Re: DNS honeypots?
Brent Huston <[email protected]> Wed, 3 Mar 2010 10:55:02 -0400
| Newsgroups | gmane.comp.security.honeypots |
|---|---|
| Message-ID | <[email protected]> |
Likely nothing today, most malware isn't smart enough to figure that = out. On Mar 3, 2010, at 10:38 AM, Jason Lewis wrote: > Slightly related, I was wondering what might happen if I made every > query to the honeypot resolve back to the honeypot? >=20 > On Wed, Mar 3, 2010 at 9:20 AM, Brent Huston <[email protected]> = wrote: >> One of the tactics our clients use is that they stand up one of our = HoneyPoint Agents on a decoy box and then send all malicious and failed = queries to that IP address. The HoneyPoint Agent then absorbs the = traffic for analysis. >>=20 >> You can find a little bit about it from one of our customers here, = they wrote it up with us: http://hurl.ws/cbhp >>=20 >> Let me know if that helps! >>=20 >> On Mar 2, 2010, at 4:00 PM, Jason Lewis wrote: >>=20 >>> Anyone have any pointers to dns honeypots or maybe just BIND >>> configurations that would allow logging of malicious queries without >>> actually executing them? >>=20 >>=20