Honeyd on firewall machine ?

From: George Pontis (gpontis_at_spamcop.net)
Date: 09/23/04

  • Next message: Rich Teer: "Re: Beta testers needed - C to Java byte-code compiler/IDE"
    Date: Thu, 23 Sep 2004 09:05:28 -0700
    
    

    Is it folly to run honeyd on a firewall machine ? I see comments to the effect
    that one should not do this since a honeypot will be interacting with hostile
    agents. But the firewall logs show that the firewall is interacting with hostile
    agents all the time.

    While I do separate the mail and other servers in a small business environment, I
    am comfortable running spamd on the firewall and watch the log with some interest.
    Could I reasonably do the same with honeyd in a systrace sandbox ?


  • Next message: Rich Teer: "Re: Beta testers needed - C to Java byte-code compiler/IDE"

    Relevant Pages

    • Re: Backdoor.Lateda.C
      ... Firewall logs are now clear of any blocked ... > | from connecting to the internet. ... You may have to disable your FireWall or allow FTP.EXE to go through your FireWall ... > It is suggested that you move the report out of c:\mcafee before performing another scan. ...
      (microsoft.public.security.virus)
    • Re: Possible firewall problem?
      ... >>I'm noticing an occasional entry in my firewall logs and I'm not sure if ... >>Could this indicate that packets are somehow getting thru the firewall ... >>The firewall is blocking the outbound packet. ... The only people for me are the mad ones -- the ones who are mad to live, mad to talk, mad to be saved, desirous of everything at the same time, the ones who never yawn or say a commonplace thing, but burn, burn, burn like fabulous yellow Roman candles. ...
      (comp.security.firewalls)
    • Firewall and Internet Reporting Software...Best One?
      ... Firewall and Internet Reporting Software...Best One? ... management/performance reports from our Checkpoint firewall logs and ... sites but found it will not work for our reporting needs (ie it uses a MS ...
      (Security-Basics)
    • Re: Constant internet activity with no programs open
      ... And what do the firewall logs and Process Explorer say? ... You might also try the online virus/malware scan at Trend Micro - ... What was the cause of the "major IE windows opening problem" you refer ...
      (microsoft.public.windowsxp.help_and_support)
    • Re: IPFW - Allowed but Denied is shown in my logs
      ... >>firewall logs and seeing the same things just woke up my curiousity and ... > connection, it's not a disaster. ... > can end up with a system that can't talk over the network reliably. ...
      (freebsd-questions)