« File infector reveals some lessons to be learned
Who is JEROME.exe? »

Setting up a web trap…

May 28th, 2009

In order to better understand web threats, what better way than to create your own web server?

Web admin stuff is not my forte, so I decided to follow my friend JP’s advice and go the easy way with XAMPP.

XAMPP will install pretty much all the stuff you need to start your own web server. It configures Apache, MySql and a bunch of other components used by most servers.

The other advantage that this has for me is the fact that XAMPP is not recommended for ‘real life’ uses. It is mainly geared towards testing and development. One of the reasons is because by doing a lot of the ‘default’ set up for you, it is not making your server very secure right off the bat.

It happens that this what I want anyway. :-)

I still have a lot to learn about Intrusion Detection Systems (IDS) and we’ve had a lot of malware lately causing us grief in our network, such as Conficker.

The idea here is to set up a vulnerable web server (Windows Server 2003) with very lax security settings (default passwords, open connections to DB etc.)

However, this site will not be available to the WWW. It is going to stay in our ‘very infected’ LAN, where I hope it will get owned soon.

server

server2

Please do :-) that’s what it’s for.

Jerome

    This entry was posted on Thursday, May 28th, 2009 at 4:15 pm and is filed under Research. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

    Comments:

    • (0) comments
    • |
    • Add your comments




RSS feed to this site Twitter Linkedin YouTube Channel

 

RSS feed to this site Jerome Segura is a Security Analyst working at ParetoLogic.

You can contact him at:
MalwareDiaries Email

 

Pages

  • Live Malware Map
  • VB2009 pictures
  • Zheng™ Technology
  • About
  • Contact Us



Security Software

  • XoftSpySE Anti-Spyware
  • Anti-Virus PLUS
  • Privacy Controls



Malware Top 10

  • Koobface Worm
  • DNS Changer Trojan
  • Fake Alert Trojan
  • Windows System Suite
  • Smart Protector
  • Home Antivirus 2010
  • PC Antispyware 2010
  • System Security
  • AVCare
  • Perfect Defender 2009



Archives

  • November 2009
  • October 2009
  • September 2009
  • August 2009
  • July 2009
  • June 2009
  • May 2009
  • April 2009
  • March 2009
  • February 2009
  • January 2009
  • December 2008
  • November 2008
  • October 2008
  • September 2008
  • August 2008
  • July 2008
  • June 2008
  • May 2008
  • April 2008
  • March 2008



Categories

  • Adware (1)
  • Banker Trojans (3)
  • Botnets (2)
  • Conferences (4)
  • DDos (1)
  • Exploits (33)
  • Fake codecs (30)
  • IM threats (1)
  • Interviews (5)
  • Keyloggers (1)
  • Mac security (15)
  • Malware Trends (67)
  • Phishing (7)
  • Podcast (1)
  • ransomware (1)
  • Research (33)
  • Rogue software (47)
  • Rootkits (2)
  • scams (3)
  • Social Networking (4)
  • Uncategorized (110)
  • Wireless Security (1)
  • world map (1)



 
 
 

© 2009 ParetoLogic Inc.