Honeypots mailing list archives

Another honeypot tool?


From: Steve Smith <steve.smith () gcmail maricopa edu>
Date: Wed, 18 Jun 2003 11:17:44 -0700

All the talk about Sebek reminded me to send this info. I'm supposing that some people on this list were at Blackhat 2001 and attended a presentation by Todd MacDermid and Eric Brandwine on a Whitehat kmod rootkit they'd developed called Fnord - the presentation and ppt are available from the BH media archives, btw.

At that time they were unable to release it to the public but that's changed. It's currently only for 2.2 kernels, but seems like a tool with lots of promise. I "discovered" it was available during some insomniac googling awhile back and have been meaning to post.

I'm by no means an expert on it in any way; I built and installed it under RH 6.2 and promptly got buried in "real work". Hope someone finds this info useful; here's the link: http://www.synacklabs.net/projects/fnord/

Regards,
Steve


Current thread: