Re: deploying honeypots...
[email protected] Sun, 21 Aug 2005 19:24:13 -0400
| Newsgroups | gmane.comp.security.honeypots |
|---|---|
| Message-ID | <[email protected]> |
On Sat, 20 Aug 2005 12:41:20 +0300, Ahmed Ameen said: > For you first question I would say leave them with no patches, the > opjective is to attract the black-hat community. This is so counter-productive as to be totally nuts. Last I checked, the DSHield survival-time estimate was sitting around 20-25 minutes. Do you *really* want a honeypot that will get whacked twice an hour by the worm du jour? If you want to use an unpatched system so you can catch new exploits, the only sane thing to do is to park it behind a good filtering IPS of some sort that munches the packets for all the exploits you already know about - if it's something that already has a Snort signature, you're probably disinterested in it. Anything useful (such as the rate you see any given exploit or what known exploits a blackhat throws before popping off a 0-day) can be extracted from your IPS logs, which is a lot easier than having to re-image 50 times a day....
signature.asc
(application/pgp-signature, 226 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.2 (GNU/Linux) Comment: Exmh version 2.5 07/13/2001 iD8DBQFDCQ0dcC3lWbTT17ARAr7+AJ4q0MycV84jSRoj2KIDVqw37Vl/VwCgqUPV mv8F2Pgml5s096OK94kFlK4= =FbWG -----END PGP SIGNATURE-----