<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Dionaea &#8211; Low interaction honeypot</title>
	<atom:link href="http://www.ethicalhack3r.co.uk/security/dionaea-low-interaction-honeypot/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ethicalhack3r.co.uk/security/dionaea-low-interaction-honeypot/</link>
	<description></description>
	<lastBuildDate>Fri, 03 Feb 2012 00:36:13 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
	<item>
		<title>By: ash</title>
		<link>http://www.ethicalhack3r.co.uk/security/dionaea-low-interaction-honeypot/comment-page-1/#comment-239934</link>
		<dc:creator>ash</dc:creator>
		<pubDate>Sun, 04 Dec 2011 20:01:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.ethicalhack3r.co.uk/?p=506#comment-239934</guid>
		<description>i want explanation of this file.can any one tell me?

linux-sqos:/opt/nepenthes/var/log # cat nepenthes.log

[18032007 02:26:03 info module] 76 4
[18032007 02:26:03 info module] SMB Session Request 76
H CKFDENECFDEFFCFGEFFCCACACACACACA
[18032007 02:26:03 warn module] Unknown NETDDE exploit 76 bytes State 1
[18032007 02:26:03 module] Stored Hexdump var/hexdumps/850745ec6a9f3cc3d7ce4bdd7294e468.bin (0x0809fa80 , 0x0000004c).
[18032007 02:26:03 warn module] Unknown SMBName exploit 0 bytes State 1
[18032007 02:26:03 info handler dia] Unknown DCOM request, dropping
[18032007 02:26:11 crit sc handler] MATCH linkxor::link matchCount 5 map_items 5
[18032007 02:26:11 info sc handler] i = 1 map_items 5 , map = size
[18032007 02:26:11 info sc handler] i = 2 map_items 5 , map = size
[18032007 02:26:11 info sc handler] i = 3 map_items 5 , map = key
[18032007 02:26:11 info sc handler] i = 4 map_items 5 , map = post
[18032007 02:26:11 info sc handler] Found linkbot XOR decoder, key 0x1b, payload is 0x00b2 bytes long.
[18032007 02:26:11 info sc handler] connectbackfiletransfer::linktransfer -&gt; 64.182.172.15:56330
[18032007 02:26:11 info sc handler] connectbackfiletransfer::linktransfer -&gt; 64.182.172.15:56330, key 0xaeed1ff8.
[18032007 02:26:11 info down mgr] Handler link download handler will download link://64.182.172.15:56330/ru0f+A==
[18032007 02:26:13 info handler dia] Download via linkbot filetransferr done! ( download is 114176 bytes)
[18032007 02:26:13 info mgr submit] File b6c9254853a642e90756cfb04efd67ea has type PE executable for MS Windows (GUI) Intel 80386 32-bit
[18032007 02:26:13 warn dia] Unknown ASN1_SMB Shellcode (Buffer 172 bytes) (State 0)
[18032007 02:26:13 dia] Stored Hexdump var/hexdumps/16e9e789e405a1bc1e69a3a7f302416b.bin (0x080a1a40 , 0x000000ac).
[18032007 02:26:13 warn module] Unknown PNP Shellcode (Buffer 172 bytes) (State 0)
[18032007 02:26:13 module] Stored Hexdump var/hexdumps/16e9e789e405a1bc1e69a3a7f302416b.bin (0x080a1638 , 0x000000ac).
[18032007 02:26:13 warn module] Unknown LSASS Shellcode (Buffer 172 bytes) (State 0)
[18032007 02:26:13 module] Stored Hexdump var/hexdumps/16e9e789e405a1bc1e69a3a7f302416b.bin (0x080a08f0 , 0x000000ac).
[18032007 02:26:13 warn handler dia] Unknown DCOM Shellcode (Buffer 172 bytes) (State 0)
[18032007 02:26:13 handler dia] Stored Hexdump var/hexdumps/16e9e789e405a1bc1e69a3a7f302416b.bin (0x0809fa80 , 0x000000ac).

linux-sqos:/opt/nepenthes/var/binaries # ls -l b6c9254853a642e90756cfb04efd67ea
-rw-r--r-- 1 root root 114176 Mar 18 02:26 b6c9254853a642e90756cfb04efd67ea
linux-sqos:/opt/nepenthes/var/binaries # file b6c9254853a642e90756cfb04efd67ea
b6c9254853a642e90756cfb04efd67ea: PE executable for MS Windows (GUI) Intel 80386 32-bit
linux-sqos:/opt/nepenthes/var/binaries # cd /opt/nepenthes/var/hexdumps
linux-sqos:/opt/nepenthes/var/hexdumps # ls -l 16e9e789e405a1bc1e69a3a7f302416b.bin
-rw-r--r-- 1 root root 172 Mar 18 02:26 16e9e789e405a1bc1e69a3a7f302416b.bin
linux-sqos:/opt/nepenthes/var/hexdumps # file 16e9e789e405a1bc1e69a3a7f302416b.bin
16e9e789e405a1bc1e69a3a7f302416b.bin: data
linux-sqos:/opt/nepenthes/var/hexdumps # xxd -g 1 -u 16e9e789e405a1bc1e69a3a7f302416b.bin
0000000: 00 00 00 A8 FF 53 4D 42 72 00 00 00 00 08 01 40 .....SMBr......@
0000010: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 2C 03 ..............,.
0000020: 02 08 10 3E 00 85 00 02 50 43 20 4E 45 54 57 4F ...&gt;....PC NETWO
0000030: 52 4B 20 50 52 4F 47 52 41 4D 20 31 2E 30 00 02 RK PROGRAM 1.0..
0000040: 4D 49 43 52 4F 53 4F 46 54 20 4E 45 54 57 4F 52 MICROSOFT NETWOR
0000050: 4B 53 20 31 2E 30 33 00 02 4D 49 43 52 4F 53 4F KS 1.03..MICROSO
0000060: 46 54 20 4E 45 54 57 4F 52 4B 53 20 33 2E 30 00 FT NETWORKS 3.0.
0000070: 02 4C 41 4E 4D 41 4E 31 2E 30 00 02 4C 4D 31 2E .LANMAN1.0..LM1.
0000080: 32 58 30 30 32 00 02 4C 41 4E 4D 41 4E 32 2E 31 2X002..LANMAN2.1
0000090: 00 02 4E 54 20 4C 41 4E 4D 41 4E 20 31 2E 30 00 ..NT LANMAN 1.0.
00000a0: 02 4E 54 20 4C 4D 20 30 2E 31 32 00 .NT LM 0.12.
linux-sqos:/opt/nepenthes/var/hexdumps #</description>
		<content:encoded><![CDATA[<p>i want explanation of this file.can any one tell me?</p>
<p>linux-sqos:/opt/nepenthes/var/log # cat nepenthes.log</p>
<p>[18032007 02:26:03 info module] 76 4<br />
[18032007 02:26:03 info module] SMB Session Request 76<br />
H CKFDENECFDEFFCFGEFFCCACACACACACA<br />
[18032007 02:26:03 warn module] Unknown NETDDE exploit 76 bytes State 1<br />
[18032007 02:26:03 module] Stored Hexdump var/hexdumps/850745ec6a9f3cc3d7ce4bdd7294e468.bin (0x0809fa80 , 0x0000004c).<br />
[18032007 02:26:03 warn module] Unknown SMBName exploit 0 bytes State 1<br />
[18032007 02:26:03 info handler dia] Unknown DCOM request, dropping<br />
[18032007 02:26:11 crit sc handler] MATCH linkxor::link matchCount 5 map_items 5<br />
[18032007 02:26:11 info sc handler] i = 1 map_items 5 , map = size<br />
[18032007 02:26:11 info sc handler] i = 2 map_items 5 , map = size<br />
[18032007 02:26:11 info sc handler] i = 3 map_items 5 , map = key<br />
[18032007 02:26:11 info sc handler] i = 4 map_items 5 , map = post<br />
[18032007 02:26:11 info sc handler] Found linkbot XOR decoder, key 0x1b, payload is 0x00b2 bytes long.<br />
[18032007 02:26:11 info sc handler] connectbackfiletransfer::linktransfer -&gt; 64.182.172.15:56330<br />
[18032007 02:26:11 info sc handler] connectbackfiletransfer::linktransfer -&gt; 64.182.172.15:56330, key 0xaeed1ff8.<br />
[18032007 02:26:11 info down mgr] Handler link download handler will download link://64.182.172.15:56330/ru0f+A==<br />
[18032007 02:26:13 info handler dia] Download via linkbot filetransferr done! ( download is 114176 bytes)<br />
[18032007 02:26:13 info mgr submit] File b6c9254853a642e90756cfb04efd67ea has type PE executable for MS Windows (GUI) Intel 80386 32-bit<br />
[18032007 02:26:13 warn dia] Unknown ASN1_SMB Shellcode (Buffer 172 bytes) (State 0)<br />
[18032007 02:26:13 dia] Stored Hexdump var/hexdumps/16e9e789e405a1bc1e69a3a7f302416b.bin (0x080a1a40 , 0x000000ac).<br />
[18032007 02:26:13 warn module] Unknown PNP Shellcode (Buffer 172 bytes) (State 0)<br />
[18032007 02:26:13 module] Stored Hexdump var/hexdumps/16e9e789e405a1bc1e69a3a7f302416b.bin (0x080a1638 , 0x000000ac).<br />
[18032007 02:26:13 warn module] Unknown LSASS Shellcode (Buffer 172 bytes) (State 0)<br />
[18032007 02:26:13 module] Stored Hexdump var/hexdumps/16e9e789e405a1bc1e69a3a7f302416b.bin (0x080a08f0 , 0x000000ac).<br />
[18032007 02:26:13 warn handler dia] Unknown DCOM Shellcode (Buffer 172 bytes) (State 0)<br />
[18032007 02:26:13 handler dia] Stored Hexdump var/hexdumps/16e9e789e405a1bc1e69a3a7f302416b.bin (0x0809fa80 , 0x000000ac).</p>
<p>linux-sqos:/opt/nepenthes/var/binaries # ls -l b6c9254853a642e90756cfb04efd67ea<br />
-rw-r&#8211;r&#8211; 1 root root 114176 Mar 18 02:26 b6c9254853a642e90756cfb04efd67ea<br />
linux-sqos:/opt/nepenthes/var/binaries # file b6c9254853a642e90756cfb04efd67ea<br />
b6c9254853a642e90756cfb04efd67ea: PE executable for MS Windows (GUI) Intel 80386 32-bit<br />
linux-sqos:/opt/nepenthes/var/binaries # cd /opt/nepenthes/var/hexdumps<br />
linux-sqos:/opt/nepenthes/var/hexdumps # ls -l 16e9e789e405a1bc1e69a3a7f302416b.bin<br />
-rw-r&#8211;r&#8211; 1 root root 172 Mar 18 02:26 16e9e789e405a1bc1e69a3a7f302416b.bin<br />
linux-sqos:/opt/nepenthes/var/hexdumps # file 16e9e789e405a1bc1e69a3a7f302416b.bin<br />
16e9e789e405a1bc1e69a3a7f302416b.bin: data<br />
linux-sqos:/opt/nepenthes/var/hexdumps # xxd -g 1 -u 16e9e789e405a1bc1e69a3a7f302416b.bin<br />
0000000: 00 00 00 A8 FF 53 4D 42 72 00 00 00 00 08 01 40 &#8230;..SMBr&#8230;&#8230;@<br />
0000010: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 2C 03 &#8230;&#8230;&#8230;&#8230;..,.<br />
0000020: 02 08 10 3E 00 85 00 02 50 43 20 4E 45 54 57 4F &#8230;&gt;&#8230;.PC NETWO<br />
0000030: 52 4B 20 50 52 4F 47 52 41 4D 20 31 2E 30 00 02 RK PROGRAM 1.0..<br />
0000040: 4D 49 43 52 4F 53 4F 46 54 20 4E 45 54 57 4F 52 MICROSOFT NETWOR<br />
0000050: 4B 53 20 31 2E 30 33 00 02 4D 49 43 52 4F 53 4F KS 1.03..MICROSO<br />
0000060: 46 54 20 4E 45 54 57 4F 52 4B 53 20 33 2E 30 00 FT NETWORKS 3.0.<br />
0000070: 02 4C 41 4E 4D 41 4E 31 2E 30 00 02 4C 4D 31 2E .LANMAN1.0..LM1.<br />
0000080: 32 58 30 30 32 00 02 4C 41 4E 4D 41 4E 32 2E 31 2X002..LANMAN2.1<br />
0000090: 00 02 4E 54 20 4C 41 4E 4D 41 4E 20 31 2E 30 00 ..NT LANMAN 1.0.<br />
00000a0: 02 4E 54 20 4C 4D 20 30 2E 31 32 00 .NT LM 0.12.<br />
linux-sqos:/opt/nepenthes/var/hexdumps #</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ash</title>
		<link>http://www.ethicalhack3r.co.uk/security/dionaea-low-interaction-honeypot/comment-page-1/#comment-239931</link>
		<dc:creator>ash</dc:creator>
		<pubDate>Sun, 04 Dec 2011 19:59:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.ethicalhack3r.co.uk/?p=506#comment-239931</guid>
		<description>how to read log file of dionaea?</description>
		<content:encoded><![CDATA[<p>how to read log file of dionaea?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Fhrobro</title>
		<link>http://www.ethicalhack3r.co.uk/security/dionaea-low-interaction-honeypot/comment-page-1/#comment-129202</link>
		<dc:creator>Fhrobro</dc:creator>
		<pubDate>Thu, 23 Dec 2010 22:06:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.ethicalhack3r.co.uk/?p=506#comment-129202</guid>
		<description>Catch those hackas! XD</description>
		<content:encoded><![CDATA[<p>Catch those hackas! XD</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andrew</title>
		<link>http://www.ethicalhack3r.co.uk/security/dionaea-low-interaction-honeypot/comment-page-1/#comment-122487</link>
		<dc:creator>Andrew</dc:creator>
		<pubDate>Tue, 16 Nov 2010 13:19:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.ethicalhack3r.co.uk/?p=506#comment-122487</guid>
		<description>Hello, I am having great difficulty running dionaea on ubuntu, I can&#039;t seem to capture anything, I have taken all security features away and taken the firewall down on my router.

Thanks</description>
		<content:encoded><![CDATA[<p>Hello, I am having great difficulty running dionaea on ubuntu, I can&#8217;t seem to capture anything, I have taken all security features away and taken the firewall down on my router.</p>
<p>Thanks</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mona</title>
		<link>http://www.ethicalhack3r.co.uk/security/dionaea-low-interaction-honeypot/comment-page-1/#comment-82286</link>
		<dc:creator>Mona</dc:creator>
		<pubDate>Mon, 17 May 2010 18:43:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.ethicalhack3r.co.uk/?p=506#comment-82286</guid>
		<description>Hello there,

I have installed Dionaea properly however I am facing some troubles when i try to run it? Please help.

Thank you,</description>
		<content:encoded><![CDATA[<p>Hello there,</p>
<p>I have installed Dionaea properly however I am facing some troubles when i try to run it? Please help.</p>
<p>Thank you,</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ambrose</title>
		<link>http://www.ethicalhack3r.co.uk/security/dionaea-low-interaction-honeypot/comment-page-1/#comment-76173</link>
		<dc:creator>Ambrose</dc:creator>
		<pubDate>Tue, 04 May 2010 11:47:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.ethicalhack3r.co.uk/?p=506#comment-76173</guid>
		<description>Hi there, 
Can you tell me please, where I can find some forums or email conferences where are discussed any problems with installing and compiling not only dionaea but also dependencies (like libemu...)...
Thanks for any response...</description>
		<content:encoded><![CDATA[<p>Hi there,<br />
Can you tell me please, where I can find some forums or email conferences where are discussed any problems with installing and compiling not only dionaea but also dependencies (like libemu&#8230;)&#8230;<br />
Thanks for any response&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: iVictor</title>
		<link>http://www.ethicalhack3r.co.uk/security/dionaea-low-interaction-honeypot/comment-page-1/#comment-38424</link>
		<dc:creator>iVictor</dc:creator>
		<pubDate>Sun, 07 Mar 2010 12:23:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.ethicalhack3r.co.uk/?p=506#comment-38424</guid>
		<description>Going to try it this week. Looks like the home page is down(?). Checking out at ohloh (http://www.ohloh.net/p/dionaea).

Best Regards.</description>
		<content:encoded><![CDATA[<p>Going to try it this week. Looks like the home page is down(?). Checking out at ohloh (<a href="http://www.ohloh.net/p/dionaea" rel="nofollow">http://www.ohloh.net/p/dionaea</a>).</p>
<p>Best Regards.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Lukas</title>
		<link>http://www.ethicalhack3r.co.uk/security/dionaea-low-interaction-honeypot/comment-page-1/#comment-14108</link>
		<dc:creator>Lukas</dc:creator>
		<pubDate>Tue, 26 Jan 2010 16:53:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.ethicalhack3r.co.uk/?p=506#comment-14108</guid>
		<description>Hi Ryan,

you are right, to get hits on Glastopf you have to set up a domain (FQDN &gt; subdomains) and wait for a google crawler.

Contact me if there are other questions.

Greetings,
Lukas</description>
		<content:encoded><![CDATA[<p>Hi Ryan,</p>
<p>you are right, to get hits on Glastopf you have to set up a domain (FQDN &gt; subdomains) and wait for a google crawler.</p>
<p>Contact me if there are other questions.</p>
<p>Greetings,<br />
Lukas</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: d0s</title>
		<link>http://www.ethicalhack3r.co.uk/security/dionaea-low-interaction-honeypot/comment-page-1/#comment-10275</link>
		<dc:creator>d0s</dc:creator>
		<pubDate>Sun, 17 Jan 2010 19:51:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.ethicalhack3r.co.uk/?p=506#comment-10275</guid>
		<description>Nice results
I plan to set up a honeypot in a VM.
Dionaea looks pretty cool.
I know malware &amp; rootkits tend to act differently in VM&#039;s but it would be interesting to see the results.

D</description>
		<content:encoded><![CDATA[<p>Nice results<br />
I plan to set up a honeypot in a VM.<br />
Dionaea looks pretty cool.<br />
I know malware &amp; rootkits tend to act differently in VM&#8217;s but it would be interesting to see the results.</p>
<p>D</p>
]]></content:encoded>
	</item>
</channel>
</rss>

