME
  VIX_HOME=/usr/lib/vmware-vix/ ; export VIX_HOME
  VIX_INCLUDE=/usr/include/vmware-vix/ ; export VIX_INCLUDE
  VIX_LIB=/usr/lib/vmware-vix/ ; export VIX_LIB
  ANT_HOME=/usr/share/ant/ ; export ANT_HOME
</pre>
<p>5) Hack the revert compilation shell script:</p>
<pre>chmod +x compile_revert_linux.sh
cat compile_revert_linux.sh</pre>
<pre>#!/bin/sh
echo $VIX_INCLUDE
#gcc -I $VIX_INCLUDE -o revert revert.c $VIX_LIB/libvmware-vix.so
gcc -I $VIX_INCLUDE -o revert revert.c /usr/lib/libvmware-vix.so</pre>
<p>6) Remove any of the logic from build.xml that refers to the Windows OS branch:</p>
<pre>vi build.xml
&lt;?xml version="1.0"?&gt;
&lt;project name="CaptureServer" default="release" basedir="."&gt;
        &lt;!-- all stuff to get the jni wrapper compiled --&gt;
        &lt;taskdef resource="net/sf/antcontrib/antcontrib.properties"/&gt;

        &lt;condition property="os" value="unix"&gt;
        &lt;os family="unix"/&gt;
    &lt;/condition&gt;

         &lt;property environment="env"/&gt;
     &lt;property name="src" value="."/&gt;
     &lt;property name="build" value="build"/&gt;
     &lt;property name="release" value="release"/&gt;

     &lt;target name="init"&gt;
          &lt;mkdir dir="${build}"/&gt;
                  &lt;mkdir dir="${release}"/&gt;
         &lt;/target&gt;

     &lt;target name="compile" depends="init"&gt;
          &lt;!-- Compile the java code --&gt;
          &lt;javac srcdir="${src}" destdir="${build}" debug="true" debuglevel="lines,vars,source"/&gt;

                  &lt;!-- Compile the revert code --&gt;
                   &lt;exec command="sh" executable="./compile_revert_linux.sh"/&gt;

     &lt;/target&gt;

         &lt;target name="jar" depends="compile"&gt;
        &lt;mkdir dir="${build}/jar"/&gt;
        &lt;jar destfile="${build}/jar/CaptureServer.jar" basedir="${build}"&gt;
            &lt;manifest&gt;
                &lt;attribute name="Main-Class" value="capture.Server"/&gt;
            &lt;/manifest&gt;
        &lt;/jar&gt;
    &lt;/target&gt;

        &lt;target name="release" depends="clean,compile,jar"&gt;
                &lt;copy file="${build}/jar/CaptureServer.jar" todir="${release}"/&gt;
                &lt;copy file="./COPYING" todir="${release}"/&gt;
                &lt;copy file="./Readme.txt" todir="${release}"/&gt;
                &lt;copy file="./input_urls_example.txt" todir="${release}"/&gt;
                &lt;copy file="./config.xsd" todir="${release}"/&gt;
                &lt;copy file="./config.xml" todir="${release}"/&gt;

                    &lt;exec executable="cp"&gt;
                      &lt;arg value="./revert"/&gt;
                      &lt;arg value="${release}"/&gt;
                    &lt;/exec&gt;

                &lt;zip destfile="./CaptureServer-Release.zip" basedir="release"/&gt;
        &lt;/target&gt;

        &lt;target name="clean"&gt;
        &lt;delete dir="${build}"/&gt;
                &lt;delete dir="${release}"/&gt;
                &lt;delete&gt;
                        &lt;fileset dir="." includes="revert.exe"/&gt;
                        &lt;fileset dir="." includes="revert"/&gt;
                        &lt;fileset dir="." includes="CaptureServer-Release.zip"/&gt;
                &lt;/delete&gt;
    &lt;/target&gt;
&lt;/project&gt;
</pre>
<p>6) Compile the Capture Server</p>
<pre>ant
Buildfile: build.xml
  [taskdef] Could not load definitions from resource net/sf/antcontrib/antcontrib.properties. It could not be found.

clean:
   [delete] Deleting directory /home/david/client_honeypots/capture-server-2.1.0-300-src/build
   [delete] Deleting directory /home/david/client_honeypots/capture-server-2.1.0-300-src/release

init:
    [mkdir] Created dir: /home/david/client_honeypots/capture-server-2.1.0-300-src/build
    [mkdir] Created dir: /home/david/client_honeypots/capture-server-2.1.0-300-src/release

compile:
    [javac] Compiling 32 source files to /home/david/client_honeypots/capture-server-2.1.0-300-src/build
    [javac] /home/david/client_honeypots/capture-server-2.1.0-300-src/capture/ClientFileReceiver.java:9: warning: sun.misc.BASE64Decoder is Sun proprietary API and may be removed in a future release
    [javac] import sun.misc.BASE64Decoder;
    [javac]                ^
    [javac] /home/david/client_honeypots/capture-server-2.1.0-300-src/capture/ClientFileReceiver.java:42: warning: sun.misc.BASE64Decoder is Sun proprietary API and may be removed in a future release
    [javac]                             BASE64Decoder base64 = new BASE64Decoder();
    [javac]                             ^
    [javac] /home/david/client_honeypots/capture-server-2.1.0-300-src/capture/ClientFileReceiver.java:42: warning: sun.misc.BASE64Decoder is Sun proprietary API and may be removed in a future release
    [javac]                             BASE64Decoder base64 = new BASE64Decoder();
    [javac]                                                        ^
    [javac] Note: /home/david/client_honeypots/capture-server-2.1.0-300-src/capture/MockClient.java uses unchecked or unsafe operations.
    [javac] Note: Recompile with -Xlint:unchecked for details.
    [javac] 3 warnings
     [exec] The command attribute is deprecated.
     [exec] Please use the executable attribute and nested arg elements.
     [exec] /usr/include/vmware-vix/
     [exec] revert.c:232:2: warning: no newline at end of file

jar:
    [mkdir] Created dir: /home/david/client_honeypots/capture-server-2.1.0-300-src/build/jar
      [jar] Building jar: /home/david/client_honeypots/capture-server-2.1.0-300-src/build/jar/CaptureServer.jar

release:
     [copy] Copying 1 file to /home/david/client_honeypots/capture-server-2.1.0-300-src/release
     [copy] Copying 1 file to /home/david/client_honeypots/capture-server-2.1.0-300-src/release
     [copy] Copying 1 file to /home/david/client_honeypots/capture-server-2.1.0-300-src/release
     [copy] Copying 1 file to /home/david/client_honeypots/capture-server-2.1.0-300-src/release
     [copy] Copying 1 file to /home/david/client_honeypots/capture-server-2.1.0-300-src/release
     [copy] Copying 1 file to /home/david/client_honeypots/capture-server-2.1.0-300-src/release
      [zip] Building zip: /home/david/client_honeypots/capture-server-2.1.0-300-src/CaptureServer-Release.zip

BUILD SUCCESSFUL
Total time: 2 seconds</pre>
<p>7) Extract the newly made CaptureServer-Release.zip file into a suitable location (such as a newly made capture-server-2.1.0-300 directory).</p>
<p>8) Configure config.xml and run as normal, such as via:</p>
<pre>cd capture-server-2.1.0-300
vi config.xml
/usr/lib/jvm/java-6-sun/bin/java -Djava.net.preferIPv4Stack=true -jar CaptureServer.jar -s your_ip:7070 -f input_urls_example.txt</pre>
<p>Hopefully Capture-HPC should work cleanly after that.</p>
<p><strong>NOTE</strong>: If you experience problems running Capture and find you receive this error when attempting to run the server:</p>
<pre><em><em>VIX Error on connect in connect: One of the parameters was invalid
</em></em></pre>
<p>check that your VMWare Server installation was clean by removing VMWare Server (vmware-uninstall.pl), finding any vmware related files in /usr, deleting them and then reinstalling VMWare. I found that one of my VMWare Server upgrades had left a number of vmware-vix shared libraries on disk and these seem to cause the newly compiled Capture Server to fail to connect on revert.</p>
<p>For more trouble shooting details, see this thread on the public <a href="http://public.honeynet.org/mailman/listinfo/capture-hpc">Capture-HPC mailing list</a>:</p>
<p><a href="http://public.honeynet.org/pipermail/capture-hpc/2008-August/000431.html">http://public.honeynet.org/pipermail/capture-hpc/2008-August/000431.html</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.ukhoneynet.org/2008/07/28/compiling-capture-hpc-on-vmware-server-106/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Sad State of IT Security</title>
		<link>http://www.ukhoneynet.org/2008/07/14/the-sad-state-of-it-security/</link>
		<comments>http://www.ukhoneynet.org/2008/07/14/the-sad-state-of-it-security/#comments</comments>
		<pubDate>Mon, 14 Jul 2008 16:29:56 +0000</pubDate>
		<dc:creator>arthur</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.ukhoneynet.org/?p=411</guid>
		<description><![CDATA[On Friday I found out that my credit card had been used, by nefarious persons unknown, to buy £500 worth of goods online. Bad enough, but this is the second time this has happened in four years. At this point I can hear the reader&#8217;s thoughts: stupid bugger, he&#8217;s been p0wned, got malware on his [...]]]></description>
				<content:encoded><![CDATA[<p>On Friday I found out that my credit card had been used, by nefarious persons unknown, to buy £500 worth of goods online. Bad enough, but this is the second time this has happened in four years.</p>
<p>At this point I can hear the reader&#8217;s thoughts: stupid bugger, he&#8217;s been p0wned, got malware on his machine. Well, it&#8217;s possible. Like nearly everyone out there, my machine might have been 0wn3d by someone really good. Unless your name is H.D.Moore, there&#8217;s always someone out there better than you. But it&#8217;s unlikely. I know exactly what should be running on my machine, I know what programs can talk to the outside world, I look at tcpdumps and use a browser + OS combination that&#8217;s not currently targetted in the wild. I think I can be reasonably confident that the only malware on my machine is the stuff that&#8217;s put there by me so I can study it.</p>
<p>So if my machine is clean (with high probability), I haven&#8217;t lost my card (100% certain as I have it with me now) and I shred all my bank statements, bills and till receipts (yup), how come I&#8217;ve still been defrauded?</p>
<p>I use my card online a lot. I don&#8217;t gamble online, buy porn, dodgy pills, email my card details around or send my details to nice gentlemen in Nigeria but I do buy stuff from a range of shops, small and big.</p>
<p>So my best guess is that my card has been taken from a merchant. What could I do to stop this happening?</p>
<p>Two options:</p>
<p>1) Never spend money online. Very limiting and not going to happen. Even if I was willing to live with the inconvience, it doesn&#8217;t give 100% protection anyway: my card could still be stolen if I use it at a bricks and mortar store (e.g. anyone who shopped at a store in the TJX group had their card placed at risk after <a href="http://www.securityfocus.com/news/11455">card details were stolen</a>). I&#8217;m certainly not going to stop using my card totally.</p>
<p>2) Only ever spend money with the biggest online shops: ones that are big enough to have their own security teams, do code audits etc etc. Stick with amazon.co.uk and tesco.com. Not foolproof, but a reasonable reduction in risk. The problem with this is that a lot of stuff I want to buy online is only available from smaller shops. Worse, it&#8217;s only available from mid-sized retailers. Ones that are too big to just use Paypal, big enough to have their own in house ASP or PHP developers, but not big enough to do it right.</p>
<p>You might think I&#8217;ve missed an option there: &#8217;3) Only buy from trusted retailers&#8217;. The trouble is that as a consumer, even one much more knowledgeable about security than most, there is no way I can make any valid judgement about a retailers security or lack thereof. I don&#8217;t have access to any information that will let me evaluate a retailers security, and without that information being available, there&#8217;s also no competitive pressure on stores. Instead we have to rely on the banking groups dragging standards upwards via things like the PCI DSS standards. These are good, but it&#8217;s a long slow grind.</p>
<p>Conclusions? My card has been stolen, it&#8217;s quite possible it&#8217;ll happen again, and there&#8217;s nothing I can do about it except to never use my card. Worse, because online crime is now a low priority for UK Police, I don&#8217;t even get to report this to the police, only to my bank, and I can be pretty confident that no-one will ever be charged for this (they weren&#8217;t last time even though I did report that incident to the police as it predated the new reporting arragements).</p>
<p>This is not a happy state of affairs. If the definition of distributed computing is the failure of a machine whose existence you don&#8217;t know about breaking something you are doing, then this is the security version: being compromised by systems you don&#8217;t know about and can&#8217;t influence.</p>
<p>Arthur</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ukhoneynet.org/2008/07/14/the-sad-state-of-it-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Phishers branch out in their targetting</title>
		<link>http://www.ukhoneynet.org/2008/07/08/phishing-branch-out-in-their-targetting/</link>
		<comments>http://www.ukhoneynet.org/2008/07/08/phishing-branch-out-in-their-targetting/#comments</comments>
		<pubDate>Tue, 08 Jul 2008 09:03:09 +0000</pubDate>
		<dc:creator>arthur</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Add new tag]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[scams]]></category>
		<category><![CDATA[spam]]></category>

		<guid isPermaLink="false">http://www.ukhoneynet.org/2008/07/08/phishing-branch-out-in-their-targetting/</guid>
		<description><![CDATA[Phishers have been branching out recently, moving on to new targets away from the traditional bank account scam. As users become more aware, and more banks roll out two factor authentication and other mitigations, scammers are having to move on to softer targets. In the past few months we&#8217;ve seen two new targets, with different [...]]]></description>
				<content:encoded><![CDATA[<p>Phishers have been branching out recently, moving on to new targets away from the traditional bank account scam. As users become more aware, and more banks roll out two factor authentication and other mitigations, scammers are having to move on to softer targets.</p>
<p>In the past few months we&#8217;ve seen two new targets, with different motivations. Both of these targets show trends in attacks as some targets become hardened. </p>
<p>First, many UK Universities have been hit with targetted phishing scams, usually claiming to come from &#8220;IT Support&#8221;. Any compromised accounts are then used to send out more spam. It&#8217;s a nice example of accounts being useful not so much for the information in them, but for the access they provide to other resources: bandwidth and credible email addresses</p>
<p>Second, as mentioned by Dancho Danchev <a href="http://blogs.zdnet.com/security/?p=1085">in May in ZDNet</a> and <a href="http://ddanchev.blogspot.com/2008/07/risks-of-outdated-situational-awareness.html">in June on his blog</a>, job sites are coming under attack. Dancho posted about the selling of tools that scrape information from CVs posted to online sites. Now we are seeing more direct attacks, with phishing emails aimed at getting login details of users of Monster.com and other job sites. Clearly gaining access to the information held on a job site is very useful to a scammer: it makes all sorts of nastiness easier.</p>
<p>It&#8217;s an arms race out there. Banks are now very quick at taking down phishing sites (see <a href="http://www.lightbluetouchpaper.org/category/banking-security/">the recent blog from Ross Anderson&#8217;s group at Cambridge</a> with links to stats on takedown), but other types of scams currently last much longer. If you&#8217;re one of the bad guys, it makes sense to go for the low hanging fruit. Why bother to steal someones online banking details when you can get more money for less work by stealing their identity? And why bother to go to lots of work to get their details when they have helpfully posted it on the web for you, all ready to use?</p>
<p>Arthur</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ukhoneynet.org/2008/07/08/phishing-branch-out-in-their-targetting/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Global Browser Vulnerability Survey</title>
		<link>http://www.ukhoneynet.org/2008/07/04/global-browser-vulnerability-survey/</link>
		<comments>http://www.ukhoneynet.org/2008/07/04/global-browser-vulnerability-survey/#comments</comments>
		<pubDate>Fri, 04 Jul 2008 11:40:29 +0000</pubDate>
		<dc:creator>david</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Whitepapers]]></category>

		<guid isPermaLink="false">http://www.ukhoneynet.org/2008/07/04/global-browser-vulnerability-survey/</guid>
		<description><![CDATA[A lot of current computer security threat research activity today occurs in the client space, with honeyclients such as Capture-HPC and PhoneyC regularly being used to study attacks against web browsers. Often these attacks occur through malicious obfuscated javascript and exploitation of vulnerable plugins or media extensions to allow fully automated &#8216;drive by download&#8217; infections. [...]]]></description>
				<content:encoded><![CDATA[<p>A lot of current computer security threat research activity today occurs in the client space, with honeyclients such as <a href="http://projects.honeynet.org/capture-hpc">Capture-HPC</a> and <a href="https://svn.mwcollect.org/phoneyc">PhoneyC</a> regularly being used to study attacks against web browsers. Often these attacks occur through malicious obfuscated javascript and exploitation of vulnerable plugins or media extensions to allow fully automated &#8216;drive by download&#8217; infections. The <a href="http://www.honeynet.org">Honeynet Project</a> have published a number of <a href="http://www.honeynet.org/papers/kye.html">Know Your Enemy whitepapers</a> in this area over the past year, and continue to actively research in this area. We have also <a href="http://www.ukhoneynet.org/EuSecWest08_David_Watson_EvilJS.pdf">previously</a> <a href="http://www.ukhoneynet.org/2007/07/18/new-javascript-tool-released/">blogged</a> about some of the ideas the <a href="http://www.ukhoneynet.org">UK Honeynet Project</a> have been experimenting with in this area.</p>
<p>One of the biggest challenges with client based threats is assessing the real world scale of the potential problem. For traditional server based threats, it was fair simple to survey the entire IPv4 space and determine what versions of a particular application or operating system were in active use at a particular time.  However, for client threats, you need a client application to come to you and interact with a service before any assessment of potential client vulnerabilities can be performed. This is a significant challenge for both attackers and researchers (hence the continued use of indiscriminate spamming and malicious advert serving at the same time as more targeted attacks are also being developed).</p>
<p>As the world&#8217;s most popular search engine, Google record the user agent client version data from the billions of web searches made by an estimated 75% of Internet users, and is therefore one of the organisations most likely to be able to provide an assessment of the current state of web browser security (Microsoft&#8217;s MSRT also has excellent data, but only for the ~450 million users regularly running Windows Automatic Updates). However, for obvious privacy reasons, this data has not been made available to the public.</p>
<p>An <a href="http://www.techzoom.net/publications/insecurity-iceberg/index.en">interesting survey</a> was released yesterday by Google Switzerland, IBM ISS and the Computer Engineering and Networks Laboratory of the University of Zurich, which provides the first systematic study of the browser data from around 1.4 billion Google users during the first half of 2008. They analysed Google&#8217;s client version data and correlated this with vulnerability data from sources such as Secunia&#8217;s PSI, in an attempt to assess how many vulnerable browsers were in circulation at a particular time.</p>
<p>The results are very interesting, with Internet Explorer taking 78% (1.1 billion) of the browser share and Firefox getting 16% (227 million). Drilling down deeper into the IE market share shows roughly half of IE users have now moved to IE7, whilst most FF users run the latest release. More worryingly, less that 50% of IE uses had the most secure version of their browser (rising to 83% in FF). For the month of June 2008, the authors suggest that over 45% web surfers (roughly some 637 million people) accessed Google with a browser that contained unpatched security vulnerabilities. There is also some interesting analysis of the exposure to plugged in as well as inbuilt vulnerabilities, plus some good recommendations for potential improvements to web browser security. In particular, the concept of web sites checking a browser&#8217;s agent strings and displaying a highly visible &#8220;expiry date&#8221; warning on every page (in an attempt to enforce a maximum shelf life) is worth further investigation.</p>
<p>The very welcome <a href="http://www.techzoom.net/publications/insecurity-iceberg/index.en">paper</a> is definitely worth a read, but is unlikely to cause too much immediate worry to the cyber criminals who are actively targeting web users through the thousands of mass compromised web servers, phishing emails and instant message spam we encounter each day.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ukhoneynet.org/2008/07/04/global-browser-vulnerability-survey/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>FIRST 2008</title>
		<link>http://www.ukhoneynet.org/2008/07/01/first-2008/</link>
		<comments>http://www.ukhoneynet.org/2008/07/01/first-2008/#comments</comments>
		<pubDate>Tue, 01 Jul 2008 13:15:43 +0000</pubDate>
		<dc:creator>david</dc:creator>
				<category><![CDATA[Events]]></category>
		<category><![CDATA[UK presentations]]></category>

		<guid isPermaLink="false">http://www.ukhoneynet.org/2008/07/01/first-2008/</guid>
		<description><![CDATA[The Honeynet Project were asked to present at the 20th FIRST conference in Vancouver last week, as part of their Network Monitoring Special Interest Group on Fast Flux Service Networks. We set up a two hour session broken down into three equal sections: An introduction to the basic mechanics of fast flux (David Watson, UKHP) [...]]]></description>
				<content:encoded><![CDATA[<p>The Honeynet Project were asked to present at the <a href="http://www.first.org/conference/2008/">20th FIRST conference in Vancouver</a> last week, as part of their <a href="http://www.first.org/conference/2008/program/presentations.html#p985">Network Monitoring Special Interest Group on Fast Flux Service Networks</a>. We set up a two hour session broken down into three equal sections:</p>
<ol>
<li>An introduction to the basic mechanics of fast flux (David Watson, <a href="http://www.ukhoneynet.org">UKHP</a>)</li>
<li>Current <a href="http://atlas.arbor.net/summary/fastflux">ATLAS</a> fast flux statistics (Jose Nazario, <a href="http://www.arbor.net">Arbor</a>)</li>
<li>Detection and mitigation (Christian Gorecki, <a href="http://pi1.informatik.uni-mannheim.de/index.php?pagecontent=site/Research.menu/Honeynet.page">University of Mannheim</a>)</li>
</ol>
<p>The NM-SG session was open to FIRST members only, so the slides are not publicly available, but we hope to have a public release of similar material shortly. We had a number of questions, and feedback from the attendees seems to have been positive.</p>
<p>There were three additional short demos:</p>
<ol>
<li>Florian Weimer of <a href="http://cert.uni-stuttgart.de/stats/dns-replication.php">RUS-CERT</a> showed some new passive DNS tracking information</li>
<li>Tillmann Werner from the German <a href="http://ghp.mwcollect.org/">Giraffe Honeynet Project Chapter</a> demonstrated how <a href="http://honeytrap.mwcollect.org/">Honeytrap</a>, <a href="http://libemu.mwcollect.org/">LibEmu</a> and <a href="http://nebula.mwcollect.org/">Nebula</a> can be used to <a href="http://honeytrap.mwcollect.org/whatfor">analyze unknown attacks</a>, which is looking very promising as a long term replacement for Nepenthes</li>
<li>Piotr Kijewski of the <a href="http://www.nask.pl/nask_en/">Polish CERT/NASK</a> gave a brief demonstration of their still under development HoneySpider web interface, which shares many of the features of client honeypot systems that we are currently working on but instead uses Java and Rhino instead of Python and SpiderMonkey</li>
</ol>
<p>Overall it was an interesting event, with some good talks and lot of opportunities to meet up with a different group of people very active in the security operations and incident response fields. Quiet a few <a href="http://www.honeynet.org">Honeynet Project</a> members were also present, which always encourages a little extra R&amp;D discussion. Hopefully we&#8217;ll see some spin off activity in the coming weeks.</p>
<p>Many thanks to Carol Overes from <a href="http://www.govcert.nl/">GovCERT</a> in Holland for the invite.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ukhoneynet.org/2008/07/01/first-2008/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>It had to happen</title>
		<link>http://www.ukhoneynet.org/2008/06/30/it-had-to-happen/</link>
		<comments>http://www.ukhoneynet.org/2008/06/30/it-had-to-happen/#comments</comments>
		<pubDate>Mon, 30 Jun 2008 09:00:10 +0000</pubDate>
		<dc:creator>arthur</dc:creator>
				<category><![CDATA[Incidents]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Add new tag]]></category>

		<guid isPermaLink="false">http://www.ukhoneynet.org/2008/06/30/it-had-to-happen/</guid>
		<description><![CDATA[Today we received our first bit of spam from EC2. The message itself was pretty standard: From: "Microsoft" Date: 29 June 2008 11:47:43 BST To: XXX Subject: Important Update Notification Hello XXX, You are receiving this notification because the version of Windows you are running is effected by a critical security issue. For the protection [...]]]></description>
				<content:encoded><![CDATA[<p>Today we received our first bit of spam from EC2. The message itself was pretty standard:</p>
<pre>
From: "Microsoft" <UpdateNotify56@microsoft.biz>
Date: 29 June 2008 11:47:43 BST
To: XXX
Subject: Important Update Notification

Hello XXX,

You are receiving this notification because the version of Windows you are running is effected by a critical security issue.

For the protection of yourself and others using the Windows operating system, it is reccomended that all consumers update their operating system at their earliest convenience.

To do so, you may visit Microsoft Update by clicking here, and simply pressing "Open" or "Run" to begin the automatic update process.

Thank you for your cooperation in resolving this matter.

Kind Regards,
Microsoft Customer Support 
</pre>
<p>The link points to a phishing site</p>
<pre>

http://XXX/go.nhn?url=http%3A%2F%2Fupdate%2Emicrosoft%2Ecom%2E00000000000000000000000000000000000000000000000000000000000000%2Enet

</pre>
<p>So far, so standard. The interesting bit is in the headers of the message:</p>
<pre>
Received: (qmail 29794 invoked from network); 29 Jun 2008 09:53:08 -0000
Received: from ec2-75-101-198-26.compute-1.amazonaws.com (HELO ec2-75-101-198-26.compute-1.amazonaws.com) (75.101.198.26)
  by server-14.tower-117.messagelabs.com with SMTP; 29 Jun 2008 09:53:08 -0000
From: "Microsoft" <UpdateNotify56@microsoft.biz>
</pre>
<p>How long before all email from EC2 is blacklisted? It was only a matter of time before services like this started to be used for sending spam, but this is the first time I&#8217;ve seen it in the wild.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ukhoneynet.org/2008/06/30/it-had-to-happen/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>submit-http for nepenthes</title>
		<link>http://www.ukhoneynet.org/2008/06/03/submit-http-for-nepenthes/</link>
		<comments>http://www.ukhoneynet.org/2008/06/03/submit-http-for-nepenthes/#comments</comments>
		<pubDate>Tue, 03 Jun 2008 16:57:01 +0000</pubDate>
		<dc:creator>jamie</dc:creator>
				<category><![CDATA[HOWTO]]></category>
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.ukhoneynet.org/?p=406</guid>
		<description><![CDATA[A hideously simplistic PHP handler for the nepenthes submit-http module. It Works For Me &#8482;. &#60;?php $ts=date('U'); $log= "timestamp=$ts"; $log.=",remotehost=".$_SERVER['REMOTE_ADDR']; foreach ($_POST as $key =&#62; $value) { switch ($key) { case "url": case "trigger": case "md5": case "sha512": case "filetype": case "source_host": case "target_host": case "filename": $$key = $value; $log .= ",$key=$value" ; break; } [...]]]></description>
				<content:encoded><![CDATA[<p>A hideously simplistic PHP handler for the nepenthes submit-http module. It Works For Me &trade;.</p>
<pre>
&lt;?php

$ts=date('U');
$log= "timestamp=$ts";
$log.=",remotehost=".$_SERVER['REMOTE_ADDR'];

foreach ($_POST as $key =&gt; $value)
{
        switch ($key)
        {

        case "url":
        case "trigger":
        case "md5":
        case "sha512":
        case "filetype":
        case "source_host":
        case "target_host":
        case "filename":
          $$key = $value;

          $log .= ",$key=$value" ;
          break;
        }
}
$log=$log."\n";
$myFile = "/tmp/submit-log";
$fh = fopen($myFile, 'a');
fwrite($fh, $log);
fclose($fh);

?&gt;
</pre>
<p>You&#8217;ll want your config file /etc/nepenthes/submit-http.conf to give this script as the URL, e.g. &#8220;http://myserver.example.com/submit.php&#8221; and enable the submit-http module in /etc/nepenthes/nepenthes.conf. After that, you probably want to figure out how to collect the binaries that nepenthes has just captured.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ukhoneynet.org/2008/06/03/submit-http-for-nepenthes/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
