Author Archives: SANS Internet Storm Center, InfoCON: green
DShield Honeypot Setup with pfSense, (Tue, Jan 31st)
Setting up a DShield honeypot is well guided by the installation script &#;x26;#;x5b;1&#;x26;#;x5d;. After several minutes of following the instructions and adding some custom details, the honeypot is up and running. What&#;x26;#;39;s needed after that is to expose the honeypot to the internet. I recently decided to update my home router and thought it was a great opportunity to dig into using pfSense &#;x26;#;x5b;2&#;x26;#;x5d;. To expose the honeypot using the pfsense, there are two main options to consider for NAT rules &#;x26;#;x5b;3&#;x26;#;x5d;:
Continue reading DShield Honeypot Setup with pfSense, (Tue, Jan 31st)
ISC Stormcast For Tuesday, January 31st, 2023 https://isc.sans.edu/podcastdetail.html?id=8348, (Tue, Jan 31st)
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Continue reading ISC Stormcast For Tuesday, January 31st, 2023 https://isc.sans.edu/podcastdetail.html?id=8348, (Tue, Jan 31st)
Decoding DNS over HTTP(s) Requests, (Mon, Jan 30th)
I have written before about scans for DNS over HTTP(s) (DoH) servers. DoH is now widely supported in different browsers and recursive resolvers. It has been an important piece in the puzzle to evade various censorship regimes, in particular, the “Big Chinese Firewall”. Malware has at times used DoH, but often uses its own HTTP(s) based resolvers that do not necessarily comply with the official DoH standard.
Continue reading Decoding DNS over HTTP(s) Requests, (Mon, Jan 30th)
ISC Stormcast For Monday, January 30th, 2023 https://isc.sans.edu/podcastdetail.html?id=8346, (Mon, Jan 30th)
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Continue reading ISC Stormcast For Monday, January 30th, 2023 https://isc.sans.edu/podcastdetail.html?id=8346, (Mon, Jan 30th)
ISC Stormcast For Friday, January 27th, 2023 https://isc.sans.edu/podcastdetail.html?id=8344, (Fri, Jan 27th)
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Continue reading ISC Stormcast For Friday, January 27th, 2023 https://isc.sans.edu/podcastdetail.html?id=8344, (Fri, Jan 27th)
Live Linux IR with UAC, (Thu, Jan 26th)
ISC Stormcast For Thursday, January 26th, 2023 https://isc.sans.edu/podcastdetail.html?id=8342, (Thu, Jan 26th)
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Continue reading ISC Stormcast For Thursday, January 26th, 2023 https://isc.sans.edu/podcastdetail.html?id=8342, (Thu, Jan 26th)
ISC Stormcast For Thursday, January 26th, 2023 https://isc.sans.edu/podcastdetail.html?id=8342, (Thu, Jan 26th)
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Continue reading ISC Stormcast For Thursday, January 26th, 2023 https://isc.sans.edu/podcastdetail.html?id=8342, (Thu, Jan 26th)
A First Malicious OneNote Document, (Wed, Jan 25th)
Attackers are always trying to find new ways to deliver malware to victims. They recently started sending Microsoft OneNote files in massive phishing campaigns[1]. OneNote files (ending the extension “.one”) are handled automatically by computers that have the Microsoft Office suite installed. Yesterday, my honeypot caught a first sample. This is a good opportunity to have a look at these files. The file, called “delivery-note.one”, was delivered as an attachment to a classic phishing email:
Continue reading A First Malicious OneNote Document, (Wed, Jan 25th)