Honeypots mailing list archives

New whitepaper released & a question to the community


From: "Michael Anuzis" <michael_anuzis () hotmail com>
Date: Sun, 02 Mar 2003 16:53:40 -0500

Fellow honeypotting community, I've released another whitepaper recently. This time targetted more towards beginners in the honeypot research realm, regarding some of the diff pros/cons that can be seen with different the different types of access you decide to give your honeypot. I realize the list I created is small and only covers 5 basic examples out of the thousands of possibilities. The whitepaper was simply intended to offer a basic introduction to the topic of how you allow access, which may not seem so important to a beginner at first glance. For those interested the paper is available at http://www.lucidic.net/whitepapers/manuzis-2-22-2003.html

Also, a question to the community. I couldn't continue my honeypotting research for a while due to my life getting excessively busy, but now I've tried returning to my research and setting up a few honeynets and I'm not getting any bites at all. I've got a default install of a RedHat7.2 box set up with wuftpd2.6.1-18 enabled which (I'm pretty sure) is vuln to a remote root compromise, but no one's taking it. Could anyone out there who is currently/actively running successful honeypots offer me any advice on which OS/vulnerability (bait) I may try if I want to catch some of today's hackers?

Thanks in advance!




Michael Anuzis, CCNA
Network Security Consultant
http://www.anuzisnetworking.com
http://www.lucidic.net - The Distributed Honeypot Project




_________________________________________________________________
Add photos to your messages with MSN 8. Get 2 months FREE*. http://join.msn.com/?page=features/featuredemail


Current thread: