Friday, November 5, 2010

The Infosec Tables Are Turning

The good guys have always spent time researching to understand how the bad guys operate, in order to turn the tables and catch them. A honeypot is probably the best example of this.

A honeypot is a system that purposely appears to be super-vulnerable to the attackers who eventually find and attack it, while the good guys watch and learn. In theory, what they learn is used to develop newer and better tools. While this has utterly failed in the Antivirus world, it has been a fairly successful strategy in the hacking world.

In a decidedly Spy vs. Spy revelation, it seems that attackers are using honeypots to catch infosec researchers. The Zeus bot makes use of a fake administrator interface, complete with a guessable password and trivial SQL vulnerability meant to alert the attackers to the investigation so they can respond accordingly.