He nani ʻole: pehea mākou i hana ai i kahi honeypot hiki ʻole ke ʻike ʻia

He nani ʻole: pehea mākou i hana ai i kahi honeypot hiki ʻole ke ʻike ʻia
Hoʻokomo nā hui Antivirus, nā loea palekana ʻike a me nā mea hoihoi i nā ʻōnaehana honeypot ma ka Pūnaewele i mea e "hopu" ai i kahi ʻano hou o ka maʻi a i ʻole e ʻike i nā hana hacker maʻamau. He mea maʻamau ka honeypots ua hoʻomohala ka poʻe cybercriminals i kahi ʻano palekana: ʻike koke lākou aia lākou i mua o kahi pahele a haʻalele wale iā ia. No ka ʻimi ʻana i nā ʻano hana o nā hackers hou, ua hana mākou i kahi honeypot maoli i noho ma ka Pūnaewele no ʻehiku mau mahina, e huki ana i nā ʻano hoʻouka kaua. Ua kamaʻilio mākou e pili ana i ke ʻano o kēia i kā mākou haʻawina "Loaʻa i ke Kānāwai: Ke holo nei i kahi ʻoihana ʻo Honeypot ʻoiaʻiʻo e hopu i nā hoʻoweliweli maoli" Aia kekahi mau ʻike mai ka haʻawina ma kēia pou.

Honeypot development: papa inoa

ʻO ka hana nui i ka hana ʻana i kā mākou supertrap ʻo ia ka pale ʻana iā mākou mai ka hōʻike ʻia ʻana e nā mea hackers i hōʻike i ka hoihoi iā ia. Pono kēia i ka hana he nui:

  1. E hana i ka moʻolelo maoli e pili ana i ka hui, me nā inoa piha a me nā kiʻi o nā limahana, nā helu kelepona a me nā leka uila.
  2. No ka hana ʻana a hoʻokō i kahi kumu hoʻohālike o ka ʻoihana ʻoihana e pili ana i ka moʻolelo e pili ana i nā hana a kā mākou hui.
  3. E hoʻoholo i nā lawelawe pūnaewele e hiki ke loaʻa mai waho mai, akā, mai lawe ʻia me ka wehe ʻana i nā awa pilikia i ʻole ia e like me ka pahele no nā mea hānai.
  4. E hoʻonohonoho i ka ʻike ʻana o ka ʻike e pili ana i kahi ʻōnaehana palupalu a puʻunaue i kēia ʻike i waena o nā mea hoʻouka kaua.
  5. E hoʻokō i ka nānā pono ʻana i nā hana hacker ma ka honeypot infrastructure.

A i kēia manawa nā mea mua.

Ke hana ʻana i kaʻao

Ua hoʻohana mua nā Cybercriminals i ka hālāwai ʻana i ka nui o nā honeypots, no laila ʻo ka ʻaoʻao kiʻekiʻe loa o lākou e hana i kahi hoʻokolokolo hohonu o kēlā me kēia ʻōnaehana nāwaliwali e hōʻoia ʻaʻole ia he pahele. No ke kumu hoʻokahi, ua ʻimi mākou e hōʻoia ʻaʻole pono wale ka honeypot ma ke ʻano o ka hoʻolālā a me nā ʻano ʻenehana, akā no ka hana ʻana i ke ʻano o kahi hui maoli.

Hoʻokomo iā mākou iho i nā kāmaʻa o kahi hacker hypothetical cool, ua kūkulu mākou i kahi algorithm hōʻoia e hoʻokaʻawale i kahi ʻōnaehana maoli mai kahi pahele. Ua komo pū me ka ʻimi ʻana i nā helu IP ʻoihana i nā ʻōnaehana kaulana, ka huli ʻana i ka noiʻi i ka mōʻaukala o nā helu IP, ka ʻimi ʻana i nā inoa a me nā huaʻōlelo e pili ana i ka hui, a me kāna mau hoa pili, a me nā mea he nui. ʻO ka hopena, ua lilo ka moʻolelo i mea hoʻopono a nani.

Ua hoʻoholo mākou e hoʻonoho i ka hale hana hoʻopunipuni ma ke ʻano he hale kūʻai prototyping ʻoihana liʻiliʻi e hana ana no nā mea kūʻai inoa ʻole nui loa ma ka ʻāpana koa a me ka mokulele. Ua hoʻokuʻu kēia iā mākou mai nā hoʻopiʻi kānāwai e pili ana i ka hoʻohana ʻana i kahi brand i loaʻa.

A laila pono mākou e hana i kahi hihiʻo, ʻoihana a me ka inoa no ka hui. Ua hoʻoholo mākou e lilo kā mākou hui i mea hoʻomaka me kahi helu liʻiliʻi o nā limahana, ʻo kēlā me kēia mea he mea hoʻokumu. Hoʻohui kēia i ka hilinaʻi i ka moʻolelo o ke ʻano kūikawā o kā mākou ʻoihana, e hiki ai iā ia ke mālama i nā papahana koʻikoʻi no nā mea kūʻai aku nui a koʻikoʻi. Ua makemake mākou e ʻike nāwaliwali kā mākou hui mai kahi hiʻohiʻona cybersecurity, akā i ka manawa like ua maopopo ke hana nei mākou me nā waiwai koʻikoʻi ma nā ʻōnaehana target.

He nani ʻole: pehea mākou i hana ai i kahi honeypot hiki ʻole ke ʻike ʻia
Kiʻi kiʻi o ka pūnaewele MeTech honeypot. Puna: Trend Micro

Ua koho mākou i ka huaʻōlelo MeTech i ka inoa ʻoihana. Ua hana ʻia ka pūnaewele ma muli o kahi maʻamau manuahi. Ua lawe ʻia nā kiʻi mai nā panakō kiʻi, me ka hoʻohana ʻana i nā mea kaulana ʻole a hoʻololi iā lākou i mea e ʻike ʻole ʻia ai.

Makemake mākou e ʻike maoli ka ʻoihana, no laila pono mākou e hoʻohui i nā limahana me nā mākau ʻoihana e kūlike me ka ʻaoʻao o ka hana. Ua hele mai mākou me nā inoa a me nā pilikino no lākou a laila hoʻāʻo e koho i nā kiʻi mai nā waihona kiʻi e like me ka lāhui.

He nani ʻole: pehea mākou i hana ai i kahi honeypot hiki ʻole ke ʻike ʻia
Kiʻi kiʻi o ka pūnaewele MeTech honeypot. Puna: Trend Micro

No ka ʻike ʻole ʻia, ʻimi mākou i nā kiʻi pūʻulu maikaʻi maikaʻi e hiki ai iā mākou ke koho i nā helehelena e pono ai mākou. Eia naʻe, ua haʻalele mākou i kēia koho, no ka mea hiki i ka mea hacker ke hoʻohana i ka huli kiʻi hoʻohuli a ʻike i kā mākou "limahana" e noho wale nei i nā waihona kiʻi. I ka hopena, ua hoʻohana mākou i nā kiʻi o nā poʻe i hana ʻole ʻia me ka hoʻohana ʻana i nā neural network.

Loaʻa nā ʻike koʻikoʻi e pili ana i kā lākou ʻike loea i nā moʻolelo limahana i paʻi ʻia ma ka pūnaewele, akā ua pale mākou i ka ʻike ʻana i nā kula a i ʻole nā ​​kūlanakauhale.
No ka hana ʻana i nā pahu leta, ua hoʻohana mākou i ke kikowaena o ka mea lawelawe, a laila hoʻolimalima i kekahi mau helu kelepona ma ʻAmelika Hui Pū ʻIa a hoʻohui iā lākou i loko o kahi PBX virtual me kahi papa kuhikuhi leo a me kahi mīkini pane.

ʻOihana Honeypot

No ka pale ʻana i ka ʻike, ua hoʻoholo mākou e hoʻohana i ka hui pū ʻana o nā ʻenehana ʻoihana maoli, nā kamepiula kino a me nā mīkini virtual palekana. Ke nānā nei mākou i mua, e ʻōlelo mākou ua nānā mākou i ka hopena o kā mākou hoʻoikaika ʻana me ka hoʻohana ʻana i ka ʻenekini ʻimi Shodan, a ua hōʻike ʻia ua like ka honeypot me kahi ʻōnaehana ʻoihana maoli.

He nani ʻole: pehea mākou i hana ai i kahi honeypot hiki ʻole ke ʻike ʻia
ʻO ka hopena o ka nānā ʻana i kahi ipu meli me ka hoʻohana ʻana iā Shodan. Puna: Trend Micro

Ua hoʻohana mākou i ʻehā PLC i mea lako no kā mākou pahele:

  • Siemens S7-1200,
  • ʻelua AllenBradley MicroLogix 1100,
  • Omron CP1L.

Ua koho ʻia kēia mau PLC no ko lākou kaulana i ka mākeke ʻōnaehana hoʻokele honua. A ke hoʻohana nei kēlā me kēia mea hoʻokele i kāna protocol ponoʻī, i ʻae iā mākou e nānā i ka PLC e hoʻouka pinepine ʻia a inā makemake lākou i kekahi ma ke kumu.

He nani ʻole: pehea mākou i hana ai i kahi honeypot hiki ʻole ke ʻike ʻia
Nā lako o kā mākou "hale hana" - pahele. Puna: Trend Micro

ʻAʻole mākou i hoʻokomo wale i ka lako lako a hoʻohui iā ia i ka Pūnaewele. Hoʻolālā mākou i kēlā me kēia mea hoʻoponopono e hana i nā hana, me

  • huikau,
  • ka mana puhi ahi a me ke kāʻei conveyor,
  • palletizing me ka manipulator robotic.

A i mea e hoʻokō pono ai ke kaʻina hana, ua hoʻolālā mākou i ka loiloi e hoʻololi i nā ʻāpana manaʻo, hoʻohālikelike i nā kaʻa e hoʻomaka ana a hoʻomaha, a me nā mea puhi ahi e hoʻohuli a pio.

Loaʻa i kā mākou hale hana ʻekolu kamepiula virtual a hoʻokahi kamepiula kino. Ua hoʻohana ʻia nā kamepiula uila e hoʻomalu i kahi mea kanu, kahi lopako palletizer, a ma ke ʻano he hana hana no ka ʻenekini polokalamu PLC. Ua hana ke kamepiula kino ma ke ʻano he kikowaena waihona.

Ma kahi o ka nānā ʻana i nā hoʻouka kaua ma nā PLC, makemake mākou e nānā i ke kūlana o nā polokalamu i hoʻouka ʻia ma kā mākou mau polokalamu. No ka hana ʻana i kēia, ua hana mākou i kahi interface e ʻae iā mākou e hoʻoholo wikiwiki i ka hoʻololi ʻana o nā mokuʻāina o kā mākou mea hana virtual a me nā hoʻonohonoho. Aia i ka pae hoʻolālā, ua ʻike mākou ʻoi aku ka maʻalahi o ka hoʻokō ʻana i kēia me ka hoʻohana ʻana i kahi papahana hoʻomalu ma mua o ka hoʻonohonoho pololei ʻana o ka logic controller. Wehe mākou i ke komo ʻana i ka mana hoʻokele hoʻokele o kā mākou honeypot ma VNC me ka ʻole o ka ʻōlelo huna.

ʻO nā robots ʻenehana kahi mea nui o ka hana akamai o kēia wā. Ma kēia mea, ua hoʻoholo mākou e hoʻohui i kahi robot a me kahi wahi hana automated e hoʻomalu iā ia i nā mea hana o kā mākou hale hana pahele. I mea e ʻoi aku ka ʻoiaʻiʻo o ka "factory", ua hoʻokomo mākou i nā polokalamu maoli ma ke kahua hana hoʻomalu, kahi e hoʻohana ai nā ʻenekinia e hoʻolālā kiʻi i ka loiloi o ka robot. ʻAe, ʻoiai ʻo nā robots ʻoihana i loaʻa i kahi pūnaewele kūloko kaʻawale, ua hoʻoholo mākou e haʻalele i ke komo ʻole ʻia ma o VNC wale nō i ke kahua hana.

He nani ʻole: pehea mākou i hana ai i kahi honeypot hiki ʻole ke ʻike ʻia
ʻO ka honua RobotStudio me kahi hiʻohiʻona 3D o kā mākou robot. Puna: Trend Micro

Ua hoʻokomo mākou i ka honua hoʻolālā RobotStudio mai ABB Robotics ma kahi mīkini virtual me kahi papa hana hoʻokele robot. Ma hope o ka hoʻonohonoho ʻana iā RobotStudio, ua wehe mākou i kahi faila simulation me kā mākou robot i loko i ʻike ʻia kona kiʻi 3D ma ka pale. ʻO ka hopena, ʻo Shodan a me nā ʻenekini ʻimi ʻē aʻe, i ka ʻike ʻana i kahi kikowaena VNC unsecured, e hopu i kēia kiʻi pale a hōʻike i ka poʻe e ʻimi nei i nā robots ʻoihana me ka wehe ʻana i ka mana.

ʻO ke kumu o kēia nānā ʻana i nā kikoʻī, ʻo ia ka hoʻokumu ʻana i kahi pahuhopu hoihoi a kūpono hoʻi no ka poʻe hoʻouka ʻia, ke loaʻa iā lākou, e hoʻi hou i laila.

Ke kahua hana a ka ʻenekinia


No ka hoʻolālā ʻana i ka loiloi PLC, ua hoʻohui mākou i kahi kamepiula ʻenekinia i ka ʻōnaehana. Ua hoʻokomo ʻia nā polokalamu ʻenehana no ka hoʻolālā PLC ma luna ona:

  • TIA Portal no Siemens,
  • ʻO MicroLogix no ka mea hoʻokele Allen-Bradley,
  • CX-One no Omron.

Ua hoʻoholo mākou ʻaʻole hiki ke ʻike ʻia ka wahi hana ʻenekinia ma waho o ka pūnaewele. Akā, hoʻonoho mākou i ka ʻōlelo huna like no ka moʻokāki luna e like me ke kahua hana hoʻomalu robot a me ka hale hana hoʻomalu hale hana i loaʻa mai ka Pūnaewele. He mea maʻamau kēia hoʻonohonoho i nā ʻoihana he nui.
ʻO ka mea pōʻino, ʻoiai kā mākou hoʻoikaika ʻana, ʻaʻole i hiki i kahi mea hoʻouka kaua i ka hale hana o ka ʻenekinia.

kikowaena waihona

Pono mākou iā ia ma ke ʻano he maunu no ka poʻe hoʻouka kaua a me ke ʻano o ke kākoʻo ʻana i kā mākou "hana" ponoʻī ma ka hale hana hoʻopunipuni. Ua ʻae kēia iā mākou e kaʻana like i nā faila me kā mākou honeypot me ka hoʻohana ʻana i nā polokalamu USB me ka waiho ʻole ʻana i kahi trace ma ka pūnaewele honeypot. Ua hoʻokomo mākou i ka Windows 7 Pro ma ke ʻano he OS no ka faila waihona, kahi i hana ai mākou i kahi waihona i hiki ke heluhelu a kākau ʻia e kekahi.

I ka wā mua ʻaʻole mākou i hana i kahi hierarchy o nā waihona a me nā palapala ma ka waihona waihona. Eia naʻe, ua ʻike mākou ma hope mai ke aʻo ikaika nei nā mea hoʻouka i kēia waihona, no laila ua hoʻoholo mākou e hoʻopiha iā ia me nā faila like ʻole. No ka hana ʻana i kēia, ua kākau mākou i kahi palapala python i hana i kahi faila o ka nui o ka nui me kekahi o nā hoʻonui i hāʻawi ʻia, e hana ana i kahi inoa e pili ana i ka puke wehewehe.

He nani ʻole: pehea mākou i hana ai i kahi honeypot hiki ʻole ke ʻike ʻia
Palapala no ka hana ʻana i nā inoa faila maikaʻi. Puna: Trend Micro

Ma hope o ka holo ʻana i ka palapala, loaʻa iā mākou ka hopena i makemake ʻia ma ke ʻano o kahi waihona i hoʻopiha ʻia me nā faila me nā inoa hoihoi.

He nani ʻole: pehea mākou i hana ai i kahi honeypot hiki ʻole ke ʻike ʻia
Ka hopena o ka palapala. Puna: Trend Micro

Kaiapuni nānā


Ma muli o ka hoʻoikaika nui ʻana i ka hana ʻana i kahi ʻoihana ʻoiaʻiʻo, ʻaʻole hiki iā mākou ke hāʻule i ke kaiapuni no ka nānā ʻana i kā mākou "malihini". Pono mākou e kiʻi i nā ʻikepili āpau i ka manawa maoli me ka ʻike ʻole o ka poʻe hoʻouka kaua ke nānā ʻia nei lākou.

Ua hoʻokō mākou i kēia me ka hoʻohana ʻana i ʻehā USB i Ethernet adapters, ʻehā SharkTap Ethernet paʻi, kahi Raspberry Pi 3, a me kahi kaʻa waho nui. ʻO kā mākou kiʻina pūnaewele e like me kēia:

He nani ʻole: pehea mākou i hana ai i kahi honeypot hiki ʻole ke ʻike ʻia
Honeypot network diagram me nā lako nānā. Puna: Trend Micro

Ua hoʻonoho mākou i ʻekolu paʻi SharkTap no ka nānā ʻana i nā kaʻa waho a pau i ka PLC, hiki ke loaʻa mai ka pūnaewele kūloko. Ua nānā ʻo SharkTap ʻehā i ka hele ʻana o nā malihini o kahi mīkini virtual palupalu.

He nani ʻole: pehea mākou i hana ai i kahi honeypot hiki ʻole ke ʻike ʻia
SharkTap Ethernet Tap a me Sierra Wireless AirLink RV50 Router. Puna: Trend Micro

Ua hana ʻo Raspberry Pi i ka hopu kaʻa i kēlā me kēia lā. Hoʻopili mākou i ka Pūnaewele me ka Sierra Wireless AirLink RV50 cellular router, hoʻohana pinepine ʻia i nā ʻoihana ʻoihana.

ʻO ka mea pōʻino, ʻaʻole i ʻae kēia router iā mākou e koho i nā hoʻouka kaua ʻaʻole i kūlike i kā mākou mau hoʻolālā, no laila ua hoʻohui mākou i kahi pā ahi Cisco ASA 5505 i ka pūnaewele ma ke ʻano aniani e hana i ka pale ʻana me ka hopena liʻiliʻi ma ka pūnaewele.

Nānā kaʻahele


Ua kūpono ʻo Tshark a me tcpdump no ka hoʻoponopono wikiwiki ʻana i nā pilikia o kēia manawa, akā i kā mākou hihia, ʻaʻole lawa kā lākou hiki, no ka mea he nui nā gigabytes o ke kaʻa, i loiloi ʻia e kekahi poʻe. Ua hoʻohana mākou i ka Moloch analyzer i hoʻomohala ʻia e AOL. Hoʻohālikelike ʻia ia i ka hana iā Wireshark, akā ʻoi aku ka nui o nā mana no ka hui pū ʻana, wehewehe a kau ʻana i nā pūʻolo, lawe aku a me nā hana ʻē aʻe.

No ka mea ʻaʻole mākou makemake e hoʻoponopono i ka ʻikepili i hōʻiliʻili ʻia ma nā kamepiula honeypot, ua lawe ʻia nā pahu PCAP i kēlā me kēia lā i kahi waihona AWS, mai kahi a mākou i lawe mua ai iā lākou ma ka mīkini Moloch.

Hoʻopaʻa leo

No ka hoʻopaʻa ʻana i nā hana a ka poʻe hackers i kā mākou honeypot, ua kākau mākou i kahi palapala i lawe i nā screenshots o ka mīkini virtual i kahi manawa i hāʻawi ʻia a, i ka hoʻohālikelike ʻana me ka kiʻi mua, ua hoʻoholo inā he mea e hana ana ma laila a ʻaʻole paha. I ka ʻike ʻia ʻana o ka hana, ua hoʻokomo ʻia ka palapala i ka hoʻopaʻa ʻana i ka pale. Ua lilo kēia ala i mea maikaʻi loa. Ua hoʻāʻo hoʻi mākou e kālailai VNC traffic mai kahi PCAP dump no ka hoʻomaopopo ʻana i nā loli i hana ʻia i loko o ka ʻōnaehana, akā i ka hopena o ka hoʻopaʻa ʻana o ka pale a mākou i hoʻokō ai i maʻalahi a ʻoi aku ka ʻike.

Ke nānā nei i nā kau VNC


No kēia ua hoʻohana mākou i Chaosreader a me VNCLogger. Hoʻopuka nā mea pono ʻelua i nā kī kī mai kahi PCAP dump, akā ʻo VNCLogger e mālama i nā kī e like me Backspace, Enter, Ctrl me ka pololei.

ʻElua mau hemahema ʻo VNCLogger. ʻO ka mua: hiki iā ia ke unuhi i nā kī ma ka "hoʻolohe" i ke kaʻa ma ka interface, no laila pono mākou e hoʻohālikelike i kahi hālāwai VNC no ia me ka hoʻohana ʻana i ka tcpreplay. ʻO ka lua o ka hemahema o VNCLogger ka mea maʻamau me Chaosreader: ʻaʻole lākou e hōʻike i nā ʻike o ka clipboard. No ka hana ʻana i kēia, pono wau e hoʻohana iā Wireshark.

Hoʻowalewale mākou i nā hackers


Ua hana mākou i ka honeypot e hoʻouka ʻia. No ka hoʻokō ʻana i kēia, ua hoʻonohonoho mākou i kahi leka ʻike e huki i ka manaʻo o nā mea hoʻouka kaua. Ua wehe ʻia nā awa ma luna o ka honeypot:

He nani ʻole: pehea mākou i hana ai i kahi honeypot hiki ʻole ke ʻike ʻia

Pono e pani ʻia ka awa RDP ma hope koke iho o ko mākou hele ʻana i ke ola no ka mea ʻo ka nui o ka nānā ʻana i nā kaʻa ma kā mākou pūnaewele ke kumu i nā pilikia hana.
Ua hana mua nā kikowaena VNC ma ke ʻano ʻike wale nō me ka ʻole o ka ʻōlelo huna, a laila "kuhihewa" mākou i hoʻololi iā lākou i ke ʻano komo piha.

No ka huki ʻana i nā mea hoʻouka kaua, ua hoʻopuka mākou i ʻelua mau pou me ka ʻike leaked e pili ana i ka ʻōnaehana ʻoihana i loaʻa ma PasteBin.

He nani ʻole: pehea mākou i hana ai i kahi honeypot hiki ʻole ke ʻike ʻia
ʻO kekahi o nā pou i kau ʻia ma PasteBin e huki i nā hoʻouka kaua. Puna: Trend Micro

hoouka kaua


Noho ʻo Honeypot ma ka pūnaewele no ʻehiku mahina. ʻO ka hoʻouka mua ʻana i hoʻokahi mahina ma hope o ka hele ʻana o ka honeypot ma ka pūnaewele.

Nā kiʻaupō

He nui nā kaʻa mai nā scanners o nā hui kaulana - ip-ip, Rapid, Shadow Server, Shodan, ZoomEye a me nā mea ʻē aʻe. Nui ka nui o ia mau mea a mākou e hoʻokaʻawale ai i kā lākou mau IP address mai ka nānā ʻana: 610 mai ka 9452 a i ʻole 6,45% o nā helu IP kūʻokoʻa āpau i loaʻa i nā scanners kūpono.

Nā Kahu Pūnaewele

ʻO kekahi o nā pilikia nui a mākou i alo ai, ʻo ia ka hoʻohana ʻana i kā mākou ʻōnaehana no ka hana hewa: e kūʻai i nā kelepona ma o ka moʻokāki o ka mea kākau inoa, e hoʻolilo i nā mile mokulele me ka hoʻohana ʻana i nā kāleka makana a me nā ʻano hoʻopunipuni ʻē aʻe.

Nā Miners

ʻO kekahi o ka poʻe kipa mua i kā mākou pūnaewele i lilo i mea miner. Ua hoʻoiho ʻo ia i ka polokalamu mining Monero ma luna ona. ʻAʻole hiki iā ia ke loaʻa kālā nui ma kā mākou ʻōnaehana ma muli o ka haʻahaʻa o ka huahana. Eia nō naʻe, inā mākou e hoʻohui i nā hana o kekahi mau haneli a i ʻole mau haneli o ia mau ʻōnaehana, hiki ke hoʻololi maikaʻi ʻia.

Ransomware

I ka wā o ka hana o ka honeypot, ua ʻike mākou i nā maʻi ransomware maoli ʻelua. I ka hihia mua ʻo Crysis. Ua hoʻokomo kāna mau mea hana i ka ʻōnaehana ma o VNC, akā ua hoʻokomo ʻo TeamViewer a hoʻohana iā ia e hana i nā hana hou aʻe. Ma hope o ke kali ʻana i kahi leka hoʻopiʻi e koi ana i kahi pānaʻi o $ 10 ma BTC, ua komo mākou i nā leka me nā lawehala, e noi ana iā lākou e hoʻokaʻawale i kekahi o nā faila no mākou. Ua hoʻokō lākou i ka noi a hoʻihoʻi hou i ke koi pānaʻi. Ua hiki iā mākou ke kūkākūkā a hiki i 6 tausani kālā, ma hope o ka hoʻouka hou ʻana i ka ʻōnaehana i kahi mīkini virtual, ʻoiai ua loaʻa iā mākou nā ʻike āpau e pono ai.

ʻO ka lua o ka ransomware i lilo i Phobos. ʻO ka mea hacker nāna i hoʻokomo iā ia i hoʻolimalima i hoʻokahi hola e nānā i ka ʻōnaehana file honeypot a nānā i ka pūnaewele, a laila hoʻokomo i ka ransomware.
Ua hoʻopunipuni ke kolu o ka ransomware hoʻouka kaua. Ua hoʻoiho kekahi "hacker" i ʻike ʻole ʻia i ka faila haha.bat ma luna o kā mākou ʻōnaehana, a laila nānā mākou no kekahi manawa ʻoiai ʻo ia e hoʻāʻo e hoʻomaka i ka hana. ʻO kekahi o nā hoʻāʻo ʻana e hoʻololi i ka inoa haha.bat i haha.rnsmwr.

He nani ʻole: pehea mākou i hana ai i kahi honeypot hiki ʻole ke ʻike ʻia
Hoʻonui ka "hacker" i ka pōʻino o ka faila bat ma ka hoʻololi ʻana i kona hoʻonui i .rnsmwr. Puna: Trend Micro

I ka hoʻomaka ʻana o ka waihona pūʻulu e holo, ua hoʻoponopono ka "hacker" iā ia, e hoʻonui ana i ka pānaʻi mai $200 a i $750. Ma hope o kēlā, ua "hoʻopili" ʻo ia i nā faila a pau, waiho i kahi memo extortion ma ka pākaukau a nalowale, hoʻololi i nā ʻōlelo huna ma kā mākou VNC.

I kekahi mau lā ma hope mai, ua hoʻi mai ka mea hacker a, e hoʻomanaʻo iā ia iho, ua hoʻokuʻu i kahi faila puʻupuʻu i wehe i nā puka makani he nui me kahi pūnaewele porn. Me he mea lā, ma kēia ʻano ua hoʻāʻo ʻo ia e huki i ka manaʻo i kāna koi.

Nā hopena


I ka wā o ke aʻo ʻana, ua ʻike ʻia i ka wā i paʻi ʻia ai ka ʻike e pili ana i ka nāwaliwali, ua huki ka honeypot i ka nānā, me ka ulu ʻana o ka hana i kēlā me kēia lā. I mea e loaʻa ai ka manaʻo o ka pahele, pono e loaʻa i kā mākou hui fictitious nā haki palekana he nui. ʻO ka mea pōʻino, ʻaʻole i maʻamau kēia kūlana ma waena o nā ʻoihana maoli i loaʻa ʻole i ka IT piha a me nā limahana palekana ʻike.

Ma keʻano laulā, pono e hoʻohana nā hui i ke kumu o ka pono liʻiliʻi, ʻoiai mākou e hoʻokō i ke ʻano kūʻē o ia mea e huki ai i nā mea hoʻouka. A ʻo ka lōʻihi o kā mākou nānā ʻana i nā hoʻouka ʻana, ʻoi aku ka maʻalahi o lākou i hoʻohālikelike ʻia i nā ʻano hoʻokolohua maʻamau.

A ʻo ka mea nui loa, ua pau kēia mau hoʻouka ʻana inā i hoʻokō ʻia nā hana palekana i ka wā e hoʻonohonoho ai i ka pūnaewele. Pono nā hui e hōʻoia i ka loaʻa ʻole o kā lākou mau mea hana a me nā ʻāpana ʻenehana mai ka Pūnaewele, e like me kā mākou i hana ai i kā mākou pahele.

ʻOiai ʻaʻole mākou i hoʻopaʻa i hoʻokahi hoʻouka kaua ʻana i ka hale hana o ka ʻenekinia, ʻoiai ka hoʻohana ʻana i ka ʻōlelo huna hoʻokele kūloko ma nā kamepiula āpau, pono e pale ʻia kēia hana i mea e hōʻemi ai i ka hiki ke komo. Ma hope o nā mea a pau, lilo ka palekana nāwaliwali ma ke ʻano he kono hou e hoʻouka i nā ʻōnaehana ʻoihana, i makemake nui ʻia i nā cybercriminals.

Source: www.habr.com

Pākuʻi i ka manaʻo hoʻopuka