Home > ParetoLogic Blogs > Malware Diaries > HoneyPot Workflow
Reply
 
Thread Tools Display Modes
  #1  
Old 07-29-2009, 09:10 PM
JSegura JSegura is offline
Editor
Join Date: Mar 2008
Posts: 51
Default HoneyPot Workflow

As mentioned in a previous post, our HoneyPots look for exploits with the most common browsers (and plugins).

We generate a pool of URLs refreshed every day, as well as get incoming spam URLs in real time.

An array of machines process those URLs. Every time a malicious URL is found, it gets added to our blacklist.

URLs on the blacklist are verified every hour to make sure the content:

- is the same
- has a different payload
- no longer is there

hon

Jerome Segura
Reply With Quote
Reply

« Previous Thread | Next Thread »

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump


Terms of Use