Re: Honeyd on firewall machine ?

From: erik (erik_at_geenspam.vanwesten.net)
Date: 09/23/04

  • Next message: No Spam Sorry: "Re: when using cvs to update ports, i get: "Disconnecting: Corrupted MAC on input""
    Date: Thu, 23 Sep 2004 19:03:33 +0200
    
    

    George Pontis wrote:

    > Is it folly to run honeyd on a firewall machine ? I see comments to
    > the effect that one should not do this since a honeypot will be
    > interacting with hostile agents. But the firewall logs show that the
    > firewall is interacting with hostile agents all the time.

    But a firewall should not run services. Any services. Certainly not
    supposedly vulnerable services. That is plain stupid.

    >
    > While I do separate the mail and other servers in a small business
    > environment, I am comfortable running spamd on the firewall and watch
    > the log with some interest. Could I reasonably do the same with honeyd
    > in a systrace sandbox ?

    Use a machine in a dmz, safely contained...

    EJ

    -- 
    Remove the obvious part (including the dot) for my email address.
    http://www.vanwesten.net for examples of ipf and pf.
    

  • Next message: No Spam Sorry: "Re: when using cvs to update ports, i get: "Disconnecting: Corrupted MAC on input""

    Relevant Pages

    • lcsrv16.exe
      ... My firewall (Sygate) tells me that I have outgoing traffic from my computer ... my system32 folder, it was created at the same time I fresh installed W2K. ...
      (microsoft.public.win2000.general)
    • Re: Backdoor.Lateda.C
      ... Firewall logs are now clear of any blocked ... > | from connecting to the internet. ... You may have to disable your FireWall or allow FTP.EXE to go through your FireWall ... > It is suggested that you move the report out of c:\mcafee before performing another scan. ...
      (microsoft.public.security.virus)
    • Re: Possible firewall problem?
      ... >>I'm noticing an occasional entry in my firewall logs and I'm not sure if ... >>Could this indicate that packets are somehow getting thru the firewall ... >>The firewall is blocking the outbound packet. ... The only people for me are the mad ones -- the ones who are mad to live, mad to talk, mad to be saved, desirous of everything at the same time, the ones who never yawn or say a commonplace thing, but burn, burn, burn like fabulous yellow Roman candles. ...
      (comp.security.firewalls)
    • Firewall and Internet Reporting Software...Best One?
      ... Firewall and Internet Reporting Software...Best One? ... management/performance reports from our Checkpoint firewall logs and ... sites but found it will not work for our reporting needs (ie it uses a MS ...
      (Security-Basics)
    • Re: Constant internet activity with no programs open
      ... And what do the firewall logs and Process Explorer say? ... You might also try the online virus/malware scan at Trend Micro - ... What was the cause of the "major IE windows opening problem" you refer ...
      (microsoft.public.windowsxp.help_and_support)