<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Honeypots (honeypots) Mailing List</title>
<link>http://seclists.org/#honeypots</link>
<atom:link href="http://seclists.org/rss/honeypots.rss" rel="self" type="application/rss+xml" />
<description>Discussions about tracking attackers by setting up decoy honeypots or entire honeynet networks.</description>
<language>en-us</language><ttl>60</ttl>
<item><title>Workshop on the Analysis of System Logs (WASL) 2009</title><description>Posted by Greg Bronevetsky on Jun 16&lt;p&gt;


&lt;p&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Workshop on the Analysis of System Logs (WASL) 2009
&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;http://www.systemloganalysis.com Call for Papers
&lt;br /&gt;
&lt;p&gt;...</description>
<link>http://seclists.org/honeypots/2009/q2/0018.html</link><guid isPermaLink="true">http://seclists.org/honeypots/2009/q2/0018.html</guid>
<pubDate>Tue, 16 Jun 2009 08:42:33 -0700</pubDate></item>
<item><title>Call for Participation - DIMVA 2009</title><description>Posted by Sebastian Schmerl on May 26&lt;p&gt;


&lt;p&gt;
&amp;nbsp;&amp;nbsp;(We apologize if you receive multiple copies of this message.)
&lt;br /&gt;
----------------------------------------------------------------------
&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;C A L L F O R P A R T I C I P A T I O N
&lt;br /&gt;...</description>
<link>http://seclists.org/honeypots/2009/q2/0017.html</link><guid isPermaLink="true">http://seclists.org/honeypots/2009/q2/0017.html</guid>
<pubDate>Tue, 26 May 2009 12:59:20 +0200</pubDate></item>
<item><title>SETOP 2009 - Call for Papers, Deadline June 1st</title><description>Posted by Yves Roudier on May 26&lt;p&gt;


&lt;p&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;[Apologies for multiple copies of this announcement]
&lt;br /&gt;
&lt;p&gt;&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;CALL FOR PAPERS
&lt;br /&gt;
&lt;p&gt;...</description>
<link>http://seclists.org/honeypots/2009/q2/0016.html</link><guid isPermaLink="true">http://seclists.org/honeypots/2009/q2/0016.html</guid>
<pubDate>Tue, 26 May 2009 12:07:10 +0200</pubDate></item>
<item><title>HoneyD Data Visualization Scripts</title><description>Posted by Joshua Gimer on May 7&lt;p&gt;


&lt;p&gt;
I have been doing a little work on updating my HoneyD data
&lt;br /&gt;
visualization scripts and the web interface to be a little bit more
&lt;br /&gt;
appealing.
&lt;br /&gt;
&lt;p&gt;More information at my blog:
&lt;br /&gt;
&lt;p&gt;http://itsecops.blogspot.com/
&lt;br /&gt;
&lt;p&gt;</description>
<link>http://seclists.org/honeypots/2009/q2/0015.html</link><guid isPermaLink="true">http://seclists.org/honeypots/2009/q2/0015.html</guid>
<pubDate>Thu, 7 May 2009 17:11:10 -0600</pubDate></item>
<item><title>EUSecWest 2009 (May2728) London Agenda and PacSec 2009 (Nov 45) Tokyo CFP deadline: June 1 2009</title><description>Posted by Dragos Ruiu on May 6&lt;p&gt;


&lt;p&gt;
EUSecWest 2009 Speakers
&lt;br /&gt;
&lt;p&gt;Efficient UAK Recovery attacks against DECT 
&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;- Ralf-Philipp Weinmann,  University of Luxembourg
&lt;br /&gt;
A year in the life of an Adobe Flash security researcher 
&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;- Peleus  Uhley,...</description>
<link>http://seclists.org/honeypots/2009/q2/0014.html</link><guid isPermaLink="true">http://seclists.org/honeypots/2009/q2/0014.html</guid>
<pubDate>Wed, 6 May 2009 15:24:04 -0700</pubDate></item>
<item><title>Call for Papers Hack.lu 2009</title><description>Posted by hack.lu 2009 info on Apr 30&lt;p&gt;


&lt;p&gt;
Call for Papers Hack.lu 2009
&lt;br /&gt;
============================
&lt;br /&gt;
&lt;p&gt;The purpose of the hack.lu convention is to give an open and free
&lt;br /&gt;
playground where people can discuss the implication of new technologies
&lt;br /&gt;
in society. hack.lu is a balanced mix convention where technical and
&lt;br /&gt;
non-technical people can...</description>
<link>http://seclists.org/honeypots/2009/q2/0013.html</link><guid isPermaLink="true">http://seclists.org/honeypots/2009/q2/0013.html</guid>
<pubDate>Thu, 30 Apr 2009 14:42:46 +0200</pubDate></item>
<item><title>RE: Mail Honeypot Thesis</title><description>Posted by Ian Bradshaw on Apr 22&lt;p&gt;


&lt;p&gt;
I would have thought that botnets are a much greater problem than an open
&lt;br /&gt;
relay, which is just a couple of pcs / servers and can easily be knocked
&lt;br /&gt;
offline by an ISP etc.
&lt;br /&gt;
&lt;p&gt;Also, be careful where you run your relay ... whatever ISP your using will
&lt;br /&gt;
be none too happy at being blacklisted;...</description>
<link>http://seclists.org/honeypots/2009/q2/0012.html</link><guid isPermaLink="true">http://seclists.org/honeypots/2009/q2/0012.html</guid>
<pubDate>Wed, 22 Apr 2009 22:18:15 +0100</pubDate></item>
<item><title>RE: Mail Honeypot Thesis</title><description>Posted by Jesper Jurcenoks on Apr 22&lt;p&gt;


&lt;p&gt;
Hi dotcompex.
&lt;br /&gt;
&lt;p&gt;Make sure you don&#39;t actually relay the emails!
&lt;br /&gt;
Only emulate an open relay, and then accept the emails for relay, without actually relaying them.
&lt;br /&gt;
&lt;p&gt;If you relay then you become part of the problem, and not part of the solution.
&lt;br /&gt;
&lt;p&gt;There should be no need to use TCPdump to capture the...</description>
<link>http://seclists.org/honeypots/2009/q2/0011.html</link><guid isPermaLink="true">http://seclists.org/honeypots/2009/q2/0011.html</guid>
<pubDate>Wed, 22 Apr 2009 14:15:14 -0700</pubDate></item>
<item><title>Mail Honeypot Thesis</title><description>Posted by dotcompex on Apr 22&lt;p&gt;


&lt;p&gt;
I&#39;m doing mail honeypot project for my thesis.  Having a little bit problem
&lt;br /&gt;
in writing good report.  I hope u all can comment it so I can edit before
&lt;br /&gt;
submit it.  For the start, I attach my abstract.
&lt;br /&gt;
&lt;p&gt;Electronic mail or in short can be called email is an important
&lt;br /&gt;
communication method since...</description>
<link>http://seclists.org/honeypots/2009/q2/0010.html</link><guid isPermaLink="true">http://seclists.org/honeypots/2009/q2/0010.html</guid>
<pubDate>Wed, 22 Apr 2009 06:54:55 -0700 (PDT)</pubDate></item>
<item><title>Re: nepenthes for multiple ip addresses</title><description>Posted by Viktor on Apr 19&lt;p&gt;


&lt;p&gt;
Thanks for all the answers, i have profited a lot from them! Let me
&lt;br /&gt;
answer for each reply in one mail.
&lt;br /&gt;
&lt;p&gt;Kashyap Timmaraju wrote:
&lt;br /&gt;
&amp;gt; The reason you need arpd is because you have to bind the unused IP
&lt;br /&gt;
&amp;gt; addresses to a MAC address in this case it will be your MAC
&lt;br /&gt;
&amp;gt; address(how else can u...</description>
<link>http://seclists.org/honeypots/2009/q2/0009.html</link><guid isPermaLink="true">http://seclists.org/honeypots/2009/q2/0009.html</guid>
<pubDate>Sun, 19 Apr 2009 20:56:45 +0200</pubDate></item>
<item><title>Re: nepenthes for multiple ip addresses</title><description>Posted by Gergely RÃvay on Apr 19&lt;p&gt;


&lt;p&gt;
Hi,
&lt;br /&gt;
&lt;p&gt;If there is no address translation in the routing process then you
&lt;br /&gt;
should have alias interfaces for those IPs which you want to listen
&lt;br /&gt;
on.
&lt;br /&gt;
&lt;p&gt;For instance if the 192.168.1.0/24 network is redirected to your
&lt;br /&gt;
computer then you should use a command like this:
&lt;br /&gt;
&lt;p&gt;$ for i in `seq 2 254`; do sudo...</description>
<link>http://seclists.org/honeypots/2009/q2/0008.html</link><guid isPermaLink="true">http://seclists.org/honeypots/2009/q2/0008.html</guid>
<pubDate>Sun, 19 Apr 2009 17:11:38 +0200</pubDate></item>
<item><title>Re: nepenthes for multiple ip addresses</title><description>Posted by Sushant Sinha on Apr 18&lt;p&gt;


&lt;p&gt;
Did you try arpd to get packets to your box?
&lt;br /&gt;
&lt;p&gt;-sushant.
&lt;br /&gt;
&lt;p&gt;On Sat, 2009-04-18 at 17:17 +0200, Viktor wrote:
&lt;br /&gt;
&amp;gt; Hello!
&lt;br /&gt;
&amp;gt; 
&lt;br /&gt;
&amp;gt; I&#39;m running nepenthes on a debian OS at an universiry network with a fix IP. I managed to get a high number of unused IP addresses from the university network...</description>
<link>http://seclists.org/honeypots/2009/q2/0007.html</link><guid isPermaLink="true">http://seclists.org/honeypots/2009/q2/0007.html</guid>
<pubDate>Sat, 18 Apr 2009 11:37:29 -0400</pubDate></item>
<item><title>nepenthes for multiple ip addresses</title><description>Posted by Viktor on Apr 18&lt;p&gt;


&lt;p&gt;
Hello!
&lt;br /&gt;
&lt;p&gt;I&#39;m running nepenthes on a debian OS at an universiry network with a fix IP. I managed to get a high number of unused IP addresses from the university network administrator, all traffic from these are routed to my computer. Now i&#39;m having 200 packet/s income rate, but nepenthes only looks...</description>
<link>http://seclists.org/honeypots/2009/q2/0006.html</link><guid isPermaLink="true">http://seclists.org/honeypots/2009/q2/0006.html</guid>
<pubDate>Sat, 18 Apr 2009 17:17:32 +0200</pubDate></item>
<item><title>HITBSecConf2009 - Malaysia: Call for Papers</title><description>Posted by S. Praburaajan on Apr 15&lt;p&gt;


&lt;p&gt;
The Call for Papers for HITB Security Conference 2009 Malaysia is now open!
&lt;br /&gt;
&lt;p&gt;Talks that are more technical or that discuss new and never before seen
&lt;br /&gt;
attack methods are of more interest than a subject that has been covered
&lt;br /&gt;
several times before. Summaries not exceeding 1250 words should be
&lt;br /&gt;...</description>
<link>http://seclists.org/honeypots/2009/q2/0005.html</link><guid isPermaLink="true">http://seclists.org/honeypots/2009/q2/0005.html</guid>
<pubDate>Wed, 15 Apr 2009 12:12:17 +0800</pubDate></item>
<item><title>In need of LOTS of quotsanitized Sebek Keystrokes</title><description>Posted by Blarnum Seamus on Apr 11&lt;p&gt;


&lt;p&gt;
Hey All,
&lt;br /&gt;
&lt;p&gt;I am trying to write a college paper on various hacker methods and I would like to know if anyone has any sanitized sebek keystroke logs I could use in my paper. All I need is the actual command inputs and any associated process information. Everything else is not required (or better...</description>
<link>http://seclists.org/honeypots/2009/q2/0004.html</link><guid isPermaLink="true">http://seclists.org/honeypots/2009/q2/0004.html</guid>
<pubDate>Sat, 11 Apr 2009 11:47:08 -0700 (PDT)</pubDate></item>
</channel></rss>