Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Honeypots: Windows honeypot and TS

Windows honeypot and TS

From: Tora <tagetora_at_users.sourceforge.net>
Date: Mon, 3 Jul 2006 09:53:40 +0200

Hi all,

I'm currently in the design stage of a honeynet with a Windows
honeypot inside. I want to add a Terminal Server service to the
honeypot or at least have the technology to "see" whats happening via
Terminal Server if any intruder activates it ¿?

I have been searching for tools that can "look" into a TS session (I
know I can't just look at the traffic, I'm looking for a host-level
tool). I found this post:

http://seclists.org/lists/honeypots/2004/Jan-Mar/0105.html

but I didn't find any implementation of this concept.

Any thoughts, workarounds or alternatives?
Thanks
Received on Jul 04 2006

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos