Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: How Would I Find the Actual Name of the Honeypot Software via a Pen Test? |
|---|---|
| Date: | Wed, 20 Jun 2007 14:56:26 -0400 |
You may try and fingerprint the bios. This may lead you to determine if its vmware etc... or perhaps it can fingerprint the HP if they dont randomize bios data. Jay ----- Original Message ----- From: StaticRez [mailto:staticrez@gmail.com] To: pen-test@securityfocus.com Sent: Wed, 20 Jun 2007 11:55:56 -0500 Subject: Re: How Would I Find the Actual Name of the Honeypot Software via a Pen Test? Well, here's a list: http://www.honeypots.net/honeypots/products If you can actually tell them the name of the software then you're THE MAN. I'm assuming that within the honeypot configs, you can pick which services you'd want to be open. With that in mind, I don't think there's any way of knowing what the actual software is. And even assuming you know the OS, unless you're analyzing packets, the honeypot should be able to "mimic" (to a certain extent) an IIS server, it could be sitting on a BSD or any linux/unix variant box. this one might require some social engineering... staticrez On 6/19/07, TStark <stark.ironman@gmail.com> wrote:
Good afternoon, I'm doing a pen test a new IPS appliance from outside the network, while working through the assessment I found that the server designated as my target was a honeypot set up by our server team rather than a normal server. I've now been challenged to now tell them the actual name of the honeypot software they are using. So with that, I figure I'd ask the pros, hoping that someone has a suggestion other than me low crawling under the raised floor in the server room looking for the host server:P Thanks for the help! Tony ------------------------------------------------------------------------ This List Sponsored by: Cenzic Are you using SPI, Watchfire or WhiteHat? Consider getting clear vision with Cenzic See HOW Now with our 20/20 program! http://www.cenzic.com/c/2020 ------------------------------------------------------------------------
------------------------------------------------------------------------ This List Sponsored by: Cenzic Are you using SPI, Watchfire or WhiteHat? Consider getting clear vision with Cenzic See HOW Now with our 20/20 program! http://www.cenzic.com/c/2020 ------------------------------------------------------------------------
------------------------------------------------------------------------ This List Sponsored by: Cenzic Are you using SPI, Watchfire or WhiteHat? Consider getting clear vision with Cenzic See HOW Now with our 20/20 program! http://www.cenzic.com/c/2020 ------------------------------------------------------------------------
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: Security and VPN, Robin Wood |
|---|---|
| Next by Date: | Re: How Would I Find the Actual Name of the Honeypot Software via a Pen Test?, Dragos Ruiu |
| Previous by Thread: | RE: How Would I Find the Actual Name of the Honeypot Software via a Pen Test?, ep |
| Next by Thread: | RE: How Would I Find the Actual Name of the Honeypot Software via a Pen Test?, Michael Scheidell |
| Indexes: | [Date] [Thread] [Top] [All Lists] |