Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Honeypots: RE: Building an Honeypot using VMWare

RE: Building an Honeypot using VMWare

From: Edward Balas <ebalas_at_iu.edu>
Date: Mon, 4 Nov 2002 14:02:07 -0500 (EST)

On Mon, 4 Nov 2002, Bruno MAC Castro wrote:

>
> Thanks Bill,
>
> I agree with you in everything... But, it would improve the concept of a
> Honeypot if the trace of a virtual machine (VMWare) was hard (or
> impossible) to find. My goal is to reach a stage where there is no
> visible VMWare process in my honeypot. I also know that it is almost
> impossible to reach it, but we need high goals to keep us working...
> right?
> ;-)
>
There arent any vmware processes running per se in the honeypot the
problem is that many OSs recognize the disk as of vmware type, and
the same for the ethernet and other such devices. Regarding the MAC
address that is configuratable so its no issue.
 
Also dont install the vmware-tools on the guest.

> For a start, I would be happy with a solution (maybe a tool) that hides
> or "camouflage" the VMWare process from the OS Process List.
>
> Any ideas?
> Regards
> Bruno
> ______________________________________
> Bruno Miguel Abrantes de Campos e Castro
> Mail To:
> bcastro_at_portugalmail.pt
> bcastro_at_dei.uc.pt
> ______________________________________
Received on Nov 04 2002

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos