The new forums will be named Coin Return (based on the most recent vote)! You can check on the status and timeline of the transition to the new forums here.
The Guiding Principles and New Rules document is now in effect.

Honeypots

pacbowlpacbowl Los AngelesRegistered User regular
edited February 2009 in Help / Advice Forum
Quick question. I know what honeypot servers are. What I'm wondering is how exactly do you make them more enticing than your regular server or what would you do to them that they attract more network attention than your regular DB server.

steammicro.php?id=pacbowl&pngimg=background&tborder=0
pacbowl on

Posts

  • DocDoc Registered User, ClubPA regular
    edited February 2009
    Put them outside of any firewall, with easy passwords for dictionary attacks or guesses to get. Having as many responsive ports as possible helps.

    Doc on
  • vonPoonBurGervonPoonBurGer Registered User regular
    edited February 2009
    Having a DNS record that resolves to the honeypot's IP might help, but in most cases it'll be found using a network scanner like Nmap. If you look at that or similar tools, you'll see that they have multiple methods of detecting live hosts on a network. Beyond straight ping, there are a number of more exotic ways to determine whether or not there is a live system at a given network address. A good honeypot would respond to most or all of those methods, so no matter what type of scan is used, your honeypot shows up. Once it's been found, you're going to want it set up in the manner Doc described so that they're enticed to try cracking the system. Lots of open ports, old versions of server software that have known exploits, lack of security patches plugging OS security holes, etc.

    vonPoonBurGer on
    Xbox Live:vonPoon | PSN: vonPoon | Steam: vonPoonBurGer
  • supabeastsupabeast Registered User regular
    edited February 2009
    Make it part of a server farm for political blogs.

    supabeast on
Sign In or Register to comment.