Honeypots mailing list archives

Re: Oracle DB honeypot?


From: Stuart Thomas <stuartpaulthomas () gmail com>
Date: Thu, 15 Jun 2006 20:01:20 +0100


This was one of the problems I found with my 9i OracleDB honeyDBnet project in 2003, utilising a distinct (i.e. separate from the corp owned public ip's, but interesting enough to attract the big fly's) but interesting IP segment, as well as a populated site interesting and tempting enough to be attacked. Not an uncommon problem I suspect! :-)








Ronald van der Westen wrote:
I dont think you want to watch whole day to a network sniffer :)

-----Oorspronkelijk bericht-----
Van: hypermodest () gmail com [mailto:hypermodest () gmail com] Verzonden: zaterdag 10 juni 2006 4:13
Aan: honeypots () securityfocus com
Onderwerp: Oracle DB honeypot?

Hello.
Does anybody have idea how to organize Oracle DB honeypot, to attract
crackers to Listener service, iSQL*Plus service, etc?
It's easy to install Oracle DB, start network sniffer and wait, but how to
attract anyone?




--
Stu Thomas
Freelance security consultant (UK)
CISMP(ISEB), GSEC
Web: http://www.ethicalhacking.us


Current thread: