Re: deploying honeypots...

[email protected] Sun, 21 Aug 2005 19:24:13 -0400
Newsgroups gmane.comp.security.honeypots
Message-ID <[email protected]>
On Sat, 20 Aug 2005 12:41:20 +0300, Ahmed Ameen said:
> For you first question I would say leave them with no patches, the
> opjective is to attract the black-hat community.

This is so counter-productive as to be totally nuts.

Last I checked, the DSHield survival-time estimate was sitting around 20-25
minutes.  Do you *really* want a honeypot that will get whacked twice an hour
by the worm du jour?

If you want to use an unpatched system so you can catch new exploits, the only
sane thing to do is to park it behind a good filtering IPS of some sort that
munches the packets for all the exploits you already know about - if it's
something that already has a Snort signature, you're probably disinterested
in it.  Anything useful (such as the rate you see any given exploit or what
known exploits a blackhat throws before popping off a 0-day) can be extracted
from your IPS logs, which is a lot easier than having to re-image 50 times
a day....
signature.asc (application/pgp-signature, 226 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2 (GNU/Linux)
Comment: Exmh version 2.5 07/13/2001

iD8DBQFDCQ0dcC3lWbTT17ARAr7+AJ4q0MycV84jSRoj2KIDVqw37Vl/VwCgqUPV
mv8F2Pgml5s096OK94kFlK4=
=FbWG
-----END PGP SIGNATURE-----