Monthly Archives: August 2010

Export Address Table Filtering (EMET v2)

I’ll tell you the truth: Export Address Table Filtering, the feature of the upcoming release of EMET, “designed to break nearly all shell code in use today”, intrigued me a bit. Since I wasn’t able to find docs about the … Continue reading

Posted in News | Tagged

PHoneyC DOM Emulation – Browser Personality

A new improvement in PHoneyC DOM emulation code was committed in SVN r1624. The idea is to better emulate the DOM behaviour depending on the selected browser personality. Let’s take a look at the code starting from the personalities definition … Continue reading

Posted in Honeynet Project, PHoneyC, Projects | Tagged , ,

Another great step forward

“Dionaea is meant to be a Nepenthes successor, embedding Python as scripting language, using libemu to detect shellcodes, supporting IPv6 and TLS” (taken from Dionaea homepage). Besides being the most interesting project for trapping malware exploiting vulnerabilities, Dionaea supports a … Continue reading

Posted in Honeynet Project, Projects, TIP | Tagged , ,

PHoneyC DOM Emulation – Window

A few weeks ago I started reviewing the PHoneyC DOM emulation code and realized it was turning to be hard to maintain and debug due to a huge amount of undocumented (and sometimes awful) hacks. For this reason I decided … Continue reading

Posted in Honeynet Project, PHoneyC, Projects | Tagged , ,