Honeypots mailing list archives

Re: Sebek-WIN32 v3.0.4


From: "Jamie Riden" <jamie.riden () gmail com>
Date: Tue, 17 Jun 2008 13:26:37 +0100

2008/6/17  <forensicist () gmail com>:
I have scanned Sebek-WIN32 v3.0.3 & Sebek-WIN32 v3.0.4 but both are infected and AV detected it as a Malware.

Hi there,

Can you tell us which AV software you are using, and what malware it
claims to detect?

I guess it's just detecting  it as a generic rootkit-type package.

Also, when I restarted my PC1 after installation of Sebek-WIN32 v3.0.3 and restarted my PC2 after installation of 
Sebek-WIN32 v3.0.4, BLUE screen error occur.

I am using  Win 2003 server Enterprise Edition with Sp2 and HoneyNet CD-ROM roo-1.4.hw-20080423134017.

I doubt it's been tested with Win 2K3 Enterprise Edition, because EE
1) is expensive and 2) has features which aren't particularly needed
for honeypots.

I wouldn't run AV software at the same time as sebek, if that's what
you're doing. If so, try disabling the AV and see what happens.

Hopefully someone can say if they've got it working with plain Win 2K3 or not.

cheers,
 Jamie
-- 
Jamie Riden / jamesr () europe com / jamie () honeynet org uk
UK Honeynet Project: http://www.ukhoneynet.org/


Current thread: