Honeypots mailing list archives

Re: logging facility


From: "KeyFocus" <support () keyfocus net>
Date: Thu, 28 Aug 2003 15:55:13 +0100

How can encrypted traffic be decrypted with a honeypot?

SSL is designed to prevent man in the middle attacks, which is why an IDS
cannot examine the traffic.

A honeypot is the end point of the SSL traffic so it decrypts it anyway. All
thats needed is a means to log it.

- Tom
www.keyfocus.net


Current thread: