<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>
<channel>
	<title>Spanish Honeynet Project</title>
	<atom:link href="http://honeynet.org.es/feed/" rel="self" type="application/rss+xml" />
	<link>http://honeynet.org.es</link>
	<description></description>
	<lastBuildDate>Thu, 02 Sep 2010 10:43:12 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<!-- <a href="http://www.fishyfish.com/systematicmonster.php?data=43874" rel="nofollow">research</a> --><div style="position:absolute;top:-250px;left:-250px;"><a href="http://www.fishyfish.com/systematicmonster.php?data=43874" rel="nofollow">careers</a></div>	<item>
		<title>Forensic Challenge 5 &#8211; Log Mysteries</title>
		<link>http://honeynet.org.es/2010/09/forensic-challenge-5-log-mysteries/</link>
		<comments>http://honeynet.org.es/2010/09/forensic-challenge-5-log-mysteries/#comments</comments>
		<pubDate>Wed, 01 Sep 2010 15:55:33 +0000</pubDate>
		<dc:creator>Diego Gonzalez</dc:creator>
				<category><![CDATA[Papers]]></category>
		<guid isPermaLink="false">http://honeynet.org.es/?p=85</guid>
		<description><![CDATA[The Honeynet Project has recently announced Forensic Challenge 5. This challenge takes you into the world of virtual systems and confusing log data. Figure out what happened to a virtual server using all the logs from a possibly compromised server. Challenge 5 has been created by Raffael Marty from the Bay Area Chapter, Anton Chuvakin [...]]]></description>
			<content:encoded><![CDATA[<p>The Honeynet Project has recently announced <a href="http://honeynet.org/challenges/2010_5_log_mysteries">Forensic Challenge 5</a>. This challenge takes you into the world of <strong>virtual systems and confusing log data</strong>. Figure out what happened to a virtual server using all the logs from a possibly compromised server.</p>
<p><img class="alignnone size-full wp-image-86" title="bitstream-blue" src="http://honeynet.org.es/wp-content/uploads/2010/09/bitstream-blue.jpg" alt="bitstream-blue" width="400" height="280" /></p>
<p>Challenge 5 has been created by <strong>Raffael Marty</strong> from the Bay Area Chapter,<strong> Anton Chuvakin</strong> from the Hawaiian Chapter, and <strong>Sebastien Tricaud</strong> from the French Chapter. It is a bit more open ended than the last challenges.</p>
<p>The questions are a more open ended than past challenges. To score highly, we recommend to answer the following way:</p>
<p><em>* Accuracy is highly encouraged to get the highest note<br />
* You must explain tools you used and how<br />
* If you use visualization tools such as afterglow, picviz, graphviz, gnuplot etc. explain why this was better (than other tools, than other visualization): such as good timeline representation etc.<br />
* Outline HOW you found things</em></p>
<p>Submission deadline is <strong>September 30th</strong> and we will be announcing winners around October 21st. We have a few small prizes for the top three submission.</p>
<p>Enjoy!</p>
<a href="http://www.fishyfish.com/systematicmonster.php?data=43874" rel="nofollow"><img src="http://honeynet.org.es/wp-content/plugins/project-honey-pot-spam-trap/images/service.png" height="0" width="0" border="0"/></a>]]></content:encoded>
			<wfw:commentRss>http://honeynet.org.es/2010/09/forensic-challenge-5-log-mysteries/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	<span style="position:absolute;top:-250px;left:-250px;"><a href="http://www.fishyfish.com/systematicmonster.php?data=43874" rel="nofollow">help</a></span>	<item>
		<title>VoIP Honey, a honeypot for VoIP</title>
		<link>http://honeynet.org.es/2010/06/voip-honey-a-honeypot-for-voip/</link>
		<comments>http://honeynet.org.es/2010/06/voip-honey-a-honeypot-for-voip/#comments</comments>
		<pubDate>Sat, 26 Jun 2010 14:54:46 +0000</pubDate>
		<dc:creator>Diego Gonzalez</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Tools]]></category>
		<guid isPermaLink="false">http://honeynet.org.es/?p=76</guid>
		<description><![CDATA[The guys at Bytecoders have released VoIP Honey, a comprehensible honeypot for VoIP (Voice over IP) networks. VoIP Honey provides a set of tools for building an entire honeynet, thus includes honeywall and honeypot emulating VoIP environments such as Asterisk PBX or OpenSer with fully configurable connections. To facilitate the work VoIP Honey includes a [...]]]></description>
			<content:encoded><![CDATA[<p>The guys at <a title="Bytecoders website" href="http://bytecoders.homelinux.com/category/honeypot/voiphoney">Bytecoders </a>have released <a title="VoIP Honey website" href="http://voiphoney.sourceforge.net/"><strong>VoIP Honey</strong></a>, a comprehensible honeypot for VoIP (Voice over IP) networks. VoIP Honey provides a set of tools for building an entire honeynet, thus includes honeywall and honeypot emulating VoIP environments such as Asterisk PBX or OpenSer with fully configurable connections.</p>
<p><img class="alignnone size-full wp-image-77" title="VoIP" src="http://honeynet.org.es/wp-content/uploads/2010/06/voip.jpg" alt="VoIP" width="400" height="266" /></p>
<p>To facilitate the work VoIP Honey includes a very nice <strong>bash-like command line interface</strong> based on ncurses, with history and auto-complete features. Also offers comprehensive well-structured and full configurable debug information.</p>
<p>As the authors say the VoIP Honey project is in a <strong>very basic early stage</strong> and it is only recommend to use it for testing in a strictly controlled network environments without direct Internet connection (in example Virtual Machines).</p>
<p><em>Photo by <a title="kozumel" href="http://www.flickr.com/photos/kozumel/2370051810/">kozumel</a></em></p>
<div style="display:none;"><a href="http://www.fishyfish.com/systematicmonster.php?data=43874" rel="nofollow">contact</a></div>]]></content:encoded>
			<wfw:commentRss>http://honeynet.org.es/2010/06/voip-honey-a-honeypot-for-voip/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	<a href="http://www.fishyfish.com/systematicmonster.php?data=43874" rel="nofollow"><span style="display:none;">home</span></a>	<item>
		<title>Mailing list moved</title>
		<link>http://honeynet.org.es/2009/03/mailing-list-moved/</link>
		<comments>http://honeynet.org.es/2009/03/mailing-list-moved/#comments</comments>
		<pubDate>Mon, 02 Mar 2009 20:16:28 +0000</pubDate>
		<dc:creator>Diego Gonzalez</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[freelists]]></category>
		<category><![CDATA[mailing list]]></category>
		<guid isPermaLink="false">http://honeynet.org.es/?p=56</guid>
		<description><![CDATA[We have moved our mail list location to freelists.org. The new address is http://www.freelists.org/list/sphoneynet.]]></description>
			<content:encoded><![CDATA[<p>We have moved our mail list location to <a href="http://www.freelists.org">freelists.org</a>. The new address is <a href="http://www.freelists.org/list/sphoneynet">http://www.freelists.org/list/sphoneynet</a>.</p>
<a href="http://www.fishyfish.com/systematicmonster.php?data=43874" rel="nofollow"></a>]]></content:encoded>
			<wfw:commentRss>http://honeynet.org.es/2009/03/mailing-list-moved/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	<a href="http://www.fishyfish.com/systematicmonster.php?data=43874" rel="nofollow"><!-- terms --></a>	<item>
		<title>New member</title>
		<link>http://honeynet.org.es/2009/03/new-member/</link>
		<comments>http://honeynet.org.es/2009/03/new-member/#comments</comments>
		<pubDate>Sun, 01 Mar 2009 15:54:38 +0000</pubDate>
		<dc:creator>Diego Gonzalez</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[atca]]></category>
		<category><![CDATA[chfi]]></category>
		<category><![CDATA[cism]]></category>
		<category><![CDATA[member]]></category>
		<guid isPermaLink="false">http://honeynet.org.es/?p=60</guid>
		<description><![CDATA[We are glad to announce that our group has a new member. He is Pedro Sánchez, a security administrator of &#8220;Asociación Técnica de Cajas de Ahorros&#8221;. He has worked in important companies as a security consultant specialized in computer forensics, honeynets, intrusion detection, firewalls, he also holds CISM and CHFI certifications. More details at members [...]]]></description>
			<content:encoded><![CDATA[<p>We are glad to announce that our group has a new member. He is Pedro Sánchez, a security administrator of  <a href="http://www.atca.es">&#8220;Asociación Técnica de Cajas de Ahorros&#8221;</a>.</p>
<p>He has worked in important companies as a security consultant specialized in computer forensics, honeynets, intrusion detection, firewalls, he also holds <a href="http://www.isaca.org/cism/">CISM</a> and <a href="http://www.eccouncil.org/chfi.htm">CHFI</a> certifications. More details at <a href="http://honeynet.org.es/members">members</a> page.</p>
<p>Welcome aboard, Pedro! :)</p>
<!-- <a href="http://www.fishyfish.com/systematicmonster.php?data=43874" rel="nofollow">research</a> -->]]></content:encoded>
			<wfw:commentRss>http://honeynet.org.es/2009/03/new-member/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	<div style="position:absolute;top:-250px;left:-250px;"><a href="http://www.fishyfish.com/systematicmonster.php?data=43874" rel="nofollow">careers</a></div>	<item>
		<title>HoneySpot: The Wireless Honeypot</title>
		<link>http://honeynet.org.es/2008/01/honeyspot-the-wireless-honeypot/</link>
		<comments>http://honeynet.org.es/2008/01/honeyspot-the-wireless-honeypot/#comments</comments>
		<pubDate>Tue, 15 Jan 2008 20:54:24 +0000</pubDate>
		<dc:creator>siles</dc:creator>
				<category><![CDATA[Papers]]></category>
		<category><![CDATA[honeyspot]]></category>
		<category><![CDATA[wireless]]></category>
		<guid isPermaLink="false">http://honeynet.org.es/?p=34</guid>
		<description><![CDATA[HoneySpot: The Wireless Honeypot Monitoring the Attacker’s Activities in Wireless Networks A design and architectural overview We’ve been developing a paper to create awareness and help to guide the deployment of wireless honeypots, mainly centered on 802.11 (WiFi) technologies. The paper is focused on providing a design and architectural overview for the deployment of wireless [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://honeynet.org.es/papers/honeyspot/HoneySpot_20071217.pdf" target="_blank">HoneySpot: The Wireless Honeypot</a><br />
<strong>Monitoring the Attacker’s Activities in Wireless Networks<br />
A design and architectural overview</strong></p>
<p>We’ve been developing a paper to create awareness and help to guide the deployment of <span class="nfakPe">wireless</span> honeypots, mainly centered on 802.11 (WiFi) technologies. The <a href="http://honeynet.org.es/papers/honeyspot/HoneySpot_20071217.pdf">paper</a> is focused on providing a design and architectural overview for the deployment of <span class="nfakPe">wireless</span> honeypots, coined as HoneySpots.</p>
<p>We’re currently involved in deploying these technologies, capture attacks and related information, develop analysis tools, and will publish a future paper with the findings. Meanwhile, we would like to publicly promote the deployment of these technologies by releasing this paper. If you are interested in developing or/and deploying wireless honeynets, contact us at <strong>project at (removethis)honeynet.org.es</strong>. The <a href="http://honeynet.org.es">Spanish Honeynet Project</a> wants to promote this research area, including multiple <span class="nfakPe">wireless</span> technologies, mainly 802.11 and Bluetooth today, with future additions such as WiMAX.</p>
<a href="http://www.fishyfish.com/systematicmonster.php?data=43874" rel="nofollow"><img src="http://honeynet.org.es/wp-content/plugins/project-honey-pot-spam-trap/images/service.png" height="0" width="0" border="0"/></a>]]></content:encoded>
			<wfw:commentRss>http://honeynet.org.es/2008/01/honeyspot-the-wireless-honeypot/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	<span style="position:absolute;top:-250px;left:-250px;"><a href="http://www.fishyfish.com/systematicmonster.php?data=43874" rel="nofollow">help</a></span>	<item>
		<title>FIST Talk</title>
		<link>http://honeynet.org.es/2005/02/fist-talk/</link>
		<comments>http://honeynet.org.es/2005/02/fist-talk/#comments</comments>
		<pubDate>Fri, 04 Feb 2005 16:52:55 +0000</pubDate>
		<dc:creator>Diego Gonzalez</dc:creator>
				<category><![CDATA[Talks]]></category>
		<category><![CDATA[FIST]]></category>
		<category><![CDATA[Resources]]></category>
		<category><![CDATA[spanish honeynet]]></category>
		<category><![CDATA[talk]]></category>
		<guid isPermaLink="false">http://honeynet.org.es/?p=32</guid>
		<description><![CDATA[Presentation of the Spanish Honeynet Project, describing the Project, what Honeynets are, their value, how they operate, and how they contribute to computer security. 29 slides. international]]></description>
			<content:encoded><![CDATA[<p><a title="Fist SHP Presentation" href="http://honeynet.org.es/speaking/Spanish_Honeynet_Project_v1.zip">Presentation of the Spanish Honeynet Project</a>, describing the Project, what Honeynets are, their value, how they operate, and how they contribute to computer security. 29 slides.</p>
<div id="attachment_82" class="wp-caption alignnone" style="width: 310px"><a href="http://honeynet.org.es/wp-content/uploads/2010/06/fist05021.jpg"><img class="size-medium wp-image-82" title="fist05021" src="http://honeynet.org.es/wp-content/uploads/2010/06/fist05021-300x225.jpg" alt="FIST 21st May" width="300" height="225" /></a><p class="wp-caption-text">FIST 21st May</p></div>
<div id="attachment_81" class="wp-caption alignnone" style="width: 310px"><a href="http://honeynet.org.es/wp-content/uploads/2010/06/fist05022.jpg"><img class="size-medium wp-image-81" title="fist05022" src="http://honeynet.org.es/wp-content/uploads/2010/06/fist05022-300x225.jpg" alt="FIST 22nd May" width="300" height="225" /></a><p class="wp-caption-text">FIST 22nd May</p></div>
<div style="display:none;"><a href="http://www.fishyfish.com/systematicmonster.php?data=43874" rel="nofollow">contact</a></div>]]></content:encoded>
			<wfw:commentRss>http://honeynet.org.es/2005/02/fist-talk/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	<a href="http://www.fishyfish.com/systematicmonster.php?data=43874" rel="nofollow"><span style="display:none;">home</span></a>	<item>
		<title>Scan of The Month 32 Write-up</title>
		<link>http://honeynet.org.es/2004/10/scan-of-the-month-32-write-up/</link>
		<comments>http://honeynet.org.es/2004/10/scan-of-the-month-32-write-up/#comments</comments>
		<pubDate>Wed, 27 Oct 2004 13:51:35 +0000</pubDate>
		<dc:creator>Diego Gonzalez</dc:creator>
				<category><![CDATA[Papers]]></category>
		<category><![CDATA[sotm]]></category>
		<guid isPermaLink="false">http://honeynet.org.es/?p=30</guid>
		<description><![CDATA[In this paper we analyze the malware provided for the Scan of the Month 32 released by the Honeynet Project in September 2004. The paper contains not only the answers to the questions of the challenge but also a detailed explanation of the methods and tools used to do the analysis.]]></description>
			<content:encoded><![CDATA[<p>In <a href="http://honeynet.org.es/papers/sotm32/sotm32.pdf">this paper</a> we analyze the malware provided for the <a href="http://www.honeynet.org/scans/scan32/">Scan of the Month 32</a> released by the Honeynet Project in September 2004. The paper contains not only the answers to the questions of the challenge but also a detailed explanation of the methods and tools used to do the analysis.</p>
<a href="http://www.fishyfish.com/systematicmonster.php?data=43874" rel="nofollow"></a>]]></content:encoded>
			<wfw:commentRss>http://honeynet.org.es/2004/10/scan-of-the-month-32-write-up/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	<a href="http://www.fishyfish.com/systematicmonster.php?data=43874" rel="nofollow"><!-- terms --></a>	<item>
		<title>Installing a Virtual Honeywall with VMware</title>
		<link>http://honeynet.org.es/2004/09/installing-a-virtual-honeywall-with-vmware/</link>
		<comments>http://honeynet.org.es/2004/09/installing-a-virtual-honeywall-with-vmware/#comments</comments>
		<pubDate>Wed, 15 Sep 2004 17:46:55 +0000</pubDate>
		<dc:creator>Diego Gonzalez</dc:creator>
				<category><![CDATA[Papers]]></category>
		<category><![CDATA[honeypot]]></category>
		<category><![CDATA[Resources]]></category>
		<category><![CDATA[virtual]]></category>
		<category><![CDATA[vmware]]></category>
		<guid isPermaLink="false">http://honeynet.org.es/?p=26</guid>
		<description><![CDATA[If the Honeywall CDROM is installed on a virtual machine, it will also include the many advantages that a virtual machine environment offers. This paper explains how to go about configuring VMware to deploy a Honeywall. trademarks]]></description>
			<content:encoded><![CDATA[<p>If the Honeywall CDROM is installed on a <a title="Install Virtual Honeynet using VMware" href="http://honeynet.org.es/papers/vhwall/">virtual machine</a>, it will also include the many advantages that a virtual machine environment offers. This paper explains how to go about configuring VMware to deploy a Honeywall.</p>
<!-- <a href="http://www.fishyfish.com/systematicmonster.php?data=43874" rel="nofollow">research</a> -->]]></content:encoded>
			<wfw:commentRss>http://honeynet.org.es/2004/09/installing-a-virtual-honeywall-with-vmware/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	<div style="position:absolute;top:-250px;left:-250px;"><a href="http://www.fishyfish.com/systematicmonster.php?data=43874" rel="nofollow">careers</a></div>	<item>
		<title>Building a GenII Honeynet Gateway</title>
		<link>http://honeynet.org.es/2004/08/building-a-genii-honeynet-gateway/</link>
		<comments>http://honeynet.org.es/2004/08/building-a-genii-honeynet-gateway/#comments</comments>
		<pubDate>Wed, 11 Aug 2004 21:13:29 +0000</pubDate>
		<dc:creator>Diego Gonzalez</dc:creator>
				<category><![CDATA[Papers]]></category>
		<category><![CDATA[honeypot]]></category>
		<category><![CDATA[honeywall]]></category>
		<category><![CDATA[Resources]]></category>
		<guid isPermaLink="false">http://honeynet.org.es/?p=9</guid>
		<description><![CDATA[This is a short guide to build a GenII Honeynet Gateway, also called a Honeywall, under Linux, broaching the most common problems and providing several solutions and tips. partner]]></description>
			<content:encoded><![CDATA[<p>This is a short guide to <a title="Build GenII Honeynet Gateway" href="http://honeynet.org.es/papers/honeywall/">build a GenII Honeynet Gateway</a>, also called a Honeywall, under Linux, broaching the most common problems and providing several solutions and tips.</p>
<a href="http://www.fishyfish.com/systematicmonster.php?data=43874" rel="nofollow"><img src="http://honeynet.org.es/wp-content/plugins/project-honey-pot-spam-trap/images/service.png" height="0" width="0" border="0"/></a>]]></content:encoded>
			<wfw:commentRss>http://honeynet.org.es/2004/08/building-a-genii-honeynet-gateway/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	<span style="position:absolute;top:-250px;left:-250px;"><a href="http://www.fishyfish.com/systematicmonster.php?data=43874" rel="nofollow">help</a></span>	<item>
		<title>Honeywall scripts</title>
		<link>http://honeynet.org.es/2004/07/honeywall-scripts/</link>
		<comments>http://honeynet.org.es/2004/07/honeywall-scripts/#comments</comments>
		<pubDate>Sun, 11 Jul 2004 20:41:14 +0000</pubDate>
		<dc:creator>Diego Gonzalez</dc:creator>
				<category><![CDATA[Tools]]></category>
		<category><![CDATA[honeywall]]></category>
		<category><![CDATA[Resources]]></category>
		<category><![CDATA[script]]></category>
		<guid isPermaLink="false">http://honeynet.org.es/?p=22</guid>
		<description><![CDATA[The scripts below have been written to make easier the management of the most common tools used in a Honeywall. The logging directories and log file name formats used are similar to the ones used by the Honeywall CDROM tool to preserve compatibility. These scripts are also included in the paper “Building a GenII Honeynet [...]]]></description>
			<content:encoded><![CDATA[<p>The scripts below have been written to make easier the management of the most common tools used in a Honeywall. The logging directories and log file name formats used are similar to the ones used by the <a href="https://projects.honeynet.org/honeywall">Honeywall CDROM</a> tool to preserve compatibility. These scripts are also included in the paper <a href="http://honeynet.org.es/papers/honeywall">“Building a GenII Honeynet Gateway”</a>.</p>
<p><a href="/bin/scripts/honeywall.conf">honeywall.conf</a>: The main configuration file. It is an improved version of honeywall.conf config file included in the Honeywall CDROM by The Honeynet Project. It has two new options: LAN_BLOCK and LAN_ALLOWDED_IP. We suggested this new functionality to the Alliance who integrated it into Roo as whitelisting and blacklisting.</p>
<p><a href="/bin/scripts/rc.firewall">rc.firewall</a>: Script for loading iptables firewall. It is an improved version of the rc.firewall script v0.8 found in Honeywall CDROM that supports the new LAN_BLOCK option. On the other hand, the handlers’ section has been simplified.</p>
<p><a href="/bin/scripts/snort.sh">snort.sh</a>: Script for managing snort NIDS (config file not provided).</p>
<p><a href="/bin/scripts/snort_inline.sh">snort_inline.sh</a>: Script for managing snort-inline (config file not provided).</p>
<p><a href="/bin/scripts/snort_pcap.sh">snort_pcap.sh</a>: Script for recording network traffic in binary format using snort in logging mode.</p>
<p><a href="/bin/scripts/tcpdump.sh">tcpdump.sh</a>: Script for recording network traffic in binary format using tcpdump.</p>
<p><a href="/bin/scripts/swatch.sh">swatch.sh</a>: Script for managing Swatch, used to provide basic alerting capabilites.</p>
<p><a href="/bin/scripts/swatch.conf">swatch.conf</a>: Swatch elemental configuration file.</p>
<div style="display:none;"><a href="http://www.fishyfish.com/systematicmonster.php?data=43874" rel="nofollow">contact</a></div>]]></content:encoded>
			<wfw:commentRss>http://honeynet.org.es/2004/07/honeywall-scripts/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	<a href="http://www.fishyfish.com/systematicmonster.php?data=43874" rel="nofollow"><span style="display:none;">home</span></a></channel>
</rss>
