Client-Side Honeypots

A client-side honeypot is a type of honeypots that is designed to collect information about client-side attacks. Typically such a honeypot uses Internet Explorer and continuously surfs the Web in an automated way. During the surfing, the system activity is closely monitored for changes such a new files on the hard disk or new processes since such changes indicate a successful drive-by download. In such a case, a malicious website has compromised the web browser by just visiting the site. Examples of client-side honeypots are Capture-HPC and the MITRE Honeyclient.

We run several client-side honeypots in our lab and find new malicious website frequently. At the moment, we find quite often sites that use malicious PDF files to exploit our browser. In such an attack, a vulnerability in the Adobe Acrobat Reader is exploited in order to execute code on the victim's machine. To illustrate such an exploit, I created a quick movie that shows a live exploit. In the future, I hope to cover client-side exploits more frequently. With exploits such as the current MS08-078 vulnerability I'm sure that we will observe more malicious sites in the future...

Trackbacks

  1. London broil cooking time.

    Thanks for the information! I have played with this type of honeypots in the last few days and found some pretty interesting exploits.

Comments

Display comments as (Linear | Threaded)

  1. mnajem says:

    TH, I want to use that movie for my class material, can you upload any AVI/MPG format, thanks!

  2. Thorsten Holz says:

    I'll take a look at it next week (I'm currently in holidays), but converting to another format should be possible. Perhaps you can do the conversion on yourself :)


Add Comment


E-Mail addresses will not be displayed and will only be used for E-Mail notifications

To prevent automated Bots from commentspamming, please enter the string you see in the image below in the appropriate input box. Your comment will only be submitted if the strings match. Please ensure that your browser supports and accepts cookies, or your comment cannot be verified correctly.
CAPTCHA 1CAPTCHA 2CAPTCHA 3CAPTCHA 4CAPTCHA 5