Tags: malware web malware analysis honeypot
Event: Hashdays 2010
Abstract: GlastopfNG is a honeypot specialized on simulating a vulnerable web server/application to become a target of automated and even manual attacks. Instead of trying to block these attacks GlastopfNG tries to get as much information as possible about the attacker and the used attack itself. This gathered information can then be used in different ways to protect real applications in the future against such attacks and also to create statistics which can be used in research projects. This presentation will give an introduction on why we need a tool like this, how it works and how we can use the gathered information to make statistics, help ISP customers or even steal a running botnet to DDoS your evil neighbor.