Re: DNS honeypots?
Jason Lewis <[email protected]> Tue, 2 Mar 2010 17:57:36 -0500
| Newsgroups | gmane.comp.security.honeypots |
|---|---|
| Message-ID | <[email protected]> |
I just figured I'd setup something to log access and see what shows up. I wasn't planning on directing traffic to the system. On Tue, Mar 2, 2010 at 4:48 PM, <[email protected]> wrote: > On Tue, 02 Mar 2010 15:00:43 EST, Jason Lewis said: >> Anyone have any pointers to dns honeypots or maybe just BIND >> configurations that would allow logging of malicious queries without >> actually executing them? > > Out of curiosity, how do you get traffic directed to the honeypot without > listing it in an NS entry for an SOA? =A0Give it a hostname like ns1.exam= pe.com > and hope that works? > >