Honeypots mailing list archives

How do I make telnet vulnerable to attack?


From: <sae0616 () hotmail com>
Date: 25 Feb 2003 20:34:39 -0000



Hello, I recently installed my first honeypot and it sure
is fun to watch the attacks roll in. I'm seeing this one
attack against telnet that looks like this in the snort log:

cisco
telnet [ip removed] 6669
#'


It looks like some kind of attempt to long in using a default
password of 'cisco'? My question is, how can I allow the telnet
to happen so that I can see what they are doing?


Current thread: