<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Honeypots (honeypots) Mailing List</title>
<link>http://seclists.org/#honeypots</link>
<atom:link href="http://seclists.org/rss/honeypots.rss" rel="self" type="application/rss+xml" />
<description>Discussions about tracking attackers by setting up decoy honeypots or entire honeynet networks.</description>
<language>en-us</language><ttl>60</ttl>
<item><title>Re: regarding setup of a honeypot in restricted environment</title><description>Posted by Valdis.Kletnieks_at_vt.edu on Nov 25&lt;p&gt;


&lt;p&gt;
On Mon, 24 Nov 2008 21:09:17 EST, Noah Meyerhans said:
&lt;br /&gt;
&lt;p&gt;&amp;gt; A lot of the fun malware is client-side these days, anyway, so why don&#39;t
&lt;br /&gt;
&amp;gt; you make a client honeypot: http://en.wikipedia.org/wiki/Honeyclient
&lt;br /&gt;
&lt;p&gt;Amen to that.  It&#39;s pretty much directly attributable to 2 specific things:
&lt;br /&gt;
&lt;p&gt;1) XP SP2...</description>
<link>http://seclists.org/honeypots/2008/q4/0029.html</link><guid isPermaLink="true">http://seclists.org/honeypots/2008/q4/0029.html</guid>
<pubDate>Tue, 25 Nov 2008 08:34:27 -0500</pubDate></item>
<item><title>RE: regarding setup of a honeypot in restricted environment</title><description>Posted by Bhatnagar Mayank on Nov 25&lt;p&gt;


&lt;p&gt;
Hi all,
&lt;br /&gt;
&lt;p&gt;Thanks for the many responses I received on this thread.
&lt;br /&gt;
Thanks Antonio, Jesper, Noah, Dharm for some valuable suggestions including
&lt;br /&gt;
&lt;p&gt;1. redirection of some common TCP/UDP ports
&lt;br /&gt;
2. MAC spoofing
&lt;br /&gt;
3. client honeypot setup
&lt;br /&gt;
&lt;p&gt;Well I plan to begin with initial client honeypot set up and...</description>
<link>http://seclists.org/honeypots/2008/q4/0028.html</link><guid isPermaLink="true">http://seclists.org/honeypots/2008/q4/0028.html</guid>
<pubDate>Tue, 25 Nov 2008 11:46:40 +0530</pubDate></item>
<item><title>CanSecWest 2009 CFP (March 18-20 2009, Deadline December 8 2008)</title><description>Posted by Dragos Ruiu on Nov 24&lt;p&gt;


&lt;p&gt;
Call For Papers
&lt;br /&gt;
&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;The CanSecWest 2009 CFP is now open.
&lt;br /&gt;
&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Deadline is December 8th, 2008.
&lt;br /&gt;
&lt;p&gt;CanSecWest CALL FOR PAPERS
&lt;br /&gt;
&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;VANCOUVER, Canada -- The tenth annual CanSecWest applied
&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;technical security...</description>
<link>http://seclists.org/honeypots/2008/q4/0027.html</link><guid isPermaLink="true">http://seclists.org/honeypots/2008/q4/0027.html</guid>
<pubDate>Mon, 24 Nov 2008 21:32:32 -0800</pubDate></item>
<item><title>Fwd: regarding setup of a honeypot in restricted environment</title><description>Posted by dharm on Nov 25&lt;p&gt;


&lt;p&gt;
---------- Forwarded message ----------
&lt;br /&gt;
From: dharm &amp;lt;dharm910_at_gmail&amp;#46;com&amp;gt;
&lt;br /&gt;
Date: Tue, Nov 25, 2008 at 10:36 AM
&lt;br /&gt;
Subject: Re: regarding setup of a honeypot in restricted environment
&lt;br /&gt;
To: Jesper Jurcenoks &amp;lt;jesper.jurcenoks_at_netvigilance&amp;#46;com&amp;gt;
&lt;br /&gt;
Cc: &amp;quot;Bhatnagar,...</description>
<link>http://seclists.org/honeypots/2008/q4/0026.html</link><guid isPermaLink="true">http://seclists.org/honeypots/2008/q4/0026.html</guid>
<pubDate>Tue, 25 Nov 2008 10:41:27 +0530</pubDate></item>
<item><title>Re: regarding setup of a honeypot in restricted environment</title><description>Posted by Noah Meyerhans on Nov 24&lt;p&gt;


&lt;p&gt;
On Mon, Nov 24, 2008 at 05:03:52PM +0530, Bhatnagar, Mayank wrote:
&lt;br /&gt;
&amp;gt; Suppose if I want to install a honeypot in an environment where it
&lt;br /&gt;
&amp;gt; cannot get a public facing IP but the machine o which honeypot is to be
&lt;br /&gt;
&amp;gt; installed has an access to Internet 
&lt;br /&gt;
&amp;gt; 	1. via another proxy or
&lt;br /&gt;
&amp;gt;...</description>
<link>http://seclists.org/honeypots/2008/q4/0025.html</link><guid isPermaLink="true">http://seclists.org/honeypots/2008/q4/0025.html</guid>
<pubDate>Mon, 24 Nov 2008 21:09:17 -0500</pubDate></item>
<item><title>RE: regarding setup of a honeypot in restricted environment</title><description>Posted by Jesper Jurcenoks on Nov 24&lt;p&gt;


&lt;p&gt;
Hi Mayank.
&lt;br /&gt;
&lt;p&gt;Assuming you have the follwiong setup:
&lt;br /&gt;
&lt;p&gt;dsl line without static IP to home/soho office, a honeypot behind the dsl-router (with builtin firewall function), and you can put the Honeyd on a fixed internal IP address.
&lt;br /&gt;
&lt;p&gt;Then you can do the following simple honeypot.
&lt;br /&gt;
&lt;p&gt;Redirect one of more...</description>
<link>http://seclists.org/honeypots/2008/q4/0024.html</link><guid isPermaLink="true">http://seclists.org/honeypots/2008/q4/0024.html</guid>
<pubDate>Mon, 24 Nov 2008 08:33:34 -0800</pubDate></item>
<item><title>regarding setup of a honeypot in restricted environment</title><description>Posted by Bhatnagar Mayank on Nov 24&lt;p&gt;


&lt;p&gt;
Hi,
&lt;br /&gt;
&lt;p&gt;I am writing this email to know some of your valuable suggestions as to
&lt;br /&gt;
how we can use honeypot in a restricted environment.
&lt;br /&gt;
&lt;p&gt;Suppose if I want to install a honeypot in an environment where it
&lt;br /&gt;
cannot get a public facing IP but the machine o which honeypot is to be
&lt;br /&gt;
installed has an access...</description>
<link>http://seclists.org/honeypots/2008/q4/0023.html</link><guid isPermaLink="true">http://seclists.org/honeypots/2008/q4/0023.html</guid>
<pubDate>Mon, 24 Nov 2008 17:03:52 +0530</pubDate></item>
<item><title>DateTime issue on Honeywall</title><description>Posted by secpuffy on Nov 17&lt;p&gt;


&lt;p&gt;
Hi,
&lt;br /&gt;
&lt;p&gt;How can I fix the timestamps that appear in walleye? and honeywall?
&lt;br /&gt;
I am in America/Los_Angeles PDT timezone.
&lt;br /&gt;
&lt;p&gt;thx.
&lt;br /&gt;
Received on Nov 17 2008

</description>
<link>http://seclists.org/honeypots/2008/q4/0022.html</link><guid isPermaLink="true">http://seclists.org/honeypots/2008/q4/0022.html</guid>
<pubDate>Mon, 17 Nov 2008 19:36:18 -0800</pubDate></item>
<item><title>Re: botnet logs</title><description>Posted by Valdis.Kletnieks_at_vt.edu on Nov 17&lt;p&gt;


&lt;p&gt;
On Mon, 17 Nov 2008 10:15:06 EST, dxp said:
&lt;br /&gt;
&lt;p&gt;&amp;gt; Many trojans these days can easily bypass defautl firewall protection in
&lt;br /&gt;
&amp;gt; XP Sp2.  If any of those include self replication with exploit against
&lt;br /&gt;
&amp;gt; some vulnerability (ms08-067) then history will be repeated, to a
&lt;br /&gt;
&amp;gt; certain extent.
&lt;br /&gt;
&lt;p&gt;...</description>
<link>http://seclists.org/honeypots/2008/q4/0021.html</link><guid isPermaLink="true">http://seclists.org/honeypots/2008/q4/0021.html</guid>
<pubDate>Mon, 17 Nov 2008 12:48:53 -0500</pubDate></item>
<item><title>Re: botnet logs</title><description>Posted by Nathan on Nov 17&lt;p&gt;


&lt;p&gt;
Hello!
&lt;br /&gt;
&lt;p&gt;I don&#39;t really get this part. If the host pc you are running honeyd on
&lt;br /&gt;
it is infected, how can you benefit from this with your honeyd? It&#39;s
&lt;br /&gt;
okay to monitor your pc&#39;s traffic, and control the outgoing malicious
&lt;br /&gt;
packets, but where honeyd comes in? The only thing i can think of, to
&lt;br /&gt;
watch...</description>
<link>http://seclists.org/honeypots/2008/q4/0020.html</link><guid isPermaLink="true">http://seclists.org/honeypots/2008/q4/0020.html</guid>
<pubDate>Mon, 17 Nov 2008 16:31:32 +0100</pubDate></item>
<item><title>Re: botnet logs</title><description>Posted by Gabriele Zanoni on Nov 17&lt;p&gt;


&lt;p&gt;
Il Saturday 15 November 2008 13:20:21 Nathan ha scritto:
&lt;br /&gt;
&amp;gt; Hi,
&lt;br /&gt;
&amp;gt;
&lt;br /&gt;
&amp;gt; I have to make a brief presentation about honeypots and botnets
&lt;br /&gt;
&amp;gt; relation. I chose honeyd as an example honeypot, i am already running
&lt;br /&gt;
&amp;gt; it, but due to limited ip resources and short time, I wasn&#39;t able to
&lt;br /&gt;
...</description>
<link>http://seclists.org/honeypots/2008/q4/0019.html</link><guid isPermaLink="true">http://seclists.org/honeypots/2008/q4/0019.html</guid>
<pubDate>Mon, 17 Nov 2008 10:40:00 +0100</pubDate></item>
<item><title>Re: botnet logs</title><description>Posted by Valdis.Kletnieks_at_vt.edu on Nov 16&lt;p&gt;


&lt;p&gt;
On Sat, 15 Nov 2008 13:20:21 +0100, Nathan said:
&lt;br /&gt;
&amp;gt; I have to make a brief presentation about honeypots and botnets
&lt;br /&gt;
&amp;gt; relation. I chose honeyd as an example honeypot, i am already running
&lt;br /&gt;
&amp;gt; it, but due to limited ip resources and short time, I wasn&#39;t able to
&lt;br /&gt;
&amp;gt; gather any valueable...</description>
<link>http://seclists.org/honeypots/2008/q4/0018.html</link><guid isPermaLink="true">http://seclists.org/honeypots/2008/q4/0018.html</guid>
<pubDate>Sun, 16 Nov 2008 22:51:52 -0500</pubDate></item>
<item><title>botnet logs</title><description>Posted by Nathan on Nov 15&lt;p&gt;


&lt;p&gt;
Hi,
&lt;br /&gt;
&lt;p&gt;I have to make a brief presentation about honeypots and botnets
&lt;br /&gt;
relation. I chose honeyd as an example honeypot, i am already running
&lt;br /&gt;
it, but due to limited ip resources and short time, I wasn&#39;t able to
&lt;br /&gt;
gather any valueable information.
&lt;br /&gt;
I would be pleased, if anyone could send me a...</description>
<link>http://seclists.org/honeypots/2008/q4/0017.html</link><guid isPermaLink="true">http://seclists.org/honeypots/2008/q4/0017.html</guid>
<pubDate>Sat, 15 Nov 2008 13:20:21 +0100</pubDate></item>
<item><title>Re: Stealth VM</title><description>Posted by Thorsten Holz on Nov 10&lt;p&gt;


&lt;p&gt;
Hi Robert,
&lt;br /&gt;
&lt;p&gt;On Mon, Nov 10, 2008 at 4:33 PM, Robert Sandilands
&lt;br /&gt;
&amp;lt;rsandilands_at_authentium&amp;#46;com&amp;gt; wrote:
&lt;br /&gt;
&lt;p&gt;&amp;gt; If you can provide a better unbiased view of current threats I would
&lt;br /&gt;
&amp;gt; love for you to tell the world about it. Whatever the limitations of the
&lt;br /&gt;
&amp;gt; Wildlist may be, it is...</description>
<link>http://seclists.org/honeypots/2008/q4/0016.html</link><guid isPermaLink="true">http://seclists.org/honeypots/2008/q4/0016.html</guid>
<pubDate>Mon, 10 Nov 2008 22:09:45 +0100</pubDate></item>
<item><title>Re: Stealth VM</title><description>Posted by Robert Sandilands on Nov 10&lt;p&gt;


&lt;p&gt;
Hi Thorsten,
&lt;br /&gt;
&lt;p&gt;If you can provide a better unbiased view of current threats I would
&lt;br /&gt;
love for you to tell the world about it. Whatever the limitations of the
&lt;br /&gt;
Wildlist may be, it is the best unbiased view we have on the threats out
&lt;br /&gt;
there. It is easy to criticize something and I think the Wildlist...</description>
<link>http://seclists.org/honeypots/2008/q4/0015.html</link><guid isPermaLink="true">http://seclists.org/honeypots/2008/q4/0015.html</guid>
<pubDate>Mon, 10 Nov 2008 10:33:22 -0500</pubDate></item>
</channel></rss>