Sinkholing Suspicious Scripts or Executables on Linux, (Fri, Jul 25th)

When you need to analyze some suspicious pieces of code, it's interesting to detonate them in a sandbox. If you don't have a complete sandbox environment available or you just want to avoid generatin noise on your network, why not route the traffic to a sinkhole or NULL-route (read: packets won't be sent across the normal network and default gateway).

This article has been indexed from SANS Internet Storm Center, InfoCON: green

Read the original article: