Return Styles: Pseud0ch, Terminal, Valhalla, NES, Geocities, Blue Moon.

Pages: 1-

Pooh bear time, yo

Name: Anonymous 2009-10-17 16:08

I can't find anything via google that mentions how honeypot whores typically get around the ability to detect virtualization (there are a few methods, but they are all pretty hacky... like changing vmware device strings and patches that no longer work to turn off the ability for guests to molest the hypervisor).  Long story short, it seems like a better idea to go with a physical box (especially since I am interested primarily in botnet clients, pulled off 4chan, etc.).  Sure, you can't have multiple anus haxxings going on in parallel if you are using hardware directly, but at least the malware won't magically die as soon as it starts.

How would you automate getting back to an uninfected disk image?  I am considering network boot, or a fake USB device (I am not sure if that's possible... have nother box emulate a USB drive).  I'm sure something more inventive involving LISP can be concocted here.

Name: Anonymous 2009-10-17 16:10

back to /comp/

Name: Anonymous 2009-10-17 16:11

btw, I have some enterprise-class 233mhz boxes sitting around, and would prefer to use them.  Of course, these won't even support the two things I mentioned, so... I'm hoping something even lower to the hardware is possible.

Name: Anonymous 2009-10-17 16:13

I can't understand your post. Could you elaborate?

Name: Anonymous 2009-10-17 16:21

I'm not sure what you're asking friend, you should go to /g/ or /comp/. If you're asking how to get rid of viruses, I recommend reformatting and reinstalling a better operating system.

Name: Anonymous 2009-10-17 16:50

>>1 has no idea what he is talking about.  Anyone who knows a little about computers knows his whole post has little coherency, and it is likely he just used a bunch of words he found on reddit or a similar shit site together the way he thinks they work.

Name: Anonymous 2009-10-17 17:10

>>6
Well, it has coherency.
I, for example, understood it all

Name: Anonymous 2009-10-17 17:15

>>7
Whatever you say, >>1.

Name: Anonymous 2009-10-17 18:23

I'm going to bump my thread just for >>6 trolling

Name: Anonymous 2009-10-17 18:28

If you insist on using vmWare, then you'd probably have to change a lot of those strings and also would need to patch some drivers to not provide some services. There's a couple of papers out there which describe these tricks. Other solutions involve full emulation via Bochs (slow as hell, reliable) or using an open-source emulation solution, which you can just alter and recompile(VirtualBox).

Name: Anonymous 2009-10-17 20:44

>>10
Agreed. Why would anyone use vmware?

Name: Anonymous 2009-10-17 20:50

>>11
Really, SIMH's networking is a bit hackish, but other than that it's a very good suite of emulators.

Name: Anonymous 2009-10-17 22:03

>>10
And if you insist on trolling, at least use sage.

Name: Anonymous 2009-10-17 23:34

>>13
IHBT

Name: ​​​​​​​​​​ 2010-10-25 11:20

Name: Anonymous 2010-11-26 23:13

Name: Anonymous 2010-12-06 9:24

Back to /b/, ``GNAA Faggot''

Don't change these.
Name: Email:
Entire Thread Thread List