Windows IT Pro is the authoritative and independent resource for windows nt, windows 2000, windows 2003, windows xp. Features a collection of resources and magazines for windows IT professionals.
  
  
  Advanced Search 


April 2006

Laying a Malware Trap

When simple detection isn't enough, capture that virus for examination
RSS
Subscribe to Windows IT Pro | See More Security Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!
SideBar    Taking It to the Worm

Honeypots. Honeypots are a great way to catch Internet worms that have more complex interactions. Most honeypots have port listeners and contain more complex interaction mechanisms if you need them. For example, most honeypots can easily handle malware requiring TCP handshakes and respond with prescripted commands. Many are simple to set up and have many logging and notification mechanisms already built in that make them perfect as virus traps.

Several people, including Laurent Oudot of the Rstack team (http://www.rstack.org) used Honeyd (http://www.honeyd.org), a popular open-source honeypot, to catch the MSBlaster worm when it was causing damage around the world. The worm was looking for TCP port 135, so Honeyd users created a port listener on that port by adding the following line to the Honeyd.config file:

add