<?xml version="1.0" encoding="utf-8"?>
<feed version="0.3" xmlns="http://purl.org/atom/ns#" xmlns:dc="http://purl.org/dc/elements/1.1/" xml:lang="en">
<title>Honeyclient Development Project</title>
<link rel="alternate" type="text/html" href="http://www.synacklabs.net/honeyclient/" />
<modified>2007-07-03T03:00:33Z</modified>
<tagline></tagline>
<id>tag:www.synacklabs.net,2007:/honeyclient//3</id>
<generator url="http://www.movabletype.org/" version="3.12">Movable Type</generator>
<copyright>Copyright (c) 2007, Kathy</copyright>
<entry>
<title>New Honeyclient Project Website</title>
<link rel="alternate" type="text/html" href="http://www.synacklabs.net/honeyclient/archives/2007/07/new_honeyclient.html" />
<modified>2007-07-03T03:00:33Z</modified>
<issued>2007-07-03T02:54:09Z</issued>
<id>tag:www.synacklabs.net,2007:/honeyclient//3.217</id>
<created>2007-07-03T02:54:09Z</created>
<summary type="text/plain">It&apos;s been a long time, but that doesn&apos;t mean we have not been busy. I&apos;m going to go ahead and do what I should have done a while back, so here&apos;s where our up-to-date project website is now at. At...</summary>
<author>
<name>Kathy</name>

<email>knwang@synacklabs.net</email>
</author>
<dc:subject>Interesting News</dc:subject>
<content type="text/html" mode="escaped" xml:lang="en" xml:base="http://www.synacklabs.net/honeyclient/">
<![CDATA[<p>It's been a long time, but that doesn't mean we have not been busy. I'm going to go ahead and do what I should have done a while back, so here's where our up-to-date project <a href="http://www.honeyclient.org/trac">website is now at</a>.</p>

<p>At this new site (actually, close to a year old now), you will find a detailed wiki with installation and configuration instructions, a Subversion-based source code repository, and a trouble ticketing system. Oh yeah, and there's a mini-blog section on the front page as well. Enjoy and let us know if there's something else you'd like to see.</p>]]>

</content>
</entry>
<entry>
<title>Email Honeyclient Available for Download</title>
<link rel="alternate" type="text/html" href="http://www.synacklabs.net/honeyclient/archives/2005/12/email_honeyclie.html" />
<modified>2006-01-06T17:46:47Z</modified>
<issued>2005-12-13T19:10:34Z</issued>
<id>tag:www.synacklabs.net,2005:/honeyclient//3.216</id>
<created>2005-12-13T19:10:34Z</created>
<summary type="text/plain">Aidan Lynch and Daragh Murray from Dublin City University have written a cool new extension to the honeyclient which they call the email honeyclient. This extension allows you to use Outlook to grab email URLs and send them back to...</summary>
<author>
<name>Kathy</name>

<email>knwang@synacklabs.net</email>
</author>
<dc:subject>Honeyclient Research</dc:subject>
<content type="text/html" mode="escaped" xml:lang="en" xml:base="http://www.synacklabs.net/honeyclient/">
<![CDATA[<p>Aidan Lynch and Daragh Murray from <a href="http://www.dcu.ie/">Dublin City University</a> have written a cool new extension to the honeyclient which they call the email honeyclient. This extension allows you to use Outlook to grab email URLs and send them back to the honeyclient. They also added a feature to allow integrity checks for newly spawned processes. Assuming that we can get approval to do a major software release, we will definitely be including Aidan and Daragh's work in that.</p>

<p>The email honeyclient package can be downloaded <a href="http://www.synacklabs.net/honeyclient/email-honeyclient.zip">here</a>.</p>]]>

</content>
</entry>
<entry>
<title>Recent World of Warcraft Account Compromises</title>
<link rel="alternate" type="text/html" href="http://www.synacklabs.net/honeyclient/archives/2005/10/recent_world_of.html" />
<modified>2005-10-08T19:31:19Z</modified>
<issued>2005-10-08T18:47:18Z</issued>
<id>tag:www.synacklabs.net,2005:/honeyclient//3.215</id>
<created>2005-10-08T18:47:18Z</created>
<summary type="text/plain">Recently, a whole bunch of World of Warcraft (WoW) player accounts were compromised via a keylogger being installed on the users&apos; machines. The infection epidemic was so bad that Blizzard Entertainment set up customer service lines for weekend support. This...</summary>
<author>
<name>Kathy</name>

<email>knwang@synacklabs.net</email>
</author>
<dc:subject>Interesting News</dc:subject>
<content type="text/html" mode="escaped" xml:lang="en" xml:base="http://www.synacklabs.net/honeyclient/">
<![CDATA[<p>Recently, a whole bunch of <a href="http://www.worldofwarcraft.com/">World of Warcraft</a> (WoW) player accounts were compromised via a keylogger being installed on the users' machines. The infection epidemic was so bad that <a href="http://www.blizzard.com/">Blizzard Entertainment</a> set up customer service lines for weekend support. This is in addition to the already existing weekday support hours. I read somewhere that the average wait time for customer support lines is currently about three hours. There are about four million WoW players worldwide. That should give you an idea how bad the situation is.</p>

<p>So, how did this happen? Well, there's a site called <a href="http://www.allakhazam.com/">Allakhazam</a>, which WoW players can reference to see neat statistics such as the average price auction items sell for. Apparently, some bad guy bought an ad on Allakhazam, which when viewed with a vulnerable Internet Explorer browser, installs a keylogger on the IE host. The next time the player logs onto WoW, his/her account login and password are logged, and sent to the attacker. Now, the attacker can log into WoW as that player, and transfer game currency to other accounts, and do stuff like sell that game currency on Ebay for real money. Ouch!</p>

<p>Why am I interested in this? Because 1) I play WoW, and 2) honeyclient technology can help to detect sites like Allakhazam, where in this case, the user didn't even have to click on the ad to get infected. I'm not saying that this is Allakhazam's fault - they just sold an ad to a bad guy. But, if honeyclients were widely deployed, there's a good chance someone would have found this malicious ad before the infection rate become so high. Especially since the ad had already been up and running for several days, according to <a href="http://wow.allakhazam.com/news/sdetail6363.html?story=6363">this Allakhazam post</a>. By the way, Allakhazam has since then removed the malicious ad.</p>

<p>I think the important question is: what's to stop this from happening again? This is clearly a viable business model. These attackers will probably not get caught - how will they even be traced? I could sit here and tell you to download and install <a href="http://www.mozilla.org/products/firefox/">Firefox</a> browser instead, but we all know that Firefox has its vulnerabilities too. So, those of us who are using Firefox are hoping that being part of a minority user group will protect us from being the low-hanging fruit that attackers look for first. But, the sad reality is that if those attackers should choose to, they can certainly target vulnerabilities in other browsers besides IE.</p>

<p>I'm starting to feel like a broken record player saying this, but we need to spend more time thinking about proactive detection technologies. The honeyclient is one of those technologies, and I'm glad to see other people have also thought about that besides me - I'm not the only one, or the first. However, we need to hit a critical mass of people who run honeyclients so that we have a chance of finding malicious sites and spreading the word about them before an infection epidemic like this happens.</p>]]>

</content>
</entry>
<entry>
<title>More Honeyclient News at ToorCon</title>
<link rel="alternate" type="text/html" href="http://www.synacklabs.net/honeyclient/archives/2005/09/more_honeyclien.html" />
<modified>2005-09-22T14:51:04Z</modified>
<issued>2005-09-22T05:23:27Z</issued>
<id>tag:www.synacklabs.net,2005:/honeyclient//3.213</id>
<created>2005-09-22T05:23:27Z</created>
<summary type="text/plain">Dan Hubbard of Websense also gave a talk on honeyclient technology at ToorCon 7. It&apos;s good to see this technology area talked about in the security community. We really need to move away from reactive intrusion detection technologies, given that...</summary>
<author>
<name>Kathy</name>

<email>knwang@synacklabs.net</email>
</author>
<dc:subject>Conferences and Events</dc:subject>
<content type="text/html" mode="escaped" xml:lang="en" xml:base="http://www.synacklabs.net/honeyclient/">
<![CDATA[<p>Dan Hubbard of Websense also gave a talk on honeyclient technology at <a href="http://www.toorcon.org/">ToorCon 7</a>. It's good to see this technology area talked about in the security community. We really need to move away from reactive intrusion detection technologies, given that client-side exploits are on the rise.</p>

<p>Dan's slides can be downloaded <a href="http://www.synacklabs.net/honeyclient/hubbard_toorcon_sep2005.pdf">here</a>.</p>]]>

</content>
</entry>
<entry>
<title>Slides for Lastest Honeyclient Talk Posted</title>
<link rel="alternate" type="text/html" href="http://www.synacklabs.net/honeyclient/archives/2005/09/slides_for_last.html" />
<modified>2005-09-21T05:36:07Z</modified>
<issued>2005-09-21T05:29:58Z</issued>
<id>tag:www.synacklabs.net,2005:/honeyclient//3.212</id>
<created>2005-09-21T05:29:58Z</created>
<summary type="text/plain">I&apos;ve just posted my slides from the latest honeyclient talk at ToorCon 7. The slides can be downloaded here. I had a great time at ToorCon, and will talk more in detail about that on my personal weblog soon....</summary>
<author>
<name>Kathy</name>

<email>knwang@synacklabs.net</email>
</author>
<dc:subject>Conferences and Events</dc:subject>
<content type="text/html" mode="escaped" xml:lang="en" xml:base="http://www.synacklabs.net/honeyclient/">
<![CDATA[<p>I've just posted my slides from the latest honeyclient talk at <a href="http://www.toorcon.org/">ToorCon 7</a>. The slides can be downloaded <a href="http://www.synacklabs.net/honeyclient/Wang-Honeyclient-ToorCon2005.pdf">here</a>.</p>

<p>I had a great time at ToorCon, and will talk more in detail about that on my <a href="http://www.synacklabs.net/kathy/">personal weblog</a> soon.</p>]]>

</content>
</entry>
<entry>
<title>Honeyclient Briefing at ToorCon 2005</title>
<link rel="alternate" type="text/html" href="http://www.synacklabs.net/honeyclient/archives/2005/09/honeyclient_bri.html" />
<modified>2005-09-13T18:52:15Z</modified>
<issued>2005-09-13T18:46:27Z</issued>
<id>tag:www.synacklabs.net,2005:/honeyclient//3.211</id>
<created>2005-09-13T18:46:27Z</created>
<summary type="text/plain">I will be speaking about honeyclients at the upcoming ToorCon 2005. If you are planning on attending ToorCon, or if you&apos;re in San Diego, please stop by and say &apos;hi&apos;. There will be new information presented at ToorCon, and I...</summary>
<author>
<name>Kathy</name>

<email>knwang@synacklabs.net</email>
</author>
<dc:subject>Conferences and Events</dc:subject>
<content type="text/html" mode="escaped" xml:lang="en" xml:base="http://www.synacklabs.net/honeyclient/">
<![CDATA[<p>I will be speaking about honeyclients at the upcoming <a href="http://www.toorcon.org/2005/conference.html?id=56">ToorCon 2005</a>.</p>

<p>If you are planning on attending ToorCon, or if you're in San Diego, please stop by and say 'hi'.</p>

<p>There will be new information presented at ToorCon, and I will put the slides up on the <a href="http://www.honeyclient.org/">honeyclient site</a> afterwards.</p>]]>

</content>
</entry>
<entry>
<title>Microsoft Releases Technical Paper on HoneyMonkeys</title>
<link rel="alternate" type="text/html" href="http://www.synacklabs.net/honeyclient/archives/2005/08/microsoft_relea.html" />
<modified>2005-08-15T02:46:48Z</modified>
<issued>2005-08-06T02:01:05Z</issued>
<id>tag:www.synacklabs.net,2005:/honeyclient//3.210</id>
<created>2005-08-06T02:01:05Z</created>
<summary type="text/plain">Microsoft released a technical paper, entitled Automated Web Patrol with Strider HoneyMonkeys: Finding Web Sites That Exploit Browser Vulnerabilities. The paper can be downloaded here. I read the paper and thought it was very interesting. &apos;HoneyMonkeys&apos; is Microsoft&apos;s term for...</summary>
<author>
<name>Kathy</name>

<email>knwang@synacklabs.net</email>
</author>
<dc:subject>Interesting News</dc:subject>
<content type="text/html" mode="escaped" xml:lang="en" xml:base="http://www.synacklabs.net/honeyclient/">
<![CDATA[<p>Microsoft released a technical paper, entitled <em>Automated Web Patrol with Strider HoneyMonkeys: Finding Web Sites That Exploit Browser Vulnerabilities</em>. The paper can be downloaded <a href="ftp://ftp.research.microsoft.com/pub/tr/TR-2005-72.pdf">here</a>.</p>

<p>I read the paper and thought it was very interesting. 'HoneyMonkeys' is Microsoft's term for what I call 'Honeyclients'. Anyhow, the term doesn't matter much - it's essentially the same concept. Reading Microsoft's paper, it was good to see that the more patched versions of Windows XP were less susceptible to malicious sites. </p>

<p>I suspect that very few attackers are even aware of honeyclient technology at this point. It will be interesting to see what type of 'arms race' is coming down the pipeline as attackers become more aware of honeyclient technology. I'm envisioning more verification by the malicious sites of whether the client is driven in an automated fashion. How about active content malicious sites? It will be challenging to integrate automated mouse clicks within the honeyclient architecture, but is there any other way to detect these types of links?</p>]]>

</content>
</entry>
<entry>
<title>New Version of Honeyclient Now Available for Download</title>
<link rel="alternate" type="text/html" href="http://www.synacklabs.net/honeyclient/archives/2005/07/new_version_of.html" />
<modified>2005-07-06T01:15:27Z</modified>
<issued>2005-07-06T01:01:24Z</issued>
<id>tag:www.synacklabs.net,2005:/honeyclient//3.208</id>
<created>2005-07-06T01:01:24Z</created>
<summary type="text/plain">Since RECON, I&apos;ve been busy with my day job, and with travelling. Finally, over the long weekend, I was able to fix a bug in the previous honeyclient release. Namely, the MSIE browser caching mechanism was giving me some problems....</summary>
<author>
<name>Kathy</name>

<email>knwang@synacklabs.net</email>
</author>
<dc:subject>Downloads</dc:subject>
<content type="text/html" mode="escaped" xml:lang="en" xml:base="http://www.synacklabs.net/honeyclient/">
<![CDATA[<p>Since <a href="http://www.recon.cx">RECON</a>, I've been busy with my day job, and with travelling. Finally, over the long weekend, I was able to fix a bug in the previous honeyclient release. </p>

<p>Namely, the MSIE browser caching mechanism was giving me some problems. Even though I specified in the browser options that I never wanted to cache pages, and gave it the minimum memory space (1MB) for storing caches, it was still storing pages. This was indirectly causing error messages like 'Cannot open intfile: no such file or directory.' It also means that things were not going to proxy.pl, which was really the cause of the underlying intfile problem.</p>

<p>Thanks to <a href="http://www.labgeek.net/jd/index.html">JD Durick</a> for pointing out the bug while testing, and thanks also to <a href="http://cerberus.sourcefire.com/~jeff/jnathan.html">Jeff Nathan</a> for taking the time to show me MSIE caching mechanics.</p>]]>

</content>
</entry>
<entry>
<title>Honeyclient Talk Slides Available for Download</title>
<link rel="alternate" type="text/html" href="http://www.synacklabs.net/honeyclient/archives/2005/06/honeyclient_tal_1.html" />
<modified>2005-06-21T04:45:56Z</modified>
<issued>2005-06-21T02:32:48Z</issued>
<id>tag:www.synacklabs.net,2005:/honeyclient//3.207</id>
<created>2005-06-21T02:32:48Z</created>
<summary type="text/plain">I just posted the slides that were used during yesterday&apos;s honeyclient talks at RECON. They are now downloadable off the main page. I am still in Montreal today, and will be returning home tomorrow. Today, I enjoyed sightseeing around the...</summary>
<author>
<name>Kathy</name>

<email>knwang@synacklabs.net</email>
</author>
<dc:subject>Conferences and Events</dc:subject>
<content type="text/html" mode="escaped" xml:lang="en" xml:base="http://www.synacklabs.net/honeyclient/">
<![CDATA[<p>I just posted the slides that were used during yesterday's honeyclient talks at <a href="http://www.recon.cx">RECON</a>. They are now downloadable off the main page.</p>

<p>I am still in Montreal today, and will be returning home tomorrow. Today, I enjoyed sightseeing around the wonderful city of Montreal. The food here is pretty phenomenal.</p>]]>

</content>
</entry>
<entry>
<title>Honeyclient Talk Today</title>
<link rel="alternate" type="text/html" href="http://www.synacklabs.net/honeyclient/archives/2005/06/honeyclient_tal.html" />
<modified>2005-06-19T00:18:08Z</modified>
<issued>2005-06-19T00:06:39Z</issued>
<id>tag:www.synacklabs.net,2005:/honeyclient//3.206</id>
<created>2005-06-19T00:06:39Z</created>
<summary type="text/plain">I gave a talk today at RECON on honeyclients. Also, the world&apos;s first open-sourced honeyclient has just been released during my talk. Download the latest tarball from the download section on the main page. Talking to the people at RECON...</summary>
<author>
<name>Kathy</name>

<email>knwang@synacklabs.net</email>
</author>
<dc:subject>Conferences and Events</dc:subject>
<content type="text/html" mode="escaped" xml:lang="en" xml:base="http://www.synacklabs.net/honeyclient/">
<![CDATA[<p>I gave a <a href="http://www.recon.cx/en/s/kwang.html">talk</a> today at <a href="http://www.recon.cx">RECON</a> on honeyclients. Also, the world's first open-sourced honeyclient has just been released during my talk. Download the latest tarball from the download section on the main page.</p>

<p>Talking to the people at RECON was really cool. Everyone seemed to have something to say about honeyclients, and many people had good suggestions as to improving the current prototype. I also got a lot of people interested enough to do additional testing - this is the best reason of all to present at conferences.</p>

<p>Please join the mailing list and contribute! The slides I used at the RECON talk will be available for download within the next few days.</p>]]>

</content>
</entry>
<entry>
<title>Cerberus-like Attack for Botnet Formation</title>
<link rel="alternate" type="text/html" href="http://www.synacklabs.net/honeyclient/archives/2005/06/cerberuslike_at.html" />
<modified>2005-06-14T19:34:57Z</modified>
<issued>2005-06-12T19:00:55Z</issued>
<id>tag:www.synacklabs.net,2005:/honeyclient//3.205</id>
<created>2005-06-12T19:00:55Z</created>
<summary type="text/plain">I thought that this article from eWeek highlighted only the beginning of what we will start to see with increasing frequency - multi-staged attacks. I just called this attack &apos;Cerberus-like&apos; because it is a three step attack. Basically, the first...</summary>
<author>
<name>Kathy</name>

<email>knwang@synacklabs.net</email>
</author>
<dc:subject>Interesting News</dc:subject>
<content type="text/html" mode="escaped" xml:lang="en" xml:base="http://www.synacklabs.net/honeyclient/">
<![CDATA[<p>I thought that this article from eWeek highlighted only the beginning of what we will start to see with increasing frequency - multi-staged attacks. I just called this attack 'Cerberus-like' because it is a three step attack.</p>

<p>Basically, the first trojan (<a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=43216">Win32.Glieder.AK</a>) downloads malware from a hard-coded list of URLs, and disables various security measures such as the host firewall. The second trojan (<a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=43220">Win32.Fantibag.A</a>) ensures that anti-virus and Windows Update is disabled. The third trojan (<a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?ID=43232">Win32.Mitglieder.CT</a>) actually puts the host under control of the attacker, who will presumably build large botnets with these hosts.</p>

<p>Although this is a complicated attack, it is clever. For one thing, it will make identification of the source of attacks more difficult. Also, according to <a href="http://securityresponse.symantec.com/avcenter/venc/data/trojan.tooso.b.html">Symantec's information</a> on the first trojan in the three-staged attack, this trojan may be emailed out as part of a Beagle worm variant, so is this really a four-staged attack?</p>

<p>Whether honeyclients will be useful for studying this attack will depend on whether the first trojan is exploiting a vulnerability in the Windows server, or if it's exploiting a vulnerability in a client, such as IE. For the first case, honeypots would probably be more useful, for the latter, honeyclients.</p>]]>

</content>
</entry>
<entry>
<title>A New Business Model?</title>
<link rel="alternate" type="text/html" href="http://www.synacklabs.net/honeyclient/archives/2005/05/a_new_business.html" />
<modified>2005-06-14T18:57:58Z</modified>
<issued>2005-05-30T21:23:55Z</issued>
<id>tag:www.synacklabs.net,2005:/honeyclient//3.204</id>
<created>2005-05-30T21:23:55Z</created>
<summary type="text/plain">How could it be that a company in Russia is building a business around infecting other people&apos;s machines? &apos;No way!&apos;, you say. Well, this article from Information Week has the details. This Russian company (which I will not link directly...</summary>
<author>
<name>Kathy</name>

<email>knwang@synacklabs.net</email>
</author>
<dc:subject>Interesting News</dc:subject>
<content type="text/html" mode="escaped" xml:lang="en" xml:base="http://www.synacklabs.net/honeyclient/">
<![CDATA[<p>How could it be that a company in Russia is building a business around infecting other people's machines? 'No way!', you say. Well, this <a href="http://www.informationweek.com/showArticle.jhtml?articleID=163701736">article</a> from Information Week has the details.</p>

<p>This Russian company (which I will not link directly to) supplies one-line exploit code to other sites, who then get paid $0.06 per machine that is infected with that exploit code, which installs at least spyware and adware.</p>

<p>Interesting insight: I was testing my honeyclient implementation, and decided to access this Russian site to see if I could somehow download that exploit code to research. It turns out that the information they wanted from me is quite extensive. I mean, there's no way I'm giving them my address, phone number, etc., just so they can contact me to 'talk business'. So, in case you were wondering, they don't make it easy to obtain that exploit code.</p>

<p>It would be interesting to see with honeyclients if all the sites that work with this Russian company can be found via the way they would uniquely try and exploit IE and Windows 2K/XP. At least, that's what I'm assuming the exploit code targets.</p>]]>

</content>
</entry>
<entry>
<title>Microsoft&apos;s Honeyclient Project</title>
<link rel="alternate" type="text/html" href="http://www.synacklabs.net/honeyclient/archives/2005/05/microsofts_hone.html" />
<modified>2005-06-14T16:28:37Z</modified>
<issued>2005-05-19T01:21:27Z</issued>
<id>tag:www.synacklabs.net,2005:/honeyclient//3.202</id>
<created>2005-05-19T01:21:27Z</created>
<summary type="text/plain">According to this Slashdot post, Microsoft has their own version of a honeyclient, which they call &apos;honeymonkeys&apos;. I have to say, that&apos;s a cute moniker. More importantly, though, this goes to show that it&apos;s becoming increasingly important to actively seek...</summary>
<author>
<name>Kathy</name>

<email>knwang@synacklabs.net</email>
</author>
<dc:subject>Interesting News</dc:subject>
<content type="text/html" mode="escaped" xml:lang="en" xml:base="http://www.synacklabs.net/honeyclient/">
<![CDATA[<p>According to this Slashdot <a href="http://it.slashdot.org/article.pl?sid=05/05/18/2240222&tid=172&tid=109">post</a>, Microsoft has their own version of a honeyclient, which they call 'honeymonkeys'. I have to say, that's a cute moniker.</p>

<p>More importantly, though, this goes to show that it's becoming increasingly important to actively seek out the bad HTTP servers proactively. This will help to develop a better sense of situational awareness, which is where I think the future of information security is headed. I think folks are finally getting sick of constant reactive problem-solving, and this includes Microsoft.</p>]]>

</content>
</entry>
<entry>
<title>Oops, Did You Mean To Type &apos;google&apos;?</title>
<link rel="alternate" type="text/html" href="http://www.synacklabs.net/honeyclient/archives/2005/04/oops_did_you_me.html" />
<modified>2005-06-14T16:41:33Z</modified>
<issued>2005-04-27T23:29:02Z</issued>
<id>tag:www.synacklabs.net,2005:/honeyclient//3.203</id>
<created>2005-04-27T23:29:02Z</created>
<summary type="text/plain">Next time you try and access Google, be careful how you type. This article in eWeek points out that typing &apos;googkle&apos; instead of &apos;google&apos; lands you at a malicious site that then attempts to install beasties such as backdoors and...</summary>
<author>
<name>Kathy</name>

<email>knwang@synacklabs.net</email>
</author>
<dc:subject>Interesting News</dc:subject>
<content type="text/html" mode="escaped" xml:lang="en" xml:base="http://www.synacklabs.net/honeyclient/">
<![CDATA[<p>Next time you try and access Google, be careful how you type. This <a href="http://www.eweek.com/article2/0,1759,1790348,00.asp">article in eWeek</a> points out that typing 'googkle' instead of 'google' lands you at a malicious site that then attempts to install beasties such as backdoors and trojan droppers on your host.</p>

<p>I say the attackers/typosquatters are extremely enterprising, and evil to do this. I wonder what their motives are? Surely, there's money being made on their end. It used to be that if you mistyped certain domains, you'd just get porn, but this is definitely another step up. And, IMHO, another reason why we need honeyclients to help with finding sites like this, and warning the public, before they get a chance to do much damage.</p>]]>

</content>
</entry>
<entry>
<title>Why We Need Honeyclients</title>
<link rel="alternate" type="text/html" href="http://www.synacklabs.net/honeyclient/archives/2005/04/why_we_need_hon.html" />
<modified>2005-06-14T16:20:55Z</modified>
<issued>2005-04-21T03:24:19Z</issued>
<id>tag:www.synacklabs.net,2005:/honeyclient//3.195</id>
<created>2005-04-21T03:24:19Z</created>
<summary type="text/plain">This article talks about how attackers are now using fake weblogs to entice users to click on certain links. Once those links are accessed, malware such as keyloggers and trojans are uploaded to the victim host from the malicious server....</summary>
<author>
<name>Kathy</name>

<email>knwang@synacklabs.net</email>
</author>
<dc:subject>Interesting News</dc:subject>
<content type="text/html" mode="escaped" xml:lang="en" xml:base="http://www.synacklabs.net/honeyclient/">
<![CDATA[<p>This <a href="http://news.bbc.co.uk/2/hi/technology/4441333.stm">article</a> talks about how attackers are now using fake weblogs to entice users to click on certain links. Once those links are accessed, malware such as keyloggers and trojans are uploaded to the victim host from the malicious server. In this article, users are social-engineered to click on the link which starts the malware upload to their machines.  However, the attack could certainly be done in such a way that users only need to access the site and become infected, all without clicking on a single URL on that site.</p>

<p>This server to client attack cannot be detected using traditional honeypots. Traditional honeypots are passive devices which do not actively hit sites for data. Honeyclients, however, can be deployed to detect and warn of such malicious servers, because honeyclients are designed to actively  access those servers. If we hope to better detect new server to client 0-day attacks, we need to actively look for those servers.</p>]]>

</content>
</entry>

</feed>