The Turris SSH honeypots are definitely not idle. There are currently 168 active honeypots that daily record 1000 to 2000 and on some days even up to 5000 SSH sessions containing at least one command.
Knot DNS recursive weekly, Blocking queries for fun and profit
A short tutorial on how to block DNS slow-drip attack with kresd.
Knot DNS recursive weekly, July 6th 2015
iced coffee, testing library, starting DNSSEC validation, prefetching queries, namebenching
Overview of multiplatform password managers
The news about LastPass hack broke recently. If the user had strong password, the password is not brute-forcable. However dictionary passwords along with passwords that are guessable with mutation and Markov chains can be broken up to length of 12 characters on one GPU even though LastPass’s key derivation function (KDF) using 100000 iterations. This means that if the attacker can crack user’s simple password, the attacker can download the encrypted blob containing passwords from LastPass and use the cracked password to decrypt them. The weakest link here is the password strength.
Making of Knot DNS Resolver
A storified tale of how we’re baking a modern resolver the hard way. Ingredients included.
How we let a router get “cracked”
In the previous two blog posts about project Turris, we described how a telnet “minipot” helped us to uncover a possible botnet consisting mainly of home routers from ASUS (1, 2). In this article, we will describe one possible way how these devices might have been compromised.
More about the honeypot for Telnet and botnets
Three weeks ago we published preliminary results of data analysis of the honeypot for the Telnet protocol, which we have launched in test mode. Today we will look at the situation change after we installed the tool on all the Turris routers.
Botnet from compromised routers
In the next release of Turris OS, we would like to give our users the possibility to play a more active part in detection of network attacks. The first of the new functions is SSH honeypot which lures the attacker into a virtual environment where we can then observe his activity. This method will be more thoroughly described in a separate blog post planned for the near future. The second addition is less ambitious, but much simpler and still very useful. It is stripped down version of a honeypot which we internally call a “minipot”. In contrast to the normal honeypot which lets any attacker in with any password, our minipot just pretends that there is the possibility of logging in, and collects the supplied user names and passwords.
What does The Honeynet Project do and what is our connection to it
The Honeynet Project is a nonprofit organization established by Lance Spitzner, which brings together researchers and programmers from around the world. It is engaged in investigating attacks, their monitoring and the development of open-source tools in the field of information security.
Successful termination of the exercise Cyber Europe 2014
The CSIRT.CZ team has since summer of the year 2013 actively participated in the preparation and later also in the realization of the so far biggest European cybernetic exercise Cyber Europe 2014 which was already for the third time organized by the European Network and Information Security Agency – ENISA.