Re: DNS honeypots?

[email protected] Tue, 02 Mar 2010 16:48:59 -0500
Newsgroups gmane.comp.security.honeypots
Message-ID <15151.1267566539@localhost>
--==_Exmh_1267566539_3955P
Content-Type: text/plain; charset=us-ascii

On Tue, 02 Mar 2010 15:00:43 EST, Jason Lewis said:
> Anyone have any pointers to dns honeypots or maybe just BIND
> configurations that would allow logging of malicious queries without
> actually executing them?

Out of curiosity, how do you get traffic directed to the honeypot without
listing it in an NS entry for an SOA?  Give it a hostname like ns1.exampe.com
and hope that works?


--==_Exmh_1267566539_3955P
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)
Comment: Exmh version 2.5 07/13/2001

iD8DBQFLjYfLcC3lWbTT17ARAlqDAKD6soZB3r3iXjpvq890+lEj2Le0OwCdHkoW
RjiK0r3BqbSJydhe8ISKBUs=
=oDvp
-----END PGP SIGNATURE-----

--==_Exmh_1267566539_3955P--