Re: DNS honeypots?
[email protected] Tue, 02 Mar 2010 16:48:59 -0500
| Newsgroups | gmane.comp.security.honeypots |
|---|---|
| Message-ID | <15151.1267566539@localhost> |
--==_Exmh_1267566539_3955P Content-Type: text/plain; charset=us-ascii On Tue, 02 Mar 2010 15:00:43 EST, Jason Lewis said: > Anyone have any pointers to dns honeypots or maybe just BIND > configurations that would allow logging of malicious queries without > actually executing them? Out of curiosity, how do you get traffic directed to the honeypot without listing it in an NS entry for an SOA? Give it a hostname like ns1.exampe.com and hope that works? --==_Exmh_1267566539_3955P Content-Type: application/pgp-signature -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) Comment: Exmh version 2.5 07/13/2001 iD8DBQFLjYfLcC3lWbTT17ARAlqDAKD6soZB3r3iXjpvq890+lEj2Le0OwCdHkoW RjiK0r3BqbSJydhe8ISKBUs= =oDvp -----END PGP SIGNATURE----- --==_Exmh_1267566539_3955P--