<rss version="2.0"><channel><title>Honeypots (honeypots) Mailing List</title>
<link>http://seclists.org/#honeypots</link>
<description>Discussions about tracking attackers by setting up decoy honeypots or entire honeynet networks.</description>
<language>en-us</language><ttl>60</ttl>
<item><title>Re: Stealth VM</title><description>Posted by Michael Bailey on Oct 6&lt;p&gt;


&lt;p&gt;
We discussed the extent of and several techniques for honeypot  
&lt;br /&gt;
fingerprinting in our paper &amp;quot;Towards an Understanding of Anti- 
&lt;br /&gt;
virtualization and Anti-debugging Behavior in Modern Malware&amp;quot;  (http://www.eecs.umich.edu/~mibailey/publications/dsn08_final.pdf 
&lt;br /&gt;
). Techniques for...</description>
<link>http://seclists.org/honeypots/2008/q4/0002.html</link><guid isPermaLink="true">http://seclists.org/honeypots/2008/q4/0002.html</guid>
<pubDate>Mon, 6 Oct 2008 07:52:08 -0400</pubDate></item>
<item><title>Stealth VM</title><description>Posted by Stuart Gilchrist-Thomas on Oct 6&lt;p&gt;


&lt;p&gt;
Hi,
&lt;br /&gt;
&lt;p&gt;Does anyone have any pointers to evidence or advice on hiding or reducing the detection of VM honey pots. I know of temporal issues e.g. Timing metrics can give away a VM, and that you can manually alter peripheral identities e.g. virtual network cards etc. 
&lt;br /&gt;
I&#39;ve also created a company to...</description>
<link>http://seclists.org/honeypots/2008/q4/0001.html</link><guid isPermaLink="true">http://seclists.org/honeypots/2008/q4/0001.html</guid>
<pubDate>Mon,  6 Oct 2008 08:20:09 +0100</pubDate></item>
<item><title>Re: Honeypot VMs</title><description>Posted by Jason Lewis on Sep 23&lt;p&gt;


&lt;p&gt;
I should have mentioned I&#39;m using roo from The Honeynet Project. 
&lt;br /&gt;
https://projects.honeynet.org/honeywall/
&lt;br /&gt;
&lt;p&gt;I saw that someone had a VM with nepenthes
&lt;br /&gt;
(http://www.sparsa.org/node/23) and wondered if anyone else had created
&lt;br /&gt;
ready to go VMs.  It would save me some time.
&lt;br /&gt;
&lt;p&gt;jas
&lt;br /&gt;
&lt;p&gt;Jason Lewis wrote:
&lt;br /&gt;...</description>
<link>http://seclists.org/honeypots/2008/q3/0008.html</link><guid isPermaLink="true">http://seclists.org/honeypots/2008/q3/0008.html</guid>
<pubDate>Tue, 23 Sep 2008 17:40:38 -0400</pubDate></item>
<item><title>Honeypot VMs</title><description>Posted by Jason Lewis on Sep 23&lt;p&gt;


&lt;p&gt;
Are there any honeypot VM resources?  I&#39;ve seen the SPARSA one, but the
&lt;br /&gt;
link is dead.
&lt;br /&gt;
&lt;p&gt;jas
&lt;br /&gt;
Received on Sep 23 2008

</description>
<link>http://seclists.org/honeypots/2008/q3/0007.html</link><guid isPermaLink="true">http://seclists.org/honeypots/2008/q3/0007.html</guid>
<pubDate>Tue, 23 Sep 2008 14:54:21 -0400</pubDate></item>
<item><title>Picviz 0.3 released</title><description>Posted by Sebastien Tricaud on Sep 20&lt;p&gt;


&lt;p&gt;
Picviz &#39;good coffee&#39; 0.3 is *out*.
&lt;br /&gt;
...to have a good coffee, we must filter it!
&lt;br /&gt;
&lt;p&gt;What is Picviz ?
&lt;br /&gt;
================
&lt;br /&gt;
&lt;p&gt;Picviz is a parallel coordinates plotter, written to help people
&lt;br /&gt;
finding a needle in a haystack when dealing with numerous events
&lt;br /&gt;
on their system and struggling to maintain an...</description>
<link>http://seclists.org/honeypots/2008/q3/0006.html</link><guid isPermaLink="true">http://seclists.org/honeypots/2008/q3/0006.html</guid>
<pubDate>Sat, 20 Sep 2008 10:22:31 +0200 (CEST)</pubDate></item>
<item><title>Hack.lu 2008 update</title><description>Posted by hack.lu 2008 on Sep 10&lt;p&gt;


&lt;p&gt;
Hi all,
&lt;br /&gt;
&lt;p&gt;Hack.lu 2008 is getting closer and closer.
&lt;br /&gt;
&lt;p&gt;Find hereafter the line-up of speakers and talks for this year&#39;s event:
&lt;br /&gt;
&lt;p&gt;Saumil Shah  - Browser Exploits - A new model for Browser security
&lt;br /&gt;
Roelof Temmingh - Investigating individuals and groups using open source
&lt;br /&gt;
intelligence
&lt;br /&gt;
Paul Craig -...</description>
<link>http://seclists.org/honeypots/2008/q3/0005.html</link><guid isPermaLink="true">http://seclists.org/honeypots/2008/q3/0005.html</guid>
<pubDate>Wed, 10 Sep 2008 13:51:46 +0200</pubDate></item>
<item><title>Release of Client Honeypot Capture-HPC v2.5.1</title><description>Posted by christian.seifert_at_gmail.com on Sep 6&lt;p&gt;


 (&#39;binary&#39; encoding is not supported, stored as-is)
The Honeynet Project (http://www.honeynet.org) and School of Mathematics, Statistics and Computer Science at Victoria University of Wellington (http://www.mcs.vuw.ac.nz/) are excited to announce the release of Capture-HPC v2.5.1. Capture-HPC is...</description>
<link>http://seclists.org/honeypots/2008/q3/0004.html</link><guid isPermaLink="true">http://seclists.org/honeypots/2008/q3/0004.html</guid>
<pubDate>6 Sep 2008 19:57:55 -0000</pubDate></item>
<item><title>RUXCON 2008 Final Call For Papers</title><description>Posted by cfp_at_ruxcon.org.au on Sep 2&lt;p&gt;


&lt;p&gt;
RUXCON 2008 FINAL CALL FOR PAPERS
&lt;br /&gt;
&lt;p&gt;Ruxcon would like to announce the final call for papers for the fifth annual
&lt;br /&gt;
Ruxcon conference.
&lt;br /&gt;
&lt;p&gt;This year the conference will take place over the weekend of
&lt;br /&gt;
29th to the 30th of November.
&lt;br /&gt;
&lt;p&gt;As with previous years, Ruxcon will be held at the University of
&lt;br /&gt;...</description>
<link>http://seclists.org/honeypots/2008/q3/0003.html</link><guid isPermaLink="true">http://seclists.org/honeypots/2008/q3/0003.html</guid>
<pubDate>Tue,  2 Sep 2008 05:14:34 +0000 (UTC)</pubDate></item>
<item><title>PacSec 2008 CFP (Deadline Sept. 1, Conference Nov. 1213) and BA-Con 2008 Speakers (Sept. 30 Oct. 1)</title><description>Posted by Dragos Ruiu on Aug 26&lt;p&gt;


&lt;p&gt;
Spanish url: http://ba-con.com.ar/speakers.html?language=es
&lt;br /&gt;
&lt;p&gt;Speaker list and Dojos for BA-Con, September 30, October 1st.
&lt;br /&gt;
(all presentations in both Spanish and English)
&lt;br /&gt;
&lt;p&gt;&amp;nbsp;&amp;nbsp;Presentations:
&lt;br /&gt;
&lt;p&gt;&amp;nbsp;&amp;nbsp;WPA/WPA2: how long is it gonna make it - C&eacute;dric Blancher &amp;amp; Simon Mar&eacute;chal, 
&lt;br /&gt;...</description>
<link>http://seclists.org/honeypots/2008/q3/0002.html</link><guid isPermaLink="true">http://seclists.org/honeypots/2008/q3/0002.html</guid>
<pubDate>Tue, 26 Aug 2008 13:02:25 -0700</pubDate></item>
<item><title>Picviz 0.2 is out!</title><description>Posted by Sebastien Tricaud on Aug 7&lt;p&gt;


&lt;p&gt;
Release note for Picviz 0.2
&lt;br /&gt;
===========================
&lt;br /&gt;
&lt;p&gt;Picviz is a parallel coordinates plotter which enables easy scripting from
&lt;br /&gt;
various input (tcpdump, syslog, iptables logs, apache logs, etc..) to visualize
&lt;br /&gt;
your data and discover interesting results quickly.
&lt;br /&gt;
&lt;p&gt;Picviz helps you to create,...</description>
<link>http://seclists.org/honeypots/2008/q3/0001.html</link><guid isPermaLink="true">http://seclists.org/honeypots/2008/q3/0001.html</guid>
<pubDate>Thu, 7 Aug 2008 14:39:58 +0200 (CEST)</pubDate></item>
</channel></rss>