Honeypots mailing list archives

Honeywall with some problems


From: George <george.p123 () gmail com>
Date: Wed, 22 Feb 2006 14:59:50 +0200

Hello!
I just setup the honeywall cdrom, with a honeypot runing Windows XP
SP1. First i updated the system using yum, and then i configured the
honeywall in the folowing mode:

1. eth0 as management interface
2. eth1 as external interface
2. eth2 as internal interface

After that, i setup sebeck on the honeypot and i started the walleye interface.

After the login, the first problem was that when i clicked on the
admin section, i got the following error:

"could not get CONFDIR"
Is this a bug?

Second problem was that the router gave the ip to the honeypot using
dhcp, and the honeypot can't take its network settings. Can i set
iptables so that the honeypot has full acces to dhcp server?


Third, i what to use this honeypot to catch spam. How can i set snort
to extract me the mails that exit from honeypot? Is there another
method to catch them, other than tcpdump logs?

The last problem is that sometimes, the honeypot cat't be accesed from
outside, but from the honeypot i can acces the outside network. Did i
configured something wrong?


Thanks in advice.
George

Current thread: