Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

Re: Honeypot detection and countermeasures

From: Dragos Ruiu <dr(at)kyx.net>
Date: Mon Jun 23 2003 - 22:48:14 EDT

On June 23, 2003 06:58 am, Rob Shein wrote:
> This wouldn't work. Seeing the packets/traffic on the wire doesn't tell

Putting on my Honeynet Project hat...

I think you presume too much about honeypots. There are _many_ varieties of honeypots.

Some more rootable than others, some more detectable than others. And it's also possible to instrument them with many other monitoring systems besides just sniffing traffic in and out. I'll leave the specifics as an excercise for the reader.... :-) but they range from running inside vmware to instrumented os loads and even special hardware in some cases.

Lately the Honeynet Alliance folks have been deploying other systems besides your typical low hanging fruit. Different honeypots gather different data. It all depends on what you are trying to catch.

Beware the Jabberwock...

cheers,
--dr

-- 
pgpkey 
http://dragos.com/ kyxpgp

---------------------------------------------------------------------------
Latest attack techniques.

You're a pen tester, but is google.com still your R&D team? Now you can get 
trustworthy commercial-grade exploits and the latest techniques from a 
world-class research group.

Visit us at: www.coresecurity.com/promos/sf_ept1 
or call 617-399-6980
----------------------------------------------------------------------------
Received on Tue Jun 24 11:40:39 2003
Do you need help?X

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:02:38 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library