Honeypots mailing list archives
Re: Attack/Benign Packet Determination
From: Mcen navaraj <mcensamuel () yahoo com>
Date: Fri, 29 Aug 2003 14:08:00 -0700 (PDT)
hi steven, --- Steven DeFord <steve () redlance singingtree com> wrote:
I'm new at this, so you'll have to excuse me, but in the handful of white papers I've read, and from reading traffic on this list, I've not seen any .....
fine...
clear way that honeypot routers determine what traffic is bad (destined for the honeypot) and which isn't. People on the list seem to assume that "All traffic on the honeynet is inherently an attack,"
It doesnt know howto differentiate the traffic ... see the basic of honeypot is putting some vulnerable machine in the internet and check anybody trying on that machine..without the need to access that machine by them...
but how does one know which traffic is bad and which isn't? At least, how do you tell any better than an IDS?
hello man...IDS are defensive method...first try to learn the basics of IDS and type of IDS and usage of IDS... Honeypots are used to attract hackers to your system and learn from them...ok..understood ?
For example, in a recent post, someone mentioned the fact that a blackhat who's compromised a honeynet host can't get any production information out of sniffing the network,
this is 100% sure...but blackhat can use your system for other DoS attack or use your system to hack others machine.... U should take care about this...
but what if some user's authentication session were misdirected to the honeynet? Then the blackhat could (essentially) passwordsniff legitimate users' logon information, and could then infect production machines more easily. The only benefit of a honeynet, it seems, is improved logging, not due to more accurate packet detection, but simply more loggers. Could not, in theory, one set up a honeynet in the production environment? (Other than the previously-mentioned problem of privacy laws and the like.) Steven DeFord steve () singingtree com
__________________________________ Do you Yahoo!? Yahoo! SiteBuilder - Free, easy-to-use web site design software http://sitebuilder.yahoo.com
Current thread:
- Attack/Benign Packet Determination Steven DeFord (Aug 29)
- RE: [inbox] Attack/Benign Packet Determination Curt Purdy (Aug 29)
- RE: [inbox] Attack/Benign Packet Determination Roger A. Grimes (Aug 29)
- Re: Attack/Benign Packet Determination Floydman (Aug 29)
- Re: Attack/Benign Packet Determination Mcen navaraj (Aug 29)
- Re: Attack/Benign Packet Determination Valdis . Kletnieks (Aug 29)
- RE: [inbox] Attack/Benign Packet Determination Curt Purdy (Aug 29)
