Honeypots mailing list archives

Question about Dynamic Honeypots.


From: Mahdi samadi <samadi () cabinet amnafzar com>
Date: Mon, 22 Sep 2003 10:22:04 +0430 (IRST)

Dear Freinds,
I studied an article by Lance at http://www.securityfocus.com/infocus/1731
but i thinks that itsĀ idea does not working in some conditions,
for example, i think that passive fingerprinting not works in networks
that have swiths,
Are you have an idea in this situation? (arp spoofing is one solution but
it seems that is not good solution)
I have also another question? i think that there will be another feature
for future honeypot/nets, they must plug into networks and attract all
anomaly/malicous traffics to ourself.
At the least it must redirect the attacks traffic to itself. I am be so
glad to know your ideas about my notes,
await for your response,
Accept my greetings,
Regards,
--samadi



Current thread: