Welcome, Guest. Please login or register.
November 18, 2008, 12:59:32 PM

Login with username, password and session length

212122 Posts
24512 Topics
57688 Members

Latest Member: Barilla

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  General Category
| |-+  Which Product do you want Comodo to develop next?
| | |-+  HoneyPot
« previous next »
Pages: [1] Go Down Print
Author Topic: HoneyPot  (Read 1415 times)
Júštiñ™
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 2837



« on: June 27, 2006, 11:33:20 AM »

Hi,

I have been after a free HoneyPot for Windows, that has a GUI and can help catch malware (Melih knows I have been after one) the honeypots I have looked at have either not been free or have been too much of a hassle to set them up (partitioning the drive and things like that) anyways I know if proble won't happen but I would like a HoneyPot.

Thanks,

Justin
Logged

When the power of love, overcomes the love of power, the world will know peace.

~Jimi Hendrix
panic
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 5631


... and I say to myself, "What a wonderful world"


« Reply #1 on: June 27, 2006, 11:51:29 AM »

Hi,

I have been after a free HoneyPot for Windows, that has a GUI and can help catch malware (Melih knows I have been after one) the honeypots I have looked at have either not been free or have been too much of a hassle to set them up (partitioning the drive and things like that) anyways I know if proble won't happen but I would like a HoneyPot.

Thanks,

Justin

Hey Justin,

The simplest way to make a honeypot for free is to have a PC with two hard drives (call them A and B). Set Windows up on each drive, separately, of course. Disconnect drive B (this will be our "real" Windows install and will have the same IP range as your LAN and have all security software running) and leave drive A attached as bootable, but without any security software running. Make certain that the IP address is in a different range to the rest of your LAN. Install the web server component and allows this PCs IP out to the internet - I assure you,  someone will notice the server pretty damn quickly! Surf to all the suspect sites you can find, to make certain the PC is compromised.

When you are done, or just want to have a look, power down, connect drive B as the bootable drive and make drive A secondary. Boot Windows and have a look at your second drive.

PLEASE NOTE - THIS IS NOT FOOLPROOF! THIS IS NOT FOR THE FAINT OF HEART! THIS IS NOT AN IRON CLAD, SEGREGATED, DMZ'd HONEYPOT! YOU ARE INVITING BAD GUYS INTO YOUR HOUSE AND BAD GUYS CAN DO BAD THINGS!

Hope this helps,
Ewen :-)
 (WCF3) (WCF3) (WCF3)
Logged

As your mums would say, "If you can't play nice with all the other kiddies, go home".
All users are asked to please read and abide by the  Comodo Forum Policy.
If you don't like it, don't use the forum.
Júštiñ™
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 2837



« Reply #2 on: June 27, 2006, 01:32:08 PM »

Hi,

This would work but I don't have another copy of Windows to put on another HDD, I could partition I suppose but I would need to either reformat or partition using 3rd party software. I was thinking along the lines of a honeypot like KFSensor.
Logged

When the power of love, overcomes the love of power, the world will know peace.

~Jimi Hendrix
Typhoon
Newbie
*
Offline Offline

Posts: 1


« Reply #3 on: October 31, 2008, 01:51:18 PM »

since a Honeypot is requested for some time ago Smiley.

i would rather see a Tarpit, the basics are the same afaik but there's some differences


Tarpits <
Trap hackers, slow down the spread of worms and stall spammers by creating tarpits. A tarpit is a trap for harmful intruders. VisNetic Firewall accepts TCP connections but never replies and ignores disconnect requests. This leaves ports scanners and hackers stuck for hours, even days.

this procedure works and when the attacker is stuck long enough the OS he use will give up and then crash in someway. the tarpit just keeps accepting and stalling the port from the attacker. i tested the procedure some time ago with Visnetic firewall and then got a friend to 'attack' me he ended up with a hung up Pc.

cheers and keep up the good and flawless work.
Logged
Tags:
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Firewall
Page created in 1.624 seconds with 18 queries.
Powered by SMF 1.1.7 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com