Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




pen-test logo Penetration Testing mailing list archives

RE: A kind of Honeypot
From: "Andrew van der Stock" <ajv () e-secure com au>
Date: Thu, 21 Jun 2001 13:43:12 +1000

Pr0n sites do it all the time. Don't browse them with JavaScript turned on.

However, realistically, honeypots and similar ilk are man-traps. I feel
you'd get more information from running a useful web site, and looking your
web logs.

Andrew

-----Original Message-----
From: Nicolas Gregoire [mailto:nicolas.gregoire () 7thzone com]
Sent: Wednesday, 20 June 2001 18:43
To: pen-test () securityfocus com
Subject: A kind of Honeypot


Hi all,

I plan to make a website just for my pen-tests.

This website grabs as much as possible info from the visitors (IP,
browser, proxy, etc ..), tries to exploit some common vulns of browsers
(Guninski's page is a good start for this) and hosts a passive
fingerprinting app.
The victims are "spammed" with some misc. content (p0rn, free CD/DVD,
jokes) linking (or redirecting) to the site.

Has anybody ever do that ?

Nicob


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]