Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | RE: Honeypot Server |
|---|---|
| Date: | Thu, 17 Jan 2008 18:02:38 -0600 |
The bait n switch preproc with snort allows you to redirect traffic that triggered an alert to a honeypot/net which combines research and some security features into a honeypot deployment. So they definitely can provide some security. Take in mind that any traffic hitting your honeynet is malicious which can act as a warning system. You can even deploy in a round-robin fashion so if alert is for a windows vuln send to win32 HP and if linux alert send to *nix HP and so forth. I wrote a paper with Jason Larsen discussing these ideas its called, Fun Things to do with your honeypot. Hope that helps. -Albert G. -----Original Message----- From: krymson@gmail.com Sent: Thursday, January 17, 2008 3:38 PM To: security-basics@securityfocus.com Subject: Re: Honeypot Server "Easy to admin, monitor, alert..." I apologize, but I would first question what your intended purpose for the honeypot would be. I get the feeling you want something more like a network tripwire that you don't have to look at I would steer you towards an IDS solution like Snort or some other sort of deep inspection firewall or even just your firewall logs. A honeypot, while fun and interesting, is still largely a measure for malware/hacker research as opposed to any real security measure. I know you didn't call it a security measure, but it sounds like you want a security measure...? A honeypot has very little value to most shops that are not providing actual research. <- snip -> Can you advise what is the best honeypot server available Open-source or commercial - it doesn't matter as long as it will be easy to administrate and easy to monitor and alerted ...
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: Secure Login Form, MaddHatter |
|---|---|
| Next by Date: | RE: Analyzing Suspicious Attachment, Richard Golodner |
| Previous by Thread: | RE: Honeypot Server, Timmothy Lester |
| Next by Thread: | Analyzing Suspicious Attachment, Al Cooper |
| Indexes: | [Date] [Thread] [Top] [All Lists] |