<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; honeypot</title>
	<atom:link href="http://www.darknet.org.uk/tag/honeypot/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>PenTBox &#8211; Penetration Testing Security Suite</title>
		<link>http://www.darknet.org.uk/2010/03/pentbox-penetration-testing-security-suite/</link>
		<comments>http://www.darknet.org.uk/2010/03/pentbox-penetration-testing-security-suite/#comments</comments>
		<pubDate>Tue, 30 Mar 2010 09:49:46 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Password Cracking]]></category>
		<category><![CDATA[denial of service testing tool]]></category>
		<category><![CDATA[dos]]></category>
		<category><![CDATA[honeypot]]></category>
		<category><![CDATA[pentbox]]></category>
		<category><![CDATA[ruby]]></category>
		<category><![CDATA[ruby security tool]]></category>
		<category><![CDATA[secure password generator]]></category>
		<category><![CDATA[security suite]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2518</guid>
		<description><![CDATA[PenTBox is a Security Suite that packs security and stability testing oriented tools for networks and systems. Programmed in Ruby and oriented to GNU/Linux systems, but compatible with Windows, MacOS and every systems where Ruby works. It is free, licensed under GNU/GPLv3. PenTBox Contains Cryptography tools Base64 Encoder &#038; Decoder Multi-Digest (MD5, SHA1, SHA256, SHA384, [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>PenTBox is a Security Suite that packs security and stability testing oriented tools for networks and systems. Programmed in Ruby and oriented to GNU/Linux systems, but compatible with Windows, MacOS and every systems where Ruby works.</p>
<p>It is free, licensed under GNU/GPLv3.</p>
<p><strong>PenTBox Contains</strong></p>
<p><em><strong>Cryptography tools</strong></em></p>
<ul>
<li>Base64 Encoder &#038; Decoder</li>
<li>Multi-Digest (MD5, SHA1, SHA256, SHA384, SHA512)</li>
<li>Hash Password Cracker (MD5, SHA1, SHA256, SHA384, SHA512)</li>
<li>Secure Password Generator</li>
<li>Files en/decryptor Rijndael (AES) 256 bits – GOST – ARC4</li>
</ul>
<p><em><strong>Network tools</strong></em></p>
<ul>
<li>TCP Flood DoSer</li>
<li>TCP Flood AutoDoSer</li>
<li>Spoofed SYN Flood DoSer [nmap - hping3]</li>
<li>Port scanner</li>
<li>Honeypot</li>
<li>PenTBox Secure Instant Messaging</li>
</ul>
<p><em><strong>Extra</strong></em></p>
<ul>
<li>L33t Sp3@k Converter</li>
<li>Fuzzer</li>
</ul>
<p>An updated list of tools can be found <a href="http://www.pentbox.net/list-of-tools-updated/">here</a>.</p>
<p>You can download PenTBox v1.3.2 here:</p>
<p>Windows version (Ruby included) &#8211; <a href="http://www.pentbox.net/download_pentbox/releases/pentbox_1.3.2_win.zip">pentbox_1.3.2_win.zip</a><br />
Linux version &#8211; <a href="http://www.pentbox.net/download_pentbox/releases/pentbox_1.3.2.tar">pentbox_1.3.2.tar</a></p>
<p></p>
<p>Or read more <a href="http://www.pentbox.net/">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=PenTBox+%E2%80%93+Penetration+Testing+Security+Suite+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D2518+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2010/03/pentbox-penetration-testing-security-suite/&amp;t=PenTBox+%E2%80%93+Penetration+Testing+Security+Suite" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2010/03/pentbox-penetration-testing-security-suite/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2010/03/pentbox-penetration-testing-security-suite/&amp;title=PenTBox+%E2%80%93+Penetration+Testing+Security+Suite" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2010/03/pentbox-penetration-testing-security-suite/&amp;title=PenTBox+%E2%80%93+Penetration+Testing+Security+Suite" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2010/03/pentbox-penetration-testing-security-suite/&amp;title=PenTBox+%E2%80%93+Penetration+Testing+Security+Suite" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2010/03/pentbox-penetration-testing-security-suite/&amp;title=PenTBox+%E2%80%93+Penetration+Testing+Security+Suite" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2010%2F03%2Fpentbox-penetration-testing-security-suite%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2010/03/pentbox-penetration-testing-security-suite/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>DShield Web Honeypot Project &#8211; Alpha Version Released</title>
		<link>http://www.darknet.org.uk/2009/02/dshield-web-honeypot-project-alpha-version-released/</link>
		<comments>http://www.darknet.org.uk/2009/02/dshield-web-honeypot-project-alpha-version-released/#comments</comments>
		<pubDate>Fri, 20 Feb 2009 11:24:45 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Countermeasures]]></category>
		<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Security Software]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[community project]]></category>
		<category><![CDATA[dshield]]></category>
		<category><![CDATA[dshield honeypot]]></category>
		<category><![CDATA[dshield web honeypot]]></category>
		<category><![CDATA[honeypot]]></category>
		<category><![CDATA[isc]]></category>
		<category><![CDATA[sans]]></category>
		<category><![CDATA[web honeypot]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1496</guid>
		<description><![CDATA[For those of you who are not familiar with DShield (where have you been? under a rock?) it&#8217;s a Cooperative Network Security Community. Basically what that means is they collect firewall logs and map out the trends. Like when there was a worm going around that bruteforced SSH2 you could see a spike in port [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>For those of you who are not familiar with <a href="http://www.dshield.org/indexd.html">DShield</a> (where have you been? under a rock?) it&#8217;s a Cooperative Network Security Community. Basically what that means is they collect firewall logs and map out the trends.</p>
<p>Like when there was a worm going around that bruteforced SSH2 you could see a spike in port 22 traffic, to quote the about page.</p>
<blockquote><p>The ISC uses the DShield distributed intrusion detection system for data collection and analysis. DShield collects data about malicious activity from across the Internet. This data is cataloged and summarized and can be used to discover trends in activity, confirm widespread attacks, or assist in preparing better firewall rules.</p>
<p>Currently the system is tailored to process outputs of simple packet filters. As firewall systems that produce easy to parse packet filter logs are now available for most operating systems, this data can be submitted and used without much effort. </p></blockquote>
<p>If you want to know how to submit you can find out <a href="http://www.dshield.org/howto.html">here</a>.</p>
<p>Anyway to get back to the point, with the trend for development moving towards web applications DShield has come out with a Web Honeypot project.</p>
<p>The overall idea is to build something like DShield (which collects firewall logs) for webapps.</p>
<p>The goal of the project is to collect quantitative data measuring the activity of automated or semi-automated probes against web applications. First of all, we will not just look for &#8220;attacks&#8221;. We look for &#8220;probes&#8221;. If they are malicious or not can only be determined in context.</p>
<p>We will not look for 0-day style or targeted attacks. Maybe we will get lucky and catch one. But in order to detect them, we would need sensors in specific networks. What we are after is more the &#8220;background noise&#8221;.</p>
<p><strong>How does it work?</strong><br />
A:  The Web Honeypot is made up of 3 elements: a client, a set of templates and a logging system. All web requests destined for the honeypot are passed to the honeypot client. The client attempts to match the specific web application requested to one of the templates installed in the honeypot. If a suitable template is found then it is sent back to the requester. If there is no template available, a default web page is returned. In both cases the specific web application request is logged and sent to a central DShield database.</p>
<p><strong>Should I run this on my production environment?</strong><br />
A:  That depends on your risk tolerance.  If your organization is willing to approve it, then the program itself is designed so that it can run as a virtual host under apache.  You could assign unused IP addresses to the honeypot virtual host.</p>
<p><strong>Can I run this at home?</strong><br />
A:  Several people already are.  If you can forward port 80 to your honeypot machine, then it will work.<br />
Installation:</p>
<p><strong>Will the Web Honeypot work on my OS?</strong><br />
A: Currently the Web Honeypot works on Windows (2000 or later) and Linux OS with install packages available for: Debian, Redhat, openSUSE and Mac OSX.</p>
<p><strong>Does it run on Windows/IIS/PHP?</strong><br />
A:  It should with some minor modifications.  IIS does not support the same redirection of all requests that apache does.</p>
<p>You can download the Web Honeypot here:</p>
<p><a href="http://sites.google.com/site/webhoneypotsite/alpha-release/downalpha-release/webhoneypot-alpha.tgz?attredirects=0">webhoneypot-alpha.tgz</a></p>
<p></p>
<p>Or read more <a href="http://sites.google.com/site/webhoneypotsite/">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=DShield+Web+Honeypot+Project+%E2%80%93+Alpha+Version+Released+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D1496+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/02/dshield-web-honeypot-project-alpha-version-released/&amp;t=DShield+Web+Honeypot+Project+%E2%80%93+Alpha+Version+Released" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2009/02/dshield-web-honeypot-project-alpha-version-released/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/02/dshield-web-honeypot-project-alpha-version-released/&amp;title=DShield+Web+Honeypot+Project+%E2%80%93+Alpha+Version+Released" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/02/dshield-web-honeypot-project-alpha-version-released/&amp;title=DShield+Web+Honeypot+Project+%E2%80%93+Alpha+Version+Released" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2009/02/dshield-web-honeypot-project-alpha-version-released/&amp;title=DShield+Web+Honeypot+Project+%E2%80%93+Alpha+Version+Released" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/02/dshield-web-honeypot-project-alpha-version-released/&amp;title=DShield+Web+Honeypot+Project+%E2%80%93+Alpha+Version+Released" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2009%2F02%2Fdshield-web-honeypot-project-alpha-version-released%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/02/dshield-web-honeypot-project-alpha-version-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>HoneyBot &#8211; A Windows Based Honeypot</title>
		<link>http://www.darknet.org.uk/2006/07/honeybot-a-windows-based-honeypot/</link>
		<comments>http://www.darknet.org.uk/2006/07/honeybot-a-windows-based-honeypot/#comments</comments>
		<pubDate>Tue, 11 Jul 2006 04:48:32 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Countermeasures]]></category>
		<category><![CDATA[Security Software]]></category>
		<category><![CDATA[computer-security]]></category>
		<category><![CDATA[honeybot]]></category>
		<category><![CDATA[honeypot]]></category>
		<category><![CDATA[intrusion-detection]]></category>
		<category><![CDATA[network-security]]></category>
		<category><![CDATA[windows-honeypot]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2006/07/honeybot-a-windows-based-honeypot/</guid>
		<description><![CDATA[HoneyBOT HoneyBOT is a Windows based medium interaction honeypot solution. What is a Honeypot? A honeypot is a device placed on a computer network specifically designed to capture malicious network traffic. The logging capability of a honeypot is far greater than any other network security tool and captures raw packet level data even including the [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p><strong>HoneyBOT</strong></p>
<p>HoneyBOT is a Windows based medium interaction honeypot solution.</p>
<p><strong>What is a Honeypot?</strong></p>
<p>A honeypot is a device placed on a computer network specifically designed to capture malicious network traffic. The logging capability of a honeypot is far greater than any other network security tool and captures raw packet level data even including the keystrokes and mistakes made by hackers. The captured information is highly valuable as it contains only malicious traffic with little to no false positives.</p>
<p>Honeypots are becoming one of the leading security tools used to monitor the latest tricks and exploits of hackers by recording their every move so that the security community can more quickly respond to new exploits.</p>
<p><strong>How it Works</strong></p>
<p>HoneyBOT works by opening over 1000 udp and tcp listening sockets on your computer and these sockets are designed to mimic vulnerable services. When an attacker connects to these services they are fooled into thinking they are attacking a real server. The honeypot safely captures all communications with the attacker and logs these results for future analysis. Should an attacker attempt an exploit or upload a rootkit or trojan to the server the honeypot environment will safely store these files on your computer for analysis and submission to antivirus vendors. Our test server has captured several thousand trojans and rootkits from these simulated services including:</p>
<ul>
<li>Dabber</li>
<li>Devil</li>
<li>Kuang</li>
<li>MyDoom</li>
<li>Netbus</li>
<li>Sasser</li>
<li>LSASS</li>
<li>DCOM (msblast, etc)</li>
<li>Lithium</li>
<li>Sub7</li>
</ul>
<p><strong>HoneyBOT Installation</strong></p>
<p>We suggest that you install HoneyBOT on a dedicated computer with no valuable information or resources required of it. In fact, you want your honeypot to be as free as possible from any legitimate traffic so in broad terms we can consider any traffic to the honeypot to be malicious in nature.</p>
<p>HoneyBOT requires minimum operating system of Windows 2000 and at least 128MB RAM is recommended.</p>
<p>You can read more here:</p>
<p></p>
<p><a href="http://www.atomicsoftwaresolutions.com/honeybot.php">Honeybot</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=HoneyBot+%E2%80%93+A+Windows+Based+Honeypot+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D238+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2006/07/honeybot-a-windows-based-honeypot/&amp;t=HoneyBot+%E2%80%93+A+Windows+Based+Honeypot" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2006/07/honeybot-a-windows-based-honeypot/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2006/07/honeybot-a-windows-based-honeypot/&amp;title=HoneyBot+%E2%80%93+A+Windows+Based+Honeypot" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2006/07/honeybot-a-windows-based-honeypot/&amp;title=HoneyBot+%E2%80%93+A+Windows+Based+Honeypot" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2006/07/honeybot-a-windows-based-honeypot/&amp;title=HoneyBot+%E2%80%93+A+Windows+Based+Honeypot" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2006/07/honeybot-a-windows-based-honeypot/&amp;title=HoneyBot+%E2%80%93+A+Windows+Based+Honeypot" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2006%2F07%2Fhoneybot-a-windows-based-honeypot%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2006/07/honeybot-a-windows-based-honeypot/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Malware Honeypot Projects Merge &#8211; mwcollect and nepenthes</title>
		<link>http://www.darknet.org.uk/2006/02/malware-honeypot-projects-merge-mwcollect-and-nepenthes-ready/</link>
		<comments>http://www.darknet.org.uk/2006/02/malware-honeypot-projects-merge-mwcollect-and-nepenthes-ready/#comments</comments>
		<pubDate>Mon, 27 Feb 2006 02:55:35 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[honeynet]]></category>
		<category><![CDATA[honeypot]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[mwcollect]]></category>
		<category><![CDATA[nepenthes]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2006/02/malware-honeypot-projects-merge-mwcollect-and-nepenthes-ready/</guid>
		<description><![CDATA[Looking to streamline the collection of malware samples, two of the biggest honeypot projects mwcollect and nepenthes have merged operations. The two projects, which passively trap viruses, spyware and other forms of malicious software by emulating known vulnerabilities, will combine operations to develop a single malware collection tool, according to an announcement my mwcollect head [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>Looking to streamline the collection of malware samples, two of the biggest honeypot projects mwcollect and nepenthes have merged operations.</p>
<p>The two projects, which passively trap viruses, spyware and other forms of malicious software by emulating known vulnerabilities, will combine operations to develop a single malware collection tool, according to an announcement my mwcollect head developer Georg Wicherski.</p>
<p>The merger comes after a year of concurrent development that caused a lot of overlap and shared work, Wicherski said.</p>
<p>&#8220;Mwcollect.org will become a top-level community covering malware collection efforts, [and] nepenthes will become the official software used for malware collection and be part of mwcollect.org,&#8221; he said.</p>
<p>A new <a href="http://mwcollect.org/">mwcollect.org</a> meta-portal will be created to host information related to malware collection.</p>
<p></p>
<p>Source: <a href="http://www.eweek.com/article2/0,1895,1930735,00.asp">Eweek</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Malware+Honeypot+Projects+Merge+%E2%80%93+mwcollect+and+nepenthes+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D68+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2006/02/malware-honeypot-projects-merge-mwcollect-and-nepenthes-ready/&amp;t=Malware+Honeypot+Projects+Merge+%E2%80%93+mwcollect+and+nepenthes" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2006/02/malware-honeypot-projects-merge-mwcollect-and-nepenthes-ready/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2006/02/malware-honeypot-projects-merge-mwcollect-and-nepenthes-ready/&amp;title=Malware+Honeypot+Projects+Merge+%E2%80%93+mwcollect+and+nepenthes" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2006/02/malware-honeypot-projects-merge-mwcollect-and-nepenthes-ready/&amp;title=Malware+Honeypot+Projects+Merge+%E2%80%93+mwcollect+and+nepenthes" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2006/02/malware-honeypot-projects-merge-mwcollect-and-nepenthes-ready/&amp;title=Malware+Honeypot+Projects+Merge+%E2%80%93+mwcollect+and+nepenthes" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2006/02/malware-honeypot-projects-merge-mwcollect-and-nepenthes-ready/&amp;title=Malware+Honeypot+Projects+Merge+%E2%80%93+mwcollect+and+nepenthes" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2006%2F02%2Fmalware-honeypot-projects-merge-mwcollect-and-nepenthes-ready%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2006/02/malware-honeypot-projects-merge-mwcollect-and-nepenthes-ready/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

