public inbox for gentoo-user@lists.gentoo.org
 help / color / mirror / Atom feed
* [gentoo-user] Whats a good honeypot?
@ 2011-09-17 11:14 William Kenworthy
  2011-09-17 13:09 ` Alan McKinnon
  0 siblings, 1 reply; 2+ messages in thread
From: William Kenworthy @ 2011-09-17 11:14 UTC (permalink / raw
  To: Gentoo Users

I am looking at using a honeypot for a research project - need to put
something "safe" to attract packets, scans etc.  I was thinking of a
heavily stripped gentoo vm (in virtualbox) running honeyd, but the
ebuild for honeyd is looking like its getting quite old - according to
the honeyd website its 2007-05-27.

Is there an alternative?  I need to dump raw packets (pcap format) from
an unprotected network connection but dont want to risk getting actually
"hacked".

BillK






^ permalink raw reply	[flat|nested] 2+ messages in thread

* Re: [gentoo-user] Whats a good honeypot?
  2011-09-17 11:14 [gentoo-user] Whats a good honeypot? William Kenworthy
@ 2011-09-17 13:09 ` Alan McKinnon
  0 siblings, 0 replies; 2+ messages in thread
From: Alan McKinnon @ 2011-09-17 13:09 UTC (permalink / raw
  To: gentoo-user

On Sat, 17 Sep 2011 19:14:06 +0800
William Kenworthy <billk@iinet.net.au> wrote:

> I am looking at using a honeypot for a research project - need to put
> something "safe" to attract packets, scans etc.  I was thinking of a
> heavily stripped gentoo vm (in virtualbox) running honeyd, but the
> ebuild for honeyd is looking like its getting quite old - according to
> the honeyd website its 2007-05-27.
> 
> Is there an alternative?  I need to dump raw packets (pcap format)
> from an unprotected network connection but dont want to risk getting
> actually "hacked".


backtrack.

Awesome tool. Our risk and pentest guys use it lots with honeypots
scattered all over the network, most of them serving no other purpose
than to catch my team out so we owe them lots of beer :-)

Seriously though, it comes up as a full distro so runs in a VM nicely
and is designed to be a security tool. The plumbing you need to
not give away that something in a honeypot is already in place. I
consider this to be much better than most efforts we'd make to roll our
own



-- 
Alan McKinnnon
alan.mckinnon@gmail.com



^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2011-09-17 13:10 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2011-09-17 11:14 [gentoo-user] Whats a good honeypot? William Kenworthy
2011-09-17 13:09 ` Alan McKinnon

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox