<?xml version="1.0" encoding="utf-8"?>
<!-- generator="FeedCreator 1.7.2-ppt DokuWiki" -->
<?xml-stylesheet href="http://carnivore.it/lib/exe/css.php?s=feed" type="text/css"?>
<rdf:RDF
    xmlns="http://purl.org/rss/1.0/"
    xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
    xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
    xmlns:dc="http://purl.org/dc/elements/1.1/">
    <channel rdf:about="http://carnivore.it/feed.php">
        <title>carnivore news</title>
        <description></description>
        <link>http://carnivore.it/</link>
        <image rdf:resource="http://carnivore.it/lib/images/favicon.ico" />
       <dc:date>2010-09-08T02:49:39+02:00</dc:date>
        <items>
            <rdf:Seq>
                <rdf:li rdf:resource="http://carnivore.it/2010/09/06/xlinked"/>
                <rdf:li rdf:resource="http://carnivore.it/2010/08/27/attacks_on_mssql"/>
                <rdf:li rdf:resource="http://carnivore.it/2010/08/25/gsoc_2010"/>
                <rdf:li rdf:resource="http://carnivore.it/2010/08/20/stun_cli_firewallping"/>
                <rdf:li rdf:resource="http://carnivore.it/2010/08/19/metasploit_os_fingerprinting_via_smb"/>
                <rdf:li rdf:resource="http://carnivore.it/2010/08/06/nfq_fun"/>
                <rdf:li rdf:resource="http://carnivore.it/2010/07/30/getting_over_dect"/>
                <rdf:li rdf:resource="http://carnivore.it/2010/07/22/python_-_getifaddrs"/>
                <rdf:li rdf:resource="http://carnivore.it/2010/07/03/git-daemon_logfile_processing"/>
                <rdf:li rdf:resource="http://carnivore.it/2010/07/01/research.microsoft.com_-_mss_of_536_bytes"/>
                <rdf:li rdf:resource="http://carnivore.it/2010/06/30/metasploitable"/>
                <rdf:li rdf:resource="http://carnivore.it/2010/06/28/smb_bugs"/>
                <rdf:li rdf:resource="http://carnivore.it/2010/06/19/the_story_of_7867de...3e33e7"/>
                <rdf:li rdf:resource="http://carnivore.it/2010/06/17/netware_smb_remote_stack_overflow"/>
                <rdf:li rdf:resource="http://carnivore.it/2010/06/12/python3_-_ctypes"/>
                <rdf:li rdf:resource="http://carnivore.it/2010/06/11/data_visualisation_-_afterglow"/>
                <rdf:li rdf:resource="http://carnivore.it/2010/06/06/dnsbl_test"/>
                <rdf:li rdf:resource="http://carnivore.it/2010/06/06/data_visualisation"/>
                <rdf:li rdf:resource="http://carnivore.it/2010/05/27/batteries_included"/>
                <rdf:li rdf:resource="http://carnivore.it/2010/05/18/debianization"/>
            </rdf:Seq>
        </items>
    </channel>
    <image rdf:about="http://carnivore.it/lib/images/favicon.ico">
        <title>carnivore news</title>
        <link>http://carnivore.it/</link>
        <url>http://carnivore.it/lib/images/favicon.ico</url>
    </image>
    <item rdf:about="http://carnivore.it/2010/09/06/xlinked">
        <dc:format>text/html</dc:format>
        <dc:date>2010-09-06T21:11:41+02:00</dc:date>
        <title>xlinked</title>
        <link>http://carnivore.it/2010/09/06/xlinked</link>
        <description>


&lt;div class=&quot;level2&quot;&gt;

&lt;p&gt;

Some dionaea related articles worth looking at:
&lt;/p&gt;
&lt;ul&gt;
&lt;li class=&quot;level1&quot;&gt;&lt;div class=&quot;li&quot;&gt; &lt;a href=&quot;https://www.os3.nl/2009-2010/students/kevin_de_kok/idsweek1b&quot; class=&quot;urlextern&quot; title=&quot;https://www.os3.nl/2009-2010/students/kevin_de_kok/idsweek1b&quot;  rel=&quot;nofollow&quot;&gt;Week 1b (Applications)&lt;/a&gt; - very detailed look at dionaea, using different fingerprinting software, touches kippo and honeyd as well.&lt;/div&gt;
&lt;/li&gt;
&lt;li class=&quot;level1&quot;&gt;&lt;div class=&quot;li&quot;&gt; &lt;a href=&quot;http://networkdefense.com.au/2010/08/10/dionaea-update-from-down-under/&quot; class=&quot;urlextern&quot; title=&quot;http://networkdefense.com.au/2010/08/10/dionaea-update-from-down-under/&quot;  rel=&quot;nofollow&quot;&gt;Dionaea update from Down Under&lt;/a&gt; - nice visuals, looking at it you feel urged to buy Microsoft Office and create all your graphs with Excel too.&lt;/div&gt;
&lt;/li&gt;
&lt;li class=&quot;level1&quot;&gt;&lt;div class=&quot;li&quot;&gt; &lt;a href=&quot;http://blog.moep.name/index.php?/archives/2-Detecting-malware-with-dionaea.html&quot; class=&quot;urlextern&quot; title=&quot;http://blog.moep.name/index.php?/archives/2-Detecting-malware-with-dionaea.html&quot;  rel=&quot;nofollow&quot;&gt;Detecting malware with dionaea&lt;/a&gt; - bonus points for explaining readlogsqltree, missed points on the incomplete vlan setup - dionaea part is missing, this might be very interesting for others.&lt;/div&gt;
&lt;/li&gt;
&lt;li class=&quot;level1&quot;&gt;&lt;div class=&quot;li&quot;&gt; &lt;a href=&quot;http://blog.infosanity.co.uk/2009/12/01/new-dionaea-statistics-script/&quot; class=&quot;urlextern&quot; title=&quot;http://blog.infosanity.co.uk/2009/12/01/new-dionaea-statistics-script/&quot;  rel=&quot;nofollow&quot;&gt;Infosanity&amp;#039;s dionaea statistics script&lt;/a&gt; - a golden oldies, but being unsure if I linked it already, better be safe then sorry.&lt;/div&gt;
&lt;/li&gt;
&lt;li class=&quot;level1&quot;&gt;&lt;div class=&quot;li&quot;&gt; &lt;a href=&quot;http://lhs.loria.fr/index.php?option=com_content&amp;amp;view=article&amp;amp;id=94&amp;amp;Itemid=84&quot; class=&quot;urlextern&quot; title=&quot;http://lhs.loria.fr/index.php?option=com_content&amp;amp;view=article&amp;amp;id=94&amp;amp;Itemid=84&quot;  rel=&quot;nofollow&quot;&gt;Network Security Monitoring Infrastructure&lt;/a&gt; - some larger deployment, looks nice, unfortunately larger deployers never come up with issues, bugs anything.&lt;/div&gt;
&lt;/li&gt;
&lt;li class=&quot;level1&quot;&gt;&lt;div class=&quot;li&quot;&gt; &lt;a href=&quot;http://www.prowling.nu/&quot; class=&quot;urlextern&quot; title=&quot;http://www.prowling.nu/&quot;  rel=&quot;nofollow&quot;&gt;OpenIDS is alive&lt;/a&gt; - if you are interested in porting dionaea to OpenBSD, OpenIDS wants to distribute dionaea on OpenBSD.&lt;/div&gt;
&lt;/li&gt;
&lt;li class=&quot;level1&quot;&gt;&lt;div class=&quot;li&quot;&gt; &lt;a href=&quot;http://jbmoore61.blogspot.com/2010/08/dionaea-first-impressions.html&quot; class=&quot;urlextern&quot; title=&quot;http://jbmoore61.blogspot.com/2010/08/dionaea-first-impressions.html&quot;  rel=&quot;nofollow&quot;&gt;dionaea first impressions&lt;/a&gt; - he did not read the docs on sqlite, and not on logrotate, but there is useful information in the comments.&lt;/div&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;/div&gt;

&lt;p&gt;
    &lt;small&gt;
        This blog post was created on 2010-09-06 at 21:11                    and last modified on 2010-09-06 at 21:11                by
        Markus.
            &lt;/small&gt;
&lt;/p&gt;
</description>
    </item>
    <item rdf:about="http://carnivore.it/2010/08/27/attacks_on_mssql">
        <dc:format>text/html</dc:format>
        <dc:date>2010-08-27T15:13:47+02:00</dc:date>
        <title>Attacks on MSSQL</title>
        <link>http://carnivore.it/2010/08/27/attacks_on_mssql</link>
        <description>


&lt;div class=&quot;level2&quot;&gt;

&lt;p&gt;

Even though I&amp;#039;m not the only &lt;a href=&quot;http://www.securelist.com/en/blog/292/Who_needs_my_SQL_server&quot; class=&quot;urlextern&quot; title=&quot;http://www.securelist.com/en/blog/292/Who_needs_my_SQL_server&quot;  rel=&quot;nofollow&quot;&gt;reporting attacks on MSSQL&lt;/a&gt;, I&amp;#039;ve had no &lt;em&gt;shiny&lt;/em&gt; attacks addressing &lt;a href=&quot;http://carnivore.it/2010/08/25/gsoc_2010&quot; class=&quot;wikilink1&quot; title=&quot;2010:08:25:gsoc_2010&quot;&gt;the brand new mssql code for dionaea&lt;/a&gt; yet, I think due to protocol bugs. But I&amp;#039;ve had some nfq gathered bistreams which could be replayed to the mssql service.
&lt;/p&gt;

&lt;p&gt;
The bistream replayed was collected on 2010-08-09 and was &lt;em&gt;contributed&lt;/em&gt; by 182.236.160.29 to my port 1433/tcp. I choose this bistream for its size, which is 245625bytes, and the largest bistream I captured for mssql.
&lt;/p&gt;

&lt;p&gt;
After resolving some issues, I was able to dump the commands send to the database into a text file.

&lt;/div&gt;
&lt;div class=&quot;level2&quot;&gt;

&lt;p&gt;
&lt;span class=&quot;curid&quot;&gt;&lt;a href=&quot;http://carnivore.it/2010/08/27/attacks_on_mssql#readmore_2010_08_27_attacks_on_mssql&quot; class=&quot;wikilink1&quot; title=&quot;2010:08:27:attacks_on_mssql&quot;&gt;Read more…&lt;/a&gt;&lt;/span&gt;
&lt;/p&gt;

&lt;/div&gt;

&lt;p&gt;
    &lt;small&gt;
        This blog post was created on 2010-08-27 at 15:13                    and last modified on 2010-08-27 at 15:14                by
        Markus.
                    It is tagged with &lt;a href=&quot;http://carnivore.it/?btng[post][tags]=dionaea&quot; class=&quot;tag&quot;&gt;dionaea&lt;/a&gt;, &lt;a href=&quot;http://carnivore.it/?btng[post][tags]=mssql&quot; class=&quot;tag&quot;&gt;mssql&lt;/a&gt;.
            &lt;/small&gt;
&lt;/p&gt;
</description>
    </item>
    <item rdf:about="http://carnivore.it/2010/08/25/gsoc_2010">
        <dc:format>text/html</dc:format>
        <dc:date>2010-08-25T15:05:26+02:00</dc:date>
        <title>GSoC 2010</title>
        <link>http://carnivore.it/2010/08/25/gsoc_2010</link>
        <description>


&lt;div class=&quot;level2&quot;&gt;

&lt;p&gt;
Within the umbrella of &lt;a href=&quot;http://www.honeynet.org&quot; class=&quot;urlextern&quot; title=&quot;http://www.honeynet.org&quot;  rel=&quot;nofollow&quot;&gt;The Honeynet Project&lt;/a&gt; I&amp;#039;ve had two students working on dionaea as a GSoC2010 project this year.
The projects were:
&lt;/p&gt;
&lt;ul&gt;
&lt;li class=&quot;level1&quot;&gt;&lt;div class=&quot;li&quot;&gt; a basic SIP stack for dionaea&lt;/div&gt;
&lt;/li&gt;
&lt;li class=&quot;level1&quot;&gt;&lt;div class=&quot;li&quot;&gt; improvements on the current SMB stack&lt;/div&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;/div&gt;
&lt;!-- SECTION &quot;GSoC 2010&quot; [11-276] --&gt;
&lt;h3&gt;&lt;a name=&quot;dionaea_-_smb&quot; id=&quot;dionaea_-_smb&quot;&gt;dionaea - SMB&lt;/a&gt;&lt;/h3&gt;
&lt;div class=&quot;level3&quot;&gt;

&lt;p&gt;

For today, let&amp;#039;s focus on the SMB stack improvements.&lt;br/&gt;


&lt;/div&gt;
&lt;div class=&quot;level2&quot;&gt;

&lt;p&gt;
&lt;span class=&quot;curid&quot;&gt;&lt;a href=&quot;http://carnivore.it/2010/08/25/gsoc_2010#readmore_2010_08_25_gsoc_2010&quot; class=&quot;wikilink1&quot; title=&quot;2010:08:25:gsoc_2010&quot;&gt;Read more…&lt;/a&gt;&lt;/span&gt;
&lt;/p&gt;

&lt;/div&gt;

&lt;p&gt;
    &lt;small&gt;
        This blog post was created on 2010-08-25 at 15:05                    and last modified on 2010-08-25 at 15:06                by
        Markus.
                    It is tagged with &lt;a href=&quot;http://carnivore.it/?btng[post][tags]=dionaea&quot; class=&quot;tag&quot;&gt;dionaea&lt;/a&gt;, &lt;a href=&quot;http://carnivore.it/?btng[post][tags]=gsoc&quot; class=&quot;tag&quot;&gt;gsoc&lt;/a&gt;, &lt;a href=&quot;http://carnivore.it/?btng[post][tags]=mssql&quot; class=&quot;tag&quot;&gt;mssql&lt;/a&gt;, &lt;a href=&quot;http://carnivore.it/?btng[post][tags]=smb&quot; class=&quot;tag&quot;&gt;smb&lt;/a&gt;.
            &lt;/small&gt;
&lt;/p&gt;
</description>
    </item>
    <item rdf:about="http://carnivore.it/2010/08/20/stun_cli_firewallping">
        <dc:format>text/html</dc:format>
        <dc:date>2010-08-20T11:00:24+02:00</dc:date>
        <title>STUN_CLI_FIREWALLPING</title>
        <link>http://carnivore.it/2010/08/20/stun_cli_firewallping</link>
        <description>


&lt;div class=&quot;level2&quot;&gt;

&lt;p&gt;

As &lt;a href=&quot;http://carnivore.it/2010/08/06/nfq_fun#akamai_-_rsp10&quot; class=&quot;wikilink1&quot; title=&quot;2010:08:06:nfq_fun&quot;&gt;mentioned earlier&lt;/a&gt;, &lt;em&gt;I can see strange packets&lt;/em&gt;.&lt;br/&gt;

And I&amp;#039;m looking for others who share this phenomenon.
&lt;/p&gt;

&lt;p&gt;
The content of this strange packets is this:

&lt;/p&gt;
&lt;pre class=&quot;code&quot;&gt;
RSP/1.0 STUN_CLI_FIREWALLPING
aguid:f8923c21083c4bb69e462f8ace0e6e0d


&lt;/pre&gt;

&lt;p&gt;


&lt;/div&gt;
&lt;div class=&quot;level2&quot;&gt;

&lt;p&gt;
&lt;span class=&quot;curid&quot;&gt;&lt;a href=&quot;http://carnivore.it/2010/08/20/stun_cli_firewallping#readmore_2010_08_20_stun_cli_firewallping&quot; class=&quot;wikilink1&quot; title=&quot;2010:08:20:stun_cli_firewallping&quot;&gt;Read more…&lt;/a&gt;&lt;/span&gt;
&lt;/p&gt;

&lt;/div&gt;

&lt;p&gt;
    &lt;small&gt;
        This blog post was created on 2010-08-20 at 11:00                    and last modified on 2010-08-20 at 11:03                by
        Markus.
            &lt;/small&gt;
&lt;/p&gt;
</description>
    </item>
    <item rdf:about="http://carnivore.it/2010/08/19/metasploit_os_fingerprinting_via_smb">
        <dc:format>text/html</dc:format>
        <dc:date>2010-08-19T10:32:05+02:00</dc:date>
        <title>Metasploit Fingerprinting</title>
        <link>http://carnivore.it/2010/08/19/metasploit_os_fingerprinting_via_smb</link>
        <description>


&lt;div class=&quot;level2&quot;&gt;

&lt;p&gt;

&lt;em&gt; This article was written by &lt;a href=&quot;http://g3nto.blogspot.com/&quot; class=&quot;urlextern&quot; title=&quot;http://g3nto.blogspot.com/&quot;  rel=&quot;nofollow&quot;&gt;Tan Kean Siong&lt;/a&gt; during his gsoc2010 project - improving dionaeas smb stack - I just fixed some typos and formatted it - Markus &lt;/em&gt;
&lt;/p&gt;

&lt;p&gt;
The Metasploit Framework is one of the most popular open source penetration testing framework with the world&amp;#039;s largest database of public, tested exploits. Metasploit was created in 2003 using the &lt;acronym title=&quot;Practical Extraction and Report Language&quot;&gt;Perl&lt;/acronym&gt; scripting language, lateron the framework was rewritten in the Ruby programming language.&lt;br/&gt;

The usage of the framework is user-friendly and the exploitation can be done by the workflow of:
&lt;/p&gt;
&lt;ul&gt;
&lt;li class=&quot;level1&quot;&gt;&lt;div class=&quot;li&quot;&gt; choosing the exploit&lt;/div&gt;
&lt;/li&gt;
&lt;li class=&quot;level1&quot;&gt;&lt;div class=&quot;li&quot;&gt; configuring the payload &lt;/div&gt;
&lt;/li&gt;
&lt;li class=&quot;level1&quot;&gt;&lt;div class=&quot;li&quot;&gt; execute the exploit. &lt;/div&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;
This modularity, allowing all combinations of any exploit with any payload is the major advantage of the Framework. It facilitates the tasks of attackers, exploit writers, and payload writers, thus it emerge as the de facto vulnerability development framework in these days.
&lt;/p&gt;

&lt;p&gt;
During the exploitation process, it is often required to know the exact version of the target’s operating system. Often exploits need to be customized to adapt to the particular &lt;acronym title=&quot;Operating System&quot;&gt;OS&lt;/acronym&gt; environment, therefore knowing the remote operating system increase success rate of the attack.
Metasploit has includes comprehensive &lt;acronym title=&quot;Operating System&quot;&gt;OS&lt;/acronym&gt; fingerprinting support for the Microsoft Windows operating system. 
Metasploit can retrieve:
&lt;/p&gt;
&lt;ul&gt;
&lt;li class=&quot;level1&quot;&gt;&lt;div class=&quot;li&quot;&gt; the version of the operating system&lt;/div&gt;
&lt;/li&gt;
&lt;li class=&quot;level1&quot;&gt;&lt;div class=&quot;li&quot;&gt; version of the service pack&lt;/div&gt;
&lt;/li&gt;
&lt;li class=&quot;level1&quot;&gt;&lt;div class=&quot;li&quot;&gt; and the installed network services. &lt;/div&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;

Dionaea need to support these fingerprinting method, as malware may adapt this remote version fingerprinting in the future.

&lt;/div&gt;
&lt;div class=&quot;level2&quot;&gt;

&lt;p&gt;
&lt;span class=&quot;curid&quot;&gt;&lt;a href=&quot;http://carnivore.it/2010/08/19/metasploit_os_fingerprinting_via_smb#readmore_2010_08_19_metasploit_os_fingerprinting_via_smb&quot; class=&quot;wikilink1&quot; title=&quot;2010:08:19:metasploit_os_fingerprinting_via_smb&quot;&gt;Read more…&lt;/a&gt;&lt;/span&gt;
&lt;/p&gt;

&lt;/div&gt;

&lt;p&gt;
    &lt;small&gt;
        This blog post was created on 2010-08-19 at 10:32                by
        Markus.
                    It is tagged with &lt;a href=&quot;http://carnivore.it/?btng[post][tags]=dionaea&quot; class=&quot;tag&quot;&gt;dionaea&lt;/a&gt;, &lt;a href=&quot;http://carnivore.it/?btng[post][tags]=metasploit&quot; class=&quot;tag&quot;&gt;metasploit&lt;/a&gt;, &lt;a href=&quot;http://carnivore.it/?btng[post][tags]=smb&quot; class=&quot;tag&quot;&gt;smb&lt;/a&gt;.
            &lt;/small&gt;
&lt;/p&gt;
</description>
    </item>
    <item rdf:about="http://carnivore.it/2010/08/06/nfq_fun">
        <dc:format>text/html</dc:format>
        <dc:date>2010-08-06T22:40:01+02:00</dc:date>
        <title>nfq fun</title>
        <link>http://carnivore.it/2010/08/06/nfq_fun</link>
        <description>


&lt;div class=&quot;level2&quot;&gt;

&lt;p&gt;

As early adaptor I currently enjoy the nfq module for dionaea.

&lt;/div&gt;
&lt;div class=&quot;level2&quot;&gt;

&lt;p&gt;
&lt;span class=&quot;curid&quot;&gt;&lt;a href=&quot;http://carnivore.it/2010/08/06/nfq_fun#readmore_2010_08_06_nfq_fun&quot; class=&quot;wikilink1&quot; title=&quot;2010:08:06:nfq_fun&quot;&gt;Read more…&lt;/a&gt;&lt;/span&gt;
&lt;/p&gt;

&lt;/div&gt;

&lt;p&gt;
    &lt;small&gt;
        This blog post was created on 2010-08-06 at 22:40                    and last modified on 2010-08-06 at 22:42                by
        Markus.
                    It is tagged with &lt;a href=&quot;http://carnivore.it/?btng[post][tags]=dionaea&quot; class=&quot;tag&quot;&gt;dionaea&lt;/a&gt;, &lt;a href=&quot;http://carnivore.it/?btng[post][tags]=iptables&quot; class=&quot;tag&quot;&gt;iptables&lt;/a&gt;, &lt;a href=&quot;http://carnivore.it/?btng[post][tags]=mssql&quot; class=&quot;tag&quot;&gt;mssql&lt;/a&gt;, &lt;a href=&quot;http://carnivore.it/?btng[post][tags]=nfq&quot; class=&quot;tag&quot;&gt;nfq&lt;/a&gt;, &lt;a href=&quot;http://carnivore.it/?btng[post][tags]=remotedesktop&quot; class=&quot;tag&quot;&gt;remotedesktop&lt;/a&gt;, &lt;a href=&quot;http://carnivore.it/?btng[post][tags]=rsp&quot; class=&quot;tag&quot;&gt;rsp&lt;/a&gt;, &lt;a href=&quot;http://carnivore.it/?btng[post][tags]=symantec&quot; class=&quot;tag&quot;&gt;symantec&lt;/a&gt;.
            &lt;/small&gt;
&lt;/p&gt;
</description>
    </item>
    <item rdf:about="http://carnivore.it/2010/07/30/getting_over_dect">
        <dc:format>text/html</dc:format>
        <dc:date>2010-07-30T20:31:59+02:00</dc:date>
        <title>getting over dect</title>
        <link>http://carnivore.it/2010/07/30/getting_over_dect</link>
        <description>


&lt;div class=&quot;level2&quot;&gt;

&lt;p&gt;
I noticed my account balance for my voip provider to drop by ~10€ during the last 3 days, even though I did not make that much calls. So I had a look on the list of outgoing calls, which is stored by the provider. The list showed me lots of phone numbers I did not know.&lt;br/&gt;

Looking at the list of connected phones to my account, there were only the phones I used myself, a Grandstream GXP 2000 and a Siemens Gigaset C450 IP DECT phone.
So it was rather obvious somebody else was connected to the base station of my C450 DECT phone, making calls on my costs.
&lt;/p&gt;

&lt;p&gt;
&lt;em&gt;If the laws would have permitted it, I might have setup tcpdump on the gate, capturing all traffic from and to the C450 base station.&lt;/em&gt;
&lt;/p&gt;

&lt;p&gt;
I wanted this person to pay for his calls, so my first step was looking at the numbers he called, by comparing the numbers with numbers from my own phone book, this was really time consuming, and in the end he owned more than 95% of all calls.
&lt;/p&gt;

&lt;p&gt;
I noticed a lengthy call to a number which was known by google, and associated with a sex toy shops telephone order service, and lots of calls to a single mobile number.
&lt;/p&gt;

&lt;p&gt;
&lt;em&gt;If the laws would have permitted it, I&amp;#039;d have copied the pcap file from the router to a desktop with wireshark installed, and using wiresharks great VoIP replay, the conversation could have revealed the unknown person using my base station ordered drugs for 30€, the drug dealer complained about the bad quality, where the unknown replied he was using a wifi-phone.&lt;/em&gt;
&lt;/p&gt;

&lt;p&gt;
I tried to &amp;#039;call myself&amp;#039;, hoping his phone would ring too, so I could talk to him about his phone being connected to my base station, but nobody accepted the call.
So, I decided to call the most often called number, using my mobile.
This number turned out to be the unknowns girlfriend, who got really cooperative when I mentioned &lt;em&gt;the police&lt;/em&gt;, she turned over her boyfriends address.
&lt;/p&gt;

&lt;p&gt;
Some minutes after the call, the unknown &lt;em&gt;tried&lt;/em&gt; to call me on my mobile, but he dialed the wrong number.
&lt;/p&gt;

&lt;p&gt;
&lt;em&gt;If the laws would have permitted it, I&amp;#039;d have listend to this call by using wireshark on the pcap. Somebody calling an unknown, telling a story about his girlfriend calling him, claiming she was called by an unknown who said somebody who called he was using his phone, while the called always said he did not know anything about &amp;#039;phone&amp;#039; but could get his own girlfriend on the phone. It would have been a hilarious dialogue.&lt;/em&gt;
&lt;/p&gt;

&lt;p&gt;
So, having his address, and the amount he owed me, I decided to give the unknown a visit.&lt;br/&gt;

He was expecting me, and even tipped me for my time spent on this.&lt;br/&gt;

The phone he used was a &lt;em&gt;Fritz!Fon MT-F&lt;/em&gt;, which connected to my base station right after one turned it on.
&lt;/p&gt;

&lt;p&gt;
After making sure there is no way to see the associated handsets on my C450 IP base station, I decided to get over DECT, turning the base station off.
&lt;/p&gt;

&lt;/div&gt;

&lt;p&gt;
    &lt;small&gt;
        This blog post was created on 2010-07-30 at 20:31                by
        Markus.
                    It is tagged with &lt;a href=&quot;http://carnivore.it/?btng[post][tags]=dect&quot; class=&quot;tag&quot;&gt;dect&lt;/a&gt;.
            &lt;/small&gt;
&lt;/p&gt;
</description>
    </item>
    <item rdf:about="http://carnivore.it/2010/07/22/python_-_getifaddrs">
        <dc:format>text/html</dc:format>
        <dc:date>2010-07-22T01:21:18+02:00</dc:date>
        <title>python - getifaddrs</title>
        <link>http://carnivore.it/2010/07/22/python_-_getifaddrs</link>
        <description>


&lt;div class=&quot;level2&quot;&gt;

&lt;p&gt;

For whatever reason python lacks a binding for &lt;a href=&quot;http://www.kernel.org/doc/man-pages/online/pages/man3/getifaddrs.3.html&quot; class=&quot;urlextern&quot; title=&quot;http://www.kernel.org/doc/man-pages/online/pages/man3/getifaddrs.3.html&quot;  rel=&quot;nofollow&quot;&gt;getifaddrs&lt;/a&gt;. For dionaea I created the binding myself, but the code can not be used without dionaea, and I don&amp;#039;t like having to install additional bindings to get some basic functionality.&lt;br/&gt;

Therefore, I decided to create the functionality provided by the dionaea getifaddrs binding using python ctypes, easy to &lt;em&gt;install&lt;/em&gt;, no compiling, copy&amp;amp;paste does the trick.
&lt;/p&gt;

&lt;p&gt;
The code works with python2/3, Linux works, Darwin/OSX may work, Windows? good question.&lt;br/&gt;


&lt;/div&gt;
&lt;div class=&quot;level2&quot;&gt;

&lt;p&gt;
&lt;span class=&quot;curid&quot;&gt;&lt;a href=&quot;http://carnivore.it/2010/07/22/python_-_getifaddrs#readmore_2010_07_22_python_-_getifaddrs&quot; class=&quot;wikilink1&quot; title=&quot;2010:07:22:python_-_getifaddrs&quot;&gt;Read more…&lt;/a&gt;&lt;/span&gt;
&lt;/p&gt;

&lt;/div&gt;

&lt;p&gt;
    &lt;small&gt;
        This blog post was created on 2010-07-22 at 01:21                by
        Markus.
                    It is tagged with &lt;a href=&quot;http://carnivore.it/?btng[post][tags]=ctypes&quot; class=&quot;tag&quot;&gt;ctypes&lt;/a&gt;, &lt;a href=&quot;http://carnivore.it/?btng[post][tags]=python3&quot; class=&quot;tag&quot;&gt;python3&lt;/a&gt;.
            &lt;/small&gt;
&lt;/p&gt;
</description>
    </item>
    <item rdf:about="http://carnivore.it/2010/07/03/git-daemon_logfile_processing">
        <dc:format>text/html</dc:format>
        <dc:date>2010-07-03T15:15:04+02:00</dc:date>
        <title>git-daemon logfile processing</title>
        <link>http://carnivore.it/2010/07/03/git-daemon_logfile_processing</link>
        <description>


&lt;div class=&quot;level2&quot;&gt;

&lt;p&gt;
&lt;a href=&quot;http://carnivore.it/_detail/2010/07/03/dionaea-git.png?id=2010%3A07%3A03%3Agit-daemon_logfile_processing&quot; class=&quot;media&quot; title=&quot;2010:07:03:dionaea-git.png&quot;&gt;&lt;img src=&quot;http://carnivore.it/_media/2010/07/03/dionaea-git.png&quot; class=&quot;media&quot; title=&quot;dionaea git useage&quot; alt=&quot;dionaea git useage&quot; /&gt;&lt;/a&gt;&lt;br/&gt;

&lt;em&gt;the git-daemon activity for the dionaea.git repository, pull and uniq hosts/day, basically 5-10 users update their software daily.&lt;/em&gt;
&lt;/p&gt;

&lt;p&gt;
Often the most complex part in data visualization is the processing before you can provide the data in a format your visualization software understands.&lt;br/&gt;

I choose the git-daemon logs as an example of such an case.&lt;br/&gt;

One could have used sshd logs as an example too, but I choose this, as I&amp;#039;m pretty sure there is no parser for the git-daemon logfiles.
In doubt, I&amp;#039;m pretty confident, one could adjust this git-daemon parser to deal with sshd too.
&lt;/p&gt;

&lt;p&gt;

&lt;/div&gt;
&lt;div class=&quot;level2&quot;&gt;

&lt;p&gt;
&lt;span class=&quot;curid&quot;&gt;&lt;a href=&quot;http://carnivore.it/2010/07/03/git-daemon_logfile_processing#readmore_2010_07_03_git-daemon_logfile_processing&quot; class=&quot;wikilink1&quot; title=&quot;2010:07:03:git-daemon_logfile_processing&quot;&gt;Read more…&lt;/a&gt;&lt;/span&gt;
&lt;/p&gt;

&lt;/div&gt;

&lt;p&gt;
    &lt;small&gt;
        This blog post was created on 2010-07-03 at 15:15                by
        Markus.
                    It is tagged with &lt;a href=&quot;http://carnivore.it/?btng[post][tags]=dataviz&quot; class=&quot;tag&quot;&gt;dataviz&lt;/a&gt;, &lt;a href=&quot;http://carnivore.it/?btng[post][tags]=gnuplot&quot; class=&quot;tag&quot;&gt;gnuplot&lt;/a&gt;, &lt;a href=&quot;http://carnivore.it/?btng[post][tags]=python3&quot; class=&quot;tag&quot;&gt;python3&lt;/a&gt;, &lt;a href=&quot;http://carnivore.it/?btng[post][tags]=sqlite&quot; class=&quot;tag&quot;&gt;sqlite&lt;/a&gt;.
            &lt;/small&gt;
&lt;/p&gt;
</description>
    </item>
    <item rdf:about="http://carnivore.it/2010/07/01/research.microsoft.com_-_mss_of_536_bytes">
        <dc:format>text/html</dc:format>
        <dc:date>2010-07-01T14:09:09+02:00</dc:date>
        <title>research.microsoft.com - MSS of 536 bytes</title>
        <link>http://carnivore.it/2010/07/01/research.microsoft.com_-_mss_of_536_bytes</link>
        <description>


&lt;div class=&quot;level2&quot;&gt;

&lt;p&gt;

A friend of mine recently tried to visit &lt;a href=&quot;http://research.microsoft.com&quot; class=&quot;urlextern&quot; title=&quot;http://research.microsoft.com&quot;  rel=&quot;nofollow&quot;&gt;research.microsoft.com&lt;/a&gt;, he was unable to.
He spent some time on it, and came up with the following scenario:

&lt;/p&gt;
&lt;ul&gt;
&lt;li class=&quot;level1&quot;&gt;&lt;div class=&quot;li&quot;&gt; linux router with pmtu clamping&lt;/div&gt;
&lt;ul&gt;
&lt;li class=&quot;level2&quot;&gt;&lt;div class=&quot;li&quot;&gt; linux client does not work&lt;/div&gt;
&lt;/li&gt;
&lt;li class=&quot;level2&quot;&gt;&lt;div class=&quot;li&quot;&gt; windows client works&lt;/div&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li class=&quot;level1&quot;&gt;&lt;div class=&quot;li&quot;&gt; linux router with conditional pmtu clamping (if the mss is within 1400:1536)&lt;/div&gt;
&lt;ul&gt;
&lt;li class=&quot;level2&quot;&gt;&lt;div class=&quot;li&quot;&gt; linux client works&lt;/div&gt;
&lt;/li&gt;
&lt;li class=&quot;level2&quot;&gt;&lt;div class=&quot;li&quot;&gt; windows client works&lt;/div&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;

I could reproduce this myself, for my setup &lt;a href=&quot;http://research.microsoft.com&quot; class=&quot;urlextern&quot; title=&quot;http://research.microsoft.com&quot;  rel=&quot;nofollow&quot;&gt;research.microsoft.com&lt;/a&gt; did not work too, but I felt I would not loose too much anyway.
&lt;/p&gt;

&lt;p&gt;
After some time he provided some pcap dumps for all possible combinations and scenarios, so I felt guilty and finally gave it a shot.
&lt;/p&gt;

&lt;p&gt;
So what is wrong with &lt;a href=&quot;http://research.microsoft.com&quot; class=&quot;urlextern&quot; title=&quot;http://research.microsoft.com&quot;  rel=&quot;nofollow&quot;&gt;research.microsoft.com&lt;/a&gt;?
&lt;/p&gt;

&lt;p&gt;

&lt;/div&gt;
&lt;div class=&quot;level2&quot;&gt;

&lt;p&gt;
&lt;span class=&quot;curid&quot;&gt;&lt;a href=&quot;http://carnivore.it/2010/07/01/research.microsoft.com_-_mss_of_536_bytes#readmore_2010_07_01_researchmicrosoftcom_-_mss_of_536_bytes&quot; class=&quot;wikilink1&quot; title=&quot;2010:07:01:research.microsoft.com_-_mss_of_536_bytes&quot;&gt;Read more…&lt;/a&gt;&lt;/span&gt;
&lt;/p&gt;

&lt;/div&gt;

&lt;p&gt;
    &lt;small&gt;
        This blog post was created on 2010-07-01 at 14:09                    and last modified on 2010-07-01 at 14:18                by
        Markus.
                    It is tagged with &lt;a href=&quot;http://carnivore.it/?btng[post][tags]=icmp&quot; class=&quot;tag&quot;&gt;icmp&lt;/a&gt;, &lt;a href=&quot;http://carnivore.it/?btng[post][tags]=microsoft&quot; class=&quot;tag&quot;&gt;microsoft&lt;/a&gt;, &lt;a href=&quot;http://carnivore.it/?btng[post][tags]=mss&quot; class=&quot;tag&quot;&gt;mss&lt;/a&gt;, &lt;a href=&quot;http://carnivore.it/?btng[post][tags]=pmtu&quot; class=&quot;tag&quot;&gt;pmtu&lt;/a&gt;.
            &lt;/small&gt;
&lt;/p&gt;
</description>
    </item>
    <item rdf:about="http://carnivore.it/2010/06/30/metasploitable">
        <dc:format>text/html</dc:format>
        <dc:date>2010-06-30T09:24:18+02:00</dc:date>
        <title>metasploitable</title>
        <link>http://carnivore.it/2010/06/30/metasploitable</link>
        <description>


&lt;div class=&quot;level2&quot;&gt;

&lt;p&gt;

Current dionaea trunk is metasploitable.
&lt;/p&gt;

&lt;p&gt;
Getting this working was pretty nasty:
&lt;/p&gt;
&lt;ul&gt;
&lt;li class=&quot;level1&quot;&gt;&lt;div class=&quot;li&quot;&gt; metasploit tries to authenticate using GSS-&lt;acronym title=&quot;Application Programming Interface&quot;&gt;API&lt;/acronym&gt;&lt;/div&gt;
&lt;ul&gt;
&lt;li class=&quot;level2&quot;&gt;&lt;div class=&quot;li&quot;&gt; GSS-&lt;acronym title=&quot;Application Programming Interface&quot;&gt;API&lt;/acronym&gt; requires ASN1 and embedds SPNEGO&lt;/div&gt;
&lt;ul&gt;
&lt;li class=&quot;level3&quot;&gt;&lt;div class=&quot;li&quot;&gt; SPNEGO requires ASN1 parsing, and embedds NTLMSSP&lt;/div&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;


&lt;/div&gt;
&lt;div class=&quot;level2&quot;&gt;

&lt;p&gt;
&lt;span class=&quot;curid&quot;&gt;&lt;a href=&quot;http://carnivore.it/2010/06/30/metasploitable#readmore_2010_06_30_metasploitable&quot; class=&quot;wikilink1&quot; title=&quot;2010:06:30:metasploitable&quot;&gt;Read more…&lt;/a&gt;&lt;/span&gt;
&lt;/p&gt;

&lt;/div&gt;

&lt;p&gt;
    &lt;small&gt;
        This blog post was created on 2010-06-30 at 09:24                    and last modified on 2010-06-30 at 16:13                by
        Markus.
                    It is tagged with &lt;a href=&quot;http://carnivore.it/?btng[post][tags]=dionaea&quot; class=&quot;tag&quot;&gt;dionaea&lt;/a&gt;, &lt;a href=&quot;http://carnivore.it/?btng[post][tags]=gss-api&quot; class=&quot;tag&quot;&gt;gss-api&lt;/a&gt;, &lt;a href=&quot;http://carnivore.it/?btng[post][tags]=metasploit&quot; class=&quot;tag&quot;&gt;metasploit&lt;/a&gt;, &lt;a href=&quot;http://carnivore.it/?btng[post][tags]=ntlm&quot; class=&quot;tag&quot;&gt;ntlm&lt;/a&gt;, &lt;a href=&quot;http://carnivore.it/?btng[post][tags]=spnego&quot; class=&quot;tag&quot;&gt;spnego&lt;/a&gt;.
            &lt;/small&gt;
&lt;/p&gt;
</description>
    </item>
    <item rdf:about="http://carnivore.it/2010/06/28/smb_bugs">
        <dc:format>text/html</dc:format>
        <dc:date>2010-06-28T10:34:32+02:00</dc:date>
        <title>smb bugs</title>
        <link>http://carnivore.it/2010/06/28/smb_bugs</link>
        <description>


&lt;div class=&quot;level2&quot;&gt;

&lt;p&gt;

While messing with the protocol, I found 2 bugs in smb client implementations, nothing fancy, but I really appreciate buggy implementations of this protocol, therefore …

&lt;/div&gt;
&lt;div class=&quot;level2&quot;&gt;

&lt;p&gt;
&lt;span class=&quot;curid&quot;&gt;&lt;a href=&quot;http://carnivore.it/2010/06/28/smb_bugs#readmore_2010_06_28_smb_bugs&quot; class=&quot;wikilink1&quot; title=&quot;2010:06:28:smb_bugs&quot;&gt;Read more…&lt;/a&gt;&lt;/span&gt;
&lt;/p&gt;

&lt;/div&gt;

&lt;p&gt;
    &lt;small&gt;
        This blog post was created on 2010-06-28 at 10:34                    and last modified on 2010-06-28 at 16:56                by
        Markus.
                    It is tagged with &lt;a href=&quot;http://carnivore.it/?btng[post][tags]=metasploit&quot; class=&quot;tag&quot;&gt;metasploit&lt;/a&gt;, &lt;a href=&quot;http://carnivore.it/?btng[post][tags]=nmap&quot; class=&quot;tag&quot;&gt;nmap&lt;/a&gt;, &lt;a href=&quot;http://carnivore.it/?btng[post][tags]=smb&quot; class=&quot;tag&quot;&gt;smb&lt;/a&gt;.
            &lt;/small&gt;
&lt;/p&gt;
</description>
    </item>
    <item rdf:about="http://carnivore.it/2010/06/19/the_story_of_7867de...3e33e7">
        <dc:format>text/html</dc:format>
        <dc:date>2010-06-20T12:12:48+02:00</dc:date>
        <title>the story of 7867de...3e33e7</title>
        <link>http://carnivore.it/2010/06/19/the_story_of_7867de...3e33e7</link>
        <description>


&lt;div class=&quot;level2&quot;&gt;

&lt;/div&gt;
&lt;!-- SECTION &quot;the story of 7867de...3e33e7&quot; [11-54] --&gt;
&lt;h3&gt;&lt;a name=&quot;getting_the_file&quot; id=&quot;getting_the_file&quot;&gt;getting the file&lt;/a&gt;&lt;/h3&gt;
&lt;div class=&quot;level3&quot;&gt;

&lt;p&gt;
Some days ago I pushed some code to store files which get uploaded via smb file sharing to dionaea.&lt;br/&gt;

Yesterday I merged some beautified dce rpc code which was written by Tan Kean Siong during his gsoc 2010 dionaea-project.&lt;br/&gt;

Today, I got some captures which may provide some assistance when looking at dionaea log files.&lt;br/&gt;


&lt;/div&gt;
&lt;div class=&quot;level2&quot;&gt;

&lt;p&gt;
&lt;span class=&quot;curid&quot;&gt;&lt;a href=&quot;http://carnivore.it/2010/06/19/the_story_of_7867de...3e33e7#readmore_2010_06_19_the_story_of_7867de3e33e7&quot; class=&quot;wikilink1&quot; title=&quot;2010:06:19:the_story_of_7867de...3e33e7&quot;&gt;Read more…&lt;/a&gt;&lt;/span&gt;
&lt;/p&gt;

&lt;/div&gt;

&lt;p&gt;
    &lt;small&gt;
        This blog post was created on 2010-06-20 at 12:12                    and last modified on 2010-06-20 at 12:14                by
        Markus.
                    It is tagged with &lt;a href=&quot;http://carnivore.it/?btng[post][tags]=dionaea&quot; class=&quot;tag&quot;&gt;dionaea&lt;/a&gt;, &lt;a href=&quot;http://carnivore.it/?btng[post][tags]=gsoc2010&quot; class=&quot;tag&quot;&gt;gsoc2010&lt;/a&gt;, &lt;a href=&quot;http://carnivore.it/?btng[post][tags]=smb&quot; class=&quot;tag&quot;&gt;smb&lt;/a&gt;.
            &lt;/small&gt;
&lt;/p&gt;
</description>
    </item>
    <item rdf:about="http://carnivore.it/2010/06/17/netware_smb_remote_stack_overflow">
        <dc:format>text/html</dc:format>
        <dc:date>2010-06-17T09:41:10+02:00</dc:date>
        <title>Netware SMB Remote Stack Overflow</title>
        <link>http://carnivore.it/2010/06/17/netware_smb_remote_stack_overflow</link>
        <description>


&lt;div class=&quot;level2&quot;&gt;

&lt;p&gt;

I just had a look on the Novell Netware exploit published by Laurent Gaffié, and I&amp;#039;m glad other people have problems parsing smb correctly too.
Contrary to other exploit - addressing Microsofts SMB stack - this one exploits a parsing bug instead of a DCE Remote Procedure Call.

&lt;/div&gt;
&lt;div class=&quot;level2&quot;&gt;

&lt;p&gt;
&lt;span class=&quot;curid&quot;&gt;&lt;a href=&quot;http://carnivore.it/2010/06/17/netware_smb_remote_stack_overflow#readmore_2010_06_17_netware_smb_remote_stack_overflow&quot; class=&quot;wikilink1&quot; title=&quot;2010:06:17:netware_smb_remote_stack_overflow&quot;&gt;Read more…&lt;/a&gt;&lt;/span&gt;
&lt;/p&gt;

&lt;/div&gt;

&lt;p&gt;
    &lt;small&gt;
        This blog post was created on 2010-06-17 at 09:41                    and last modified on 2010-06-17 at 22:28                by
        Markus.
                    It is tagged with &lt;a href=&quot;http://carnivore.it/?btng[post][tags]=dionaea&quot; class=&quot;tag&quot;&gt;dionaea&lt;/a&gt;, &lt;a href=&quot;http://carnivore.it/?btng[post][tags]=netware&quot; class=&quot;tag&quot;&gt;netware&lt;/a&gt;, &lt;a href=&quot;http://carnivore.it/?btng[post][tags]=smb&quot; class=&quot;tag&quot;&gt;smb&lt;/a&gt;.
            &lt;/small&gt;
&lt;/p&gt;
</description>
    </item>
    <item rdf:about="http://carnivore.it/2010/06/12/python3_-_ctypes">
        <dc:format>text/html</dc:format>
        <dc:date>2010-06-12T19:35:05+02:00</dc:date>
        <title>python3 - ctypes</title>
        <link>http://carnivore.it/2010/06/12/python3_-_ctypes</link>
        <description>


&lt;div class=&quot;level2&quot;&gt;

&lt;/div&gt;
&lt;!-- SECTION &quot;python3 - ctypes&quot; [1-32] --&gt;
&lt;h3&gt;&lt;a name=&quot;ctypes&quot; id=&quot;ctypes&quot;&gt;ctypes&lt;/a&gt;&lt;/h3&gt;
&lt;div class=&quot;level3&quot;&gt;

&lt;p&gt;
If you want to use a native library in python, but there is no binding, you can &amp;#039;try&amp;#039; to interface the library with ctypes.
&lt;/p&gt;

&lt;p&gt;
As I wanted to play with bpf, which is part of libpcap, which lacks a python3 binding, I decided to try ctypes.
&lt;/p&gt;

&lt;p&gt;
What I wanted to do:
&lt;/p&gt;
&lt;ul&gt;
&lt;li class=&quot;level1&quot;&gt;&lt;div class=&quot;li&quot;&gt; compile a bpf filter like &lt;em&gt;dst port 445 and src net 127.0.0.0/8&lt;/em&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;li class=&quot;level1&quot;&gt;&lt;div class=&quot;li&quot;&gt; match the bpf filter on a buffer&lt;/div&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;

&lt;/div&gt;
&lt;div class=&quot;level2&quot;&gt;

&lt;p&gt;
&lt;span class=&quot;curid&quot;&gt;&lt;a href=&quot;http://carnivore.it/2010/06/12/python3_-_ctypes#readmore_2010_06_12_python3_-_ctypes&quot; class=&quot;wikilink1&quot; title=&quot;2010:06:12:python3_-_ctypes&quot;&gt;Read more…&lt;/a&gt;&lt;/span&gt;
&lt;/p&gt;

&lt;/div&gt;

&lt;p&gt;
    &lt;small&gt;
        This blog post was created on 2010-06-12 at 19:35                    and last modified on 2010-06-15 at 03:13                by
        Markus.
                    It is tagged with &lt;a href=&quot;http://carnivore.it/?btng[post][tags]=bpf&quot; class=&quot;tag&quot;&gt;bpf&lt;/a&gt;, &lt;a href=&quot;http://carnivore.it/?btng[post][tags]=ctypes&quot; class=&quot;tag&quot;&gt;ctypes&lt;/a&gt;, &lt;a href=&quot;http://carnivore.it/?btng[post][tags]=pcap&quot; class=&quot;tag&quot;&gt;pcap&lt;/a&gt;, &lt;a href=&quot;http://carnivore.it/?btng[post][tags]=python3&quot; class=&quot;tag&quot;&gt;python3&lt;/a&gt;, &lt;a href=&quot;http://carnivore.it/?btng[post][tags]=sqlite&quot; class=&quot;tag&quot;&gt;sqlite&lt;/a&gt;.
            &lt;/small&gt;
&lt;/p&gt;
</description>
    </item>
    <item rdf:about="http://carnivore.it/2010/06/11/data_visualisation_-_afterglow">
        <dc:format>text/html</dc:format>
        <dc:date>2010-06-11T11:14:40+02:00</dc:date>
        <title>data visualisation - afterglow</title>
        <link>http://carnivore.it/2010/06/11/data_visualisation_-_afterglow</link>
        <description>


&lt;div class=&quot;level2&quot;&gt;

&lt;p&gt;
We will create images showing the correlation of attacker-host, vulnerability, malware.&lt;br/&gt;

Basically, image will look like this:&lt;br/&gt;

&lt;a href=&quot;http://carnivore.it/_detail/2010/06/11/afterglow-malware-hosts-small.png?id=2010%3A06%3A11%3Adata_visualisation_-_afterglow&quot; class=&quot;media&quot; title=&quot;2010:06:11:afterglow-malware-hosts-small.png&quot;&gt;&lt;img src=&quot;http://carnivore.it/_media/2010/06/11/afterglow-malware-hosts-small.png&quot; class=&quot;media&quot; title=&quot;small version of an afterglow picture&quot; alt=&quot;small version of an afterglow picture&quot; /&gt;&lt;/a&gt;&lt;br/&gt;

&lt;em&gt; I had to cheat to get the image to a valid size … &lt;/em&gt;

&lt;/div&gt;
&lt;div class=&quot;level2&quot;&gt;

&lt;p&gt;
&lt;span class=&quot;curid&quot;&gt;&lt;a href=&quot;http://carnivore.it/2010/06/11/data_visualisation_-_afterglow#readmore_2010_06_11_data_visualisation_-_afterglow&quot; class=&quot;wikilink1&quot; title=&quot;2010:06:11:data_visualisation_-_afterglow&quot;&gt;Read more…&lt;/a&gt;&lt;/span&gt;
&lt;/p&gt;

&lt;/div&gt;

&lt;p&gt;
    &lt;small&gt;
        This blog post was created on 2010-06-11 at 11:14                    and last modified on 2010-06-15 at 01:00                by
        Markus.
                    It is tagged with &lt;a href=&quot;http://carnivore.it/?btng[post][tags]=afterglow&quot; class=&quot;tag&quot;&gt;afterglow&lt;/a&gt;, &lt;a href=&quot;http://carnivore.it/?btng[post][tags]=dataviz&quot; class=&quot;tag&quot;&gt;dataviz&lt;/a&gt;, &lt;a href=&quot;http://carnivore.it/?btng[post][tags]=dionaea&quot; class=&quot;tag&quot;&gt;dionaea&lt;/a&gt;, &lt;a href=&quot;http://carnivore.it/?btng[post][tags]=sqlite&quot; class=&quot;tag&quot;&gt;sqlite&lt;/a&gt;.
            &lt;/small&gt;
&lt;/p&gt;
</description>
    </item>
    <item rdf:about="http://carnivore.it/2010/06/06/dnsbl_test">
        <dc:format>text/html</dc:format>
        <dc:date>2010-06-06T14:06:33+02:00</dc:date>
        <title>dnsbl test</title>
        <link>http://carnivore.it/2010/06/06/dnsbl_test</link>
        <description>


&lt;div class=&quot;level2&quot;&gt;

&lt;p&gt;

Given the rumor infected windows boxes send spam, I wanted to check how many ips attacking my honeypot are blacklisted on &lt;em&gt;several&lt;/em&gt; dnsbls. I used &lt;a href=&quot;http://www.dnsbl.info/dnsbl-list.php&quot; class=&quot;urlextern&quot; title=&quot;http://www.dnsbl.info/dnsbl-list.php&quot;  rel=&quot;nofollow&quot;&gt;this list for the dnsbls&lt;/a&gt; and wrote some script to query all of them for the last 1000 hosts which addressed my honeypot.
&lt;/p&gt;

&lt;p&gt;

&lt;/div&gt;
&lt;div class=&quot;level2&quot;&gt;

&lt;p&gt;
&lt;span class=&quot;curid&quot;&gt;&lt;a href=&quot;http://carnivore.it/2010/06/06/dnsbl_test#readmore_2010_06_06_dnsbl_test&quot; class=&quot;wikilink1&quot; title=&quot;2010:06:06:dnsbl_test&quot;&gt;Read more…&lt;/a&gt;&lt;/span&gt;
&lt;/p&gt;

&lt;/div&gt;

&lt;p&gt;
    &lt;small&gt;
        This blog post was created on 2010-06-06 at 14:06                    and last modified on 2010-06-15 at 01:00                by
        Markus.
                    It is tagged with &lt;a href=&quot;http://carnivore.it/?btng[post][tags]=dionaea&quot; class=&quot;tag&quot;&gt;dionaea&lt;/a&gt;, &lt;a href=&quot;http://carnivore.it/?btng[post][tags]=dnsbl&quot; class=&quot;tag&quot;&gt;dnsbl&lt;/a&gt;.
            &lt;/small&gt;
&lt;/p&gt;
</description>
    </item>
    <item rdf:about="http://carnivore.it/2010/06/06/data_visualisation">
        <dc:format>text/html</dc:format>
        <dc:date>2010-06-06T13:25:39+02:00</dc:date>
        <title>data visualisation</title>
        <link>http://carnivore.it/2010/06/06/data_visualisation</link>
        <description>


&lt;div class=&quot;level2&quot;&gt;

&lt;p&gt;
&lt;a href=&quot;http://carnivore.it/_detail/2010/06/06/newfiles.png?id=2010%3A06%3A06%3Adata_visualisation&quot; class=&quot;media&quot; title=&quot;2010:06:06:newfiles.png&quot;&gt;&lt;img src=&quot;http://carnivore.it/_media/2010/06/06/newfiles.png&quot; class=&quot;media&quot; title=&quot;new files&quot; alt=&quot;new files&quot; /&gt;&lt;/a&gt;&lt;br/&gt;

&lt;em&gt;Presenting data in a human compatible way is a problem, rumors say at this stage of evolution pictures work best.&lt;/em&gt; &lt;br/&gt;

Therefore some hints how to create graphs using the dionaea logsql sqlite database.

&lt;/div&gt;
&lt;div class=&quot;level2&quot;&gt;

&lt;p&gt;
&lt;span class=&quot;curid&quot;&gt;&lt;a href=&quot;http://carnivore.it/2010/06/06/data_visualisation#readmore_2010_06_06_data_visualisation&quot; class=&quot;wikilink1&quot; title=&quot;2010:06:06:data_visualisation&quot;&gt;Read more…&lt;/a&gt;&lt;/span&gt;
&lt;/p&gt;

&lt;/div&gt;

&lt;p&gt;
    &lt;small&gt;
        This blog post was created on 2010-06-06 at 13:25                    and last modified on 2010-06-15 at 01:00                by
        Markus.
                    It is tagged with &lt;a href=&quot;http://carnivore.it/?btng[post][tags]=dataviz&quot; class=&quot;tag&quot;&gt;dataviz&lt;/a&gt;, &lt;a href=&quot;http://carnivore.it/?btng[post][tags]=dionaea&quot; class=&quot;tag&quot;&gt;dionaea&lt;/a&gt;, &lt;a href=&quot;http://carnivore.it/?btng[post][tags]=gnuplot&quot; class=&quot;tag&quot;&gt;gnuplot&lt;/a&gt;, &lt;a href=&quot;http://carnivore.it/?btng[post][tags]=sqlite&quot; class=&quot;tag&quot;&gt;sqlite&lt;/a&gt;.
            &lt;/small&gt;
&lt;/p&gt;
</description>
    </item>
    <item rdf:about="http://carnivore.it/2010/05/27/batteries_included">
        <dc:format>text/html</dc:format>
        <dc:date>2010-05-27T15:37:50+02:00</dc:date>
        <title>batteries included</title>
        <link>http://carnivore.it/2010/05/27/batteries_included</link>
        <description>


&lt;div class=&quot;level2&quot;&gt;

&lt;p&gt;

&lt;a href=&quot;http://carnivore.it/_detail/2010/05/27/batteries.png?id=2010%3A05%3A27%3Abatteries_included&quot; class=&quot;media&quot; title=&quot;2010:05:27:batteries.png&quot;&gt;&lt;img src=&quot;http://carnivore.it/_media/2010/05/27/batteries.png&quot; class=&quot;media&quot; title=&quot;batteries from type &amp;#039;included&amp;#039;&quot; alt=&quot;batteries from type &amp;#039;included&amp;#039;&quot; /&gt;&lt;/a&gt;&lt;br/&gt;

&lt;/p&gt;

&lt;p&gt;

&lt;em&gt;Fans of Python use the phrase “batteries included” to describe the standard library, which covers everything from asynchronous processing to zip files.&lt;/em&gt; &lt;br/&gt;

Source: &lt;a href=&quot;http://www.python.org/about/&quot; class=&quot;urlextern&quot; title=&quot;http://www.python.org/about/&quot;  rel=&quot;nofollow&quot;&gt;python.org/about/&lt;/a&gt;

&lt;/div&gt;
&lt;div class=&quot;level2&quot;&gt;

&lt;p&gt;
&lt;span class=&quot;curid&quot;&gt;&lt;a href=&quot;http://carnivore.it/2010/05/27/batteries_included#readmore_2010_05_27_batteries_included&quot; class=&quot;wikilink1&quot; title=&quot;2010:05:27:batteries_included&quot;&gt;Read more…&lt;/a&gt;&lt;/span&gt;
&lt;/p&gt;

&lt;/div&gt;

&lt;p&gt;
    &lt;small&gt;
        This blog post was created on 2010-05-27 at 15:37                    and last modified on 2010-06-15 at 01:01                by
        Markus.
                    It is tagged with &lt;a href=&quot;http://carnivore.it/?btng[post][tags]=python&quot; class=&quot;tag&quot;&gt;python&lt;/a&gt;, &lt;a href=&quot;http://carnivore.it/?btng[post][tags]=python3&quot; class=&quot;tag&quot;&gt;python3&lt;/a&gt;.
            &lt;/small&gt;
&lt;/p&gt;
</description>
    </item>
    <item rdf:about="http://carnivore.it/2010/05/18/debianization">
        <dc:format>text/html</dc:format>
        <dc:date>2010-05-18T19:55:34+02:00</dc:date>
        <title>debianization</title>
        <link>http://carnivore.it/2010/05/18/debianization</link>
        <description>


&lt;div class=&quot;level2&quot;&gt;

&lt;p&gt;

Installing software using apt is convenient, compiling software using pbuilder allows creating packages apt can install - without having to install the dependencies required to compile the software yourself.
&lt;/p&gt;

&lt;p&gt;
Therefore, some notices how to create debian packages for dionaea, including the libev, libemu and liblcfg dependencies.
&lt;/p&gt;

&lt;p&gt;
This doc refers to Ubuntu &amp;gt;= 9.04 (karmic), of course it should be possible to use this on any debian plattform, but the effort may be slightly higher, as you&amp;#039;ll have to backport some more packages (at least python3 and cython).
&lt;/p&gt;

&lt;p&gt;
Backporting packages is rather easy, we&amp;#039;ll backport libev 3.9 from Debian Unstable here.

&lt;/div&gt;
&lt;div class=&quot;level2&quot;&gt;

&lt;p&gt;
&lt;span class=&quot;curid&quot;&gt;&lt;a href=&quot;http://carnivore.it/2010/05/18/debianization#readmore_2010_05_18_debianization&quot; class=&quot;wikilink1&quot; title=&quot;2010:05:18:debianization&quot;&gt;Read more…&lt;/a&gt;&lt;/span&gt;
&lt;/p&gt;

&lt;/div&gt;

&lt;p&gt;
    &lt;small&gt;
        This blog post was created on 2010-05-18 at 19:55                    and last modified on 2010-06-15 at 01:01                by
        Markus.
                    It is tagged with &lt;a href=&quot;http://carnivore.it/?btng[post][tags]=dionaea&quot; class=&quot;tag&quot;&gt;dionaea&lt;/a&gt;, &lt;a href=&quot;http://carnivore.it/?btng[post][tags]=pbuilder&quot; class=&quot;tag&quot;&gt;pbuilder&lt;/a&gt;.
            &lt;/small&gt;
&lt;/p&gt;
</description>
    </item>
</rdf:RDF>
