Detecting Botnets Using a Low Interaction Honeypot

Status
Not open for further replies.

office politics

It's all just 1s and 0s
Messages
6,555
Location
in the lab
Detecting Botnets Using a Low Interaction Honeypot by Jamie Riden on 23/03/06

This paper describes a simple honeypot using PHP and emulating several vulnerabilities in Mambo and Awstats. We show the mechanism used to 'compromise' the server and to download further malware. This honeypot is 'fail-safe' in that when left unattended, the default action is to do nothing – though if the operator is present, exploitation attempts can be investigated. IP addresses and other details have been obfuscated in this version.
 
Status
Not open for further replies.
Back
Top Bottom