Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




honeypots logo Honeypots mailing list archives

Re: Honeytokens and detection
From: george chamales <george () overt org>
Date: Fri, 4 Apr 2003 15:51:33 -0600

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

One problem I see with the whole concept is that if I was the other side,
I'd be using an encrypted tunnel to grab the info.

I think that relying on network traffic is the wrong way to handle this. I suggest having hooks set up on the host itself that monitor when the "token" is opened, read, modified, etc. In effect, real-time file integrity checking/tripwire on the fly. With a bit of work the integrity checking could be hidden from all the users on the system and alerts could be sent covertly off of the host.

All in all, I really like the idea.

george
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.7 (Darwin)

iD8DBQE+jf5v52U0zfoU/mIRAhmtAJwO/WLfH78n03VDgfDXDWK7XYWD9gCcCZ2S
XJC0wH05H4zYIdtFC99ZX/g=
=oBwN
-----END PGP SIGNATURE-----


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]