Honeypots mailing list archives

RE: Honeypots on windows


From: "Beauford, Jason" <jbeauford () EightInOnePet com>
Date: Tue, 23 Nov 2004 17:55:34 -0500

Maybe you can do something with BARTS Bootable Windows-PE disk...

http://www.nu2.nu/pebuilder/

JMB



-----Original Message-----
From: Hugo González [mailto:hugo.gonzalez () itslp edu mx] 
Sent: Tuesday, November 23, 2004 9:55 AM
To: honeypots () securityfocus com
Subject: Re: Honeypots on windows


What's up Ehsan!

i think there is a licencing problem using the windows kernel, so you should 
take other alternative to make the live DVD-ROM honeypot

Thas why, de live CD-ROMs uses GNU/Linux or BSD

Hugo.
ITSLP

----- Original Message ----- 
From: "Ehsan Hosseini" <amirehsan_h () yahoo com>
To: <honeypots () securityfocus com>
Sent: Monday, November 22, 2004 5:50 AM
Subject: Honeypots on windows


Dearest members,

Im in my last year of a degree in computer science and
like so many others I have decided to do my thesis on Honeypots and 
more specifically "building a bootable DVD-ROM" that you can kind of 
plug-n-play and deploy your honeypots or honeynets.

Sort of like the Hoenywall CD already made but im
trying to see if its possible to do it on a particular windows 
platform ,say for example windows 2000 professional.

The first question that comes to my mind is if its at
all possible to some how modify the windows Kernel or
even rap it up in something else but still leave it functional.

Or if its even possible to extract the kernel from
windows or how would I go about getting the absolute
bare bone and minimum requirements that is needed to
have a functional windows operating system.

Any sort of help would be greatly appreciated on this
issue.

Also if anyone has gone through the same as as my self
in the past and know of great sources of information
,I would truly appreciate their help in this.

Thanks in advance.

Ehsan Hosseini





__________________________________
Do you Yahoo!?
Meet the all-new My Yahoo! - Try it today! http://my.yahoo.com





Current thread: