Re: BB, SNMP, security
Jeff Stoner <[email protected]> 17 Feb 2004 10:00:20 -0500
| Newsgroups | gmane.network.bb4.devel |
|---|---|
| Organization | Blackboard, Inc. |
| Message-ID | <[email protected]> |
On Tue, 2004-02-17 at 02:26, Mouton Blanc wrote: > I am using BB to monitor some honeypots as part of my > intrusion detection system. However, O'Reilly's > "Practical Unix & Internet Security" does not > recommend using SNMP as part of an intrusion detection > system or any security infrastructure system. > So I am wondering what the potential security issues > are regarding using BB and the use of SNMP, snmptrap > in particular. > > I think one of the issue could be that by using > snmptrap, the intruder would be able to figure out the > BB server which I want to keep hidden in my case. Does > my problem make sense? I hope I am not > misunderstanding how BB works. Big Brother is not an SNMP-based monitoring tool. It does have limited SNMP capabilities. Big Brother uses its own proprietary text-based communications protocol between the client and the server. Actually, it wouldn't matter if you used SNMP, the snmptrap integration script for Big Brother or just Big Brother itself - they all report back to the Big Brother server. You could: * hack the kernel/libraries/binaries yourself to hide the monitoring process(es), network connection(s) and possibly directories/files so intruders to your honeypot won't find them * use bb-fetch from deadcat.net to do a server-pull - which has its own implications for security * something else I can't think of right now but is really clever and worth billions of dollars in the hands of the right marketing and sales people BTW, I am not a security expert. Books are not security experts. A security expert is someone who knows "it's not a matter of 'if' but a matter of 'when'" and who can put the proper policies, procedures and equipment/resources in place. -- --Jeff Blackboard Operations & Support This email may contain privileged and confidential information. It is intended only for the use of the adressee(s). I'll further add that if this message is not digitally signed or encrypted using one of my keys, than I can deny composing it in the first place. -- =-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-==-=-=-=-=-=-=-=-=-=-=-= To unsubscribe from this list send e-mail to mailto:[email protected] with unsubscribe bbd in the BODY of the message.