Botnets And VMware
Thursday, 20 July 2006 by Michel Roth
This article is about using VMware to turn the tables on botnet owners: "What I want to get across is there is an almost 24/7 turf war going on between illegal ownership of rooted boxes between all different groups of people.

Sounds like fun? Of course it does. That's why we should get involved. This is where the VMware comes in. In an essence, we're making a sandbox (much like Java infact) on our machine so anything that happens to the VMware virtual machine is independent of our own box.

Right... So we load up VMware. Build a virtual machine with Windows XP on it. However, do not patch it what so ever. We want to make it as easy as possible for them to exploit it. We are creating a honeypot in a way, however, it's sole purpose is not just for research. Right. Now you will have to mess about a little with internal bridging and networking (and even port forwarding) to get it so that if an attacker connects to say port 139 (netbios) on your external IP (which is obviously your box, not the VMware), that it forwards this to the VMware virtual machine on port 139. Once this is complete, we are almost ready to go. One more thing to do and that is to grab Ethereal (and the pCap plugin) and install it so we can sniff packets. Done that? Ready to set sail!

Read the entire article here.

Related Items:

How To Build An Effective Virtual Machine Template (30 March 2006)
VMware Virtual Machine Importer 2.0 (6 October 2006)
VMware Virtual Machine Importer And DiskMount Utilities (14 April 2005)
VMware Announces Open Virtual Machine Format (OVF) (27 February 2008)
VMware Introduces Open Virtual Machine Disk Format Specification (3 April 2006)
Virtual PC 2004 SP1 And LPT Ports (7 March 2006)
VMware's Vice President Of Research And Development Starts Blog (7 February 2006)
eWeek Names VMware Server As One Of The Top Products Of 2006 (19 December 2006)
VMware NAT Networking Buffer Overflow Vulnerability (21 December 2005)
PlateSpin Assists In Upgrading To VMware Infrastructure 3 With Near-Zero Downtime (23 August 2006)
Comments (0)