Honeypots mailing list archives

Re: Know Your Enemy: Learning with VMware


From: Lance Spitzner <lance () honeynet org>
Date: Wed, 29 Jan 2003 07:51:53 -0600 (CST)

On Mon, 27 Jan 2003, Alexandre Dulaunoy wrote:

Yes, this  is a powerful  solution but this  is still not Free  (as in
Freedom  ;-).   Another  point  is  the  fingerprint   of  the  VMware
hardware. How do you  solve that issue ? Is it a  way to do change the
hardware description in VMware ? 

You may want to check out the Virtual Honeynet paper, where we identify
the issues of fingerprinting.  With almost all virtual environments,
you can only reduce the risk of fingerprinting, not eliminate it.

    http://www.honeynet.org/papers/virtual/


PS : Is there some other honeynet running with plex/bochs ?  

There is no whitepaper explaining the use of plex/bochs Honeynets.
However, there is a paper explaining how to build Honeynets using
the OpenSource solution User-Mode Linux.
  
    http://www.honeynet.org/papers/uml/

lance


Current thread: