Snort mailing list archives

Re: inside or outside


From: "Seth L. Thomas" <s.thomas4 () comcast net>
Date: Fri, 19 Jul 2002 16:32:24 -0400

"McCammon, Keith" wrote:

Have you considered a honeypot?  Granted, there is a fair amount or research 
and responsibility involved, but if you feel comfortable and know what you're 
doing, then a honeypot is an excellent way to learn without putting your own 
data at risk.

I've considered setting up a honeypot but not before I learn alot more than
what I know now. It's a tremendous responsibility considering if not setup
properly could backfire. 

For now, though, what I plan on doing is punching a hole through the
firewall to a common port like portmapper (111) then placing something on
it that'll allow the port to appear open like running nc -l -p 111 -v along
with snort and seeing what I capture.




-- 
Join the Navy; sail to far-off exotic lands, meet 
exciting interesting people, and kill them.


-------------------------------------------------------
This sf.net email is sponsored by:ThinkGeek
Welcome to geek heaven.
http://thinkgeek.com/sf
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: