Honeypots mailing list archives

Config Help : Honeyd giving Segmentation Fault


From: skill2die4 () secguru com
Date: Wed, 6 Apr 2005 19:42:18 -0500 (CDT)

Host Information
==================================
wlan0 :: inet addr:192.168.1.105
uname :: Linux 2.6.10-1.770_FC3

config.network
-----------------
#Route Enteries
route entry 192.168.1.111 network 192.168.2.0/24
route 192.168.1.111 link 192.168.2.0/24
route 192.168.1.111 link 192.168.1.0/24
# Router - 192.168.1.111
create router
set router personality "Cisco IOS 11.3 - 12.0(11)"
set router default tcp action reset
set router default udp action reset
add router tcp port 23 "/usr/bin/perl scripts/cisco/router-telnet.pl"
bind 192.168.1.111 router


honeyd message
-----------------
[~~@Matrix honeyd]# arpd 192.168.1.111 192.168.2.0/24
[~~@Matrix honeyd]# honeyd -p nmap.prints -f config.network 192.168.1.111
192.168.2.0/24 -d
Honeyd V1.0 Copyright (c) 2002-2004 Niels Provos
honeyd[18242]: started with -p nmap.prints -f config.network -d
192.168.1.111 192.168.2.0/24
Warning: Impossible SI range in Class fingerprint "IBM OS/400 V4R2M0"
Warning: Impossible SI range in Class fingerprint "Microsoft Windows NT
4.0 SP3"
honeyd[18242]: listening promiscuously on wlan0: (arp or ip proto 47 or
(udp and src port 67 and dst port 68) or (ip and (host 192.168.1.111 or
net 192.168.2.0/24))) and not ether src 00:0c:41:16:94:59
honeyd[18242]: HTTP server listening on port 80
honeyd[18242]: HTTP server root at /usr/local/share/honeyd/webserver/htdocs
honeyd[18242]: Demoting process privileges to uid 32767, gid 32767
honeyd[18242]: arp reply 192.168.1.111 is-at 00:0c:41:16:94:59
honeyd[18242]: Sending ICMP Echo Reply: 192.168.1.111 -> 192.168.1.101
Segmentation fault


Problem
--------------
honeyd dies when i try to ping(after couple of replies as seen above) or
even telnet to 192.168.1.111.


Any clues ?


Thanks in advance.

-=skillz=-


Current thread: