Honeypots mailing list archives

Re: Java-based honeypots?


From: Mark Curphey <mark () curphey com>
Date: 26 May 2003 07:31:16 -0400

Whilst its not a Honeypot today, take a look at OWASP WebGoat. Its an
intentionally broken web application to teach people web security. Its
built in Java and runs on Tomcat. We had plans at one point to "skin"
it. It has the usual cross site scripting and SQL injection problems
that web hackers will look for. 

The current interface is an interactive training one but you could
easily change that to an online bank or similar. 

If you are interested in helping with that work, please drop me a line.

http://www.owasp.org/webgoat/




On Sun, 2003-05-25 at 14:45, Jon Baer wrote:
Hi,

Are there any Java-based Honeypots openly available anywhere?

- Jon
-- 
Mark Curphey <mark () curphey com>


Current thread: