To learn the tools, tactics and motives involved in computer and network attacks, and share the lessons learned.

Blogs

Thug Plugin Framework

In the last months I spent a lot of efforts in Thug development. During these months a few interesting features and improvements were introduced but right now I want to spend some time for taking a look at the new plugin framework introduced in the version 0.3.0. If you ever thought about extending Thug with additional features but didn’t know how to do it you should really keep on reading. Let’s start by taking a look a the code.

Taking a look at src/thug.py we can now read these lines of code

216 if p:
217     ThugPlugins(PRE_ANALYSIS_PLUGINS, self)()

Progress so far at the Network Analyzer

Although it is still time for the official coding period start at GSoC 2012, i started to make my commits for the Network Analyzer project . The output of the project will be a web based traffic analyzer. It is aimed to let people upload their files from web interface and see the results. Instead of the detail header information, network analyzer will be focusing on applicaiton level data for display.

Glastopf v3 aka Glaspot released

We where glad to announce yet another tool during our annual workshop in San Francisco. Glaspot is the third version of the web application honeypot Glastopf and it come with some very powerful new features:

  • A build-in PHP sandbox for code injection emulation, allowing us to bring vulnerability emulation to a new level
  • Hooked up to the HPFeeds generic data feed system for centralized data collection and tight integration into our sandbox and web server botnet monitoring system
  • Modular implementation: Turn your web application into a honeypot with a few easy steps
  • Runs in his own lightweight Python server or as a WSGI module in common web server environments
  • Automated attack surface generation and expansion

GSoC 2012 Accepted Students Officially Announced

Since my last post about the Google Summer Of Code 2012 Student Applications deadline closing and sharing some initial student applications statistics, all the GSoC 2012 mentoring organisations have been hard at work reviewing and scoring their student applications.

The Winner of the Norman Malware Analyzer G2 raffle is ...

At the Honeynet Project workshop 2012, we raffled off a brand new Norman Malware Analyzer G2. Thanks everybody for participating in the raffle.

The winner of this year's raffle is Todd Straceski from Zynga. Congratulations to Todd!

Thanks again to Norman to sponsoring the Honeynet Project workshop 2012. We hope to see you all again next year.

Google Summer Of Code 2012 Student Applications now closed and some statistics

After a slower than usual start, this years Google Summer of Code (GSoC) student applications period closed at 19:00 UTC on Friday April 6th, with a major application rush in the last couple of days which kept us busy right up to the deadline! Many thanks to all the interested students who applied, and our mentors and org admins for taking the time to respond to students on IRC, email and through Melange.

Honeynet Project Security Workshop 2012 - VIDEOs posted

Folks, we had a great time at the Honeynet Project Security Workshop @ Facebook. We'd like to thank again our execellent hosts Facebook, the attendees, and our many speakers.

If you were not able to attend, you can check out the videos at http://honeynet.org/SecurityWorkshops/2012_SF_Bay_Area/Mar_19/Workshop_Program_Agenda.

Just a few days left to submit your GSoc application

Students,

the GSoc 2012 student application deadline is approaching (April 06 at 19:00 UTC) - you have 2 days and 20 hours to submit your application to https://www.google-melange.com/gsoc/org/google/gsoc2012/honeynet.

We have an array of exciting open-source security projects posted on our ideas page, but feel free to submit your own idea as well (best to discuss with potential mentors first though). You can reach mentors on gsoc@public.honeynet.org or on #gsoc2012-honeynet on irc.freenode.net.

Hope to see your application soon (If you are planning on submitting an application, we recommend to submit now and modify until the deadline. You dont want to be shut out merely because of connection issues and such...)

- the HP GSoc admin & mentors

Google Summer Of Code 2012 Student Applications - Deadline Approaching

If you have been following our blog you'll know that the Honeynet Project was very happy to have been accepted as a mentoring organization for Google Summer of Code (GSoC) 2012.

If you are a student interested in applying to the Honeynet Project, the student application deadline is 19:00 UTC on Friday April 6th. So with 3 days to go, you need to be planning on submitting your project application vi the Melange system soon. To avoid disappointment, please don't leave your application until the last minute - you can edit as often as you want before the deadline.

FAQ on Kelihos.B/Hlux.B sinkholing

On March 31, 2012, the Honeynet Project published a draft Code of Conduct and a statement about Ethics in Computer Security Research: Kelihos.B/Hlux.B botnet takedown.

The initial draft of the Code of Conduct was drawn from concepts described in the The Menlo Report: Ethical Principles Guiding Information and Communication Technology Research that was published in the United States Federal Register on December 28, 2011 for public comment. The Code of Conduct was refined through discussion within the Legal and Ethics Committee and volunteer Honeynet Project members to help make it workable within the structure of the Honeynet Project membership for evaluating the ethics of future research activities.

The following FAQ reflects how the Menlo Report principles and proposed Honeynet Project Code of Conduct can be used to analyze and explain an action like the Kelihos/Hlux sinkholing operation.

Syndicate content