Honeypots mailing list archives

Re: Max OSX honeypot


From: Skip Duckwall <skip () duckwall net>
Date: Fri, 25 Jun 2004 01:03:34 -0500 (CDT)


I was actually thinking of using the Mac itself rather than running any
sort of virtual services on top of it.  I guess I should have made that
more clear.

I'd like to run something like sebek for capture purposes, but it doesn't
look like they've ported it to osx.  I'm guessing that might classify as
"non-trivial", but I haven't tried yet.

Just asking since it doesn't appear that many people have done any
honeypot work with a mac yet...

Alva Lease 'Skip' Duckwall IV
CISSP, RHCE, SCSA
skip at duckwall d0t net

On Thu, 24 Jun 2004, Jason Sidabras wrote:

Skip Duckwall wrote:

Has anybody done or seen any information about a Max OSX honeypot? I've
got a mac that's sitting around unused that I figure I'll throw to the
wolves...


I haven't seen any work porting something like sebek to osx either...

just curious...

Alva Lease 'Skip' Duckwall IV
CISSP, RHCE, SCSA
skip at duckwall d0t net


It was my understanding that OSX was a modified version of FreeBSD. As
long as you have the gcc tools and dependencies I would think any Unix
honeypot prog would work. Like honeyd or something.

Jason



Current thread: