(Move to ...)
Home
Resources
Research Projects
Career Tools
About
▼
Showing posts with label
Project Picnic Basket
.
Show all posts
Showing posts with label
Project Picnic Basket
.
Show all posts
A Look at Fax Phishing
›
I recently setup a new honeypot which appears to be an IT security related company. In addition to a few other hidden gems, this honeypot ...
New Honeypot Online!
›
I just got my second honeypot up an running - Glastopf ! This honeypot will allow me to capture HTTP based attacks, as well as the SSH att...
IRC Floodbot Placed on My Honeypot
›
Someone dropped off an IRC Floodbot today on my honeypot. It's nothing spectacular or groundbreaking, and appears to have been around ...
Hacking to Setup a Free Counter Strike Server?
›
This week an attacker cracked my honeypot's root password "123456" and tried to install software I've never seen before. ...
Linux Rootkit "bum.pdf" dropped onto my Honeypot Today
›
A malicious user from Romania using Putty dropped off a Linux rootkit on my honeypot today. From my initial analysis it appears that the h...
New Hacktool Found on my Honeypot "nt"
›
A script kiddy dropped off a new hack tool on my honeypot today. Today's guest hails from 77.28.151.190 which is in Macedonia, The Fo...
Watch my Honeypot LIVE!
›
I've decided to start streaming my honeypot on UStream. No set hours for this yet, but it should be interesting when it is live! Pl...
Malware Analysis Lab - New Feature!
›
I'm happy to announce that I have created a Google code project called the Caffeine Security Malware Analysis Lab . At this project, y...
Following the Trail: Determining the Origins of Linux/Bckdr-RKC
›
It is already known that the two Linux/Bckdr-RKC variants I have received have both been hosted by 216.83.44.229. Furthermore, the first va...
Chinese Origins in .ssyslog Decompiled - Linux/Bckdr-RKC and Hutizu
›
I have partially decompiled the second piece of malware which was similar to the original Linux/Bckdr-RKC dropped on my honeypot. Update ...
Linux/Bckdr-RKC: A New Variant Appears
›
Someone was busy this Christmas. A new variant of Linux/Bckdr-RKC has been placed on my honeypot. Unfortunately detections by Sophos do ...
Linux/Bckdr-RKC Initial Analysis
›
A malicious user dropped off a VERY interesting piece of malware on my honeypot today with the filename ".xsyslog" This piece of...
Mystery Malware: An echo powered DDoS Script?
›
Christmas came early today, and a hacker dropped off a present...a piece of mystery malware. This piece of malware was dropped onto my Lin...
If ET were a Hacker, he would just try to phone home...
›
Up until now, all of the honeypot compromises I've logged have simply been attempts to propagate network scanning and IRC bots. Today...
BUSTED!
›
The password cracker script kiddies can't resist my picnic basket... Today an attacker with a SSH brute force script accidentally ...
Mystery Malware Examined
›
In a previous post, I looked inside a hacker's toolkit, and found two "mystery files", "i" and "f". Anal...
What's in a hacker's toolkit?
›
An attacker recently gained access to my honeypot, and began uploading hack tools using wget. While his hack tools did not actually infect...
A look at a simple SSH probe and password crack
›
Here's an annotated look at how an attacker using a SSH password cracker compromises servers. First the attacker probes to see if SSH...
"Listening" to a Password Cracker
›
I used the P22.com Music Text Composition Generator to create music using attempted usernames and passwords I gathered during just one crack...
More password analysis
›
As more passwords are processed by my honeypot, I've decided to publish the password list in "cloud" format in addition to the...
›
Home
View web version