Heffalumps and woozles love honey. So how do we prevent them from getting ours?
So the first time I heard this term was last week. Which means I still have a lot to learn. First lets answer a few questions:
Q. What is a honey pot?
A. Simply put a honey pot is a server that looks too good to pass up for a hacker, and lets you know the network has been compromised amongst other things.
Q. Why use a honey pot?
A. Uses for a honey pot will vary from understanding the attack methods used by hackers, to a base start for an IDS (intrusion detection system) or IPS (intrusion prevention system).
Q. How do I set one up?
A. Well there are Many ways to do this. The simplest is downloading a Virtual Appliance that has a lot of the tools already installed. That can be found here. HoneyDrive has its benefits and fails just as all such services do. I am still looking into other options as HoneyDrive is the first and only one I have played with at the moment, but it has some sweet looking graphs with kippo already set up.
It also has a "Playlog" that you can playback and see everything a user typed once they got in.
So I got this set up and played with it a bit and found a few issues off the bat.
1) An updated ssh version won't recognize kippo due it it requiring stronger keys.
2) Some errors it throws back will let me detect that its not actually an ssh client.
In the mean time I will continue looking for a better option. I am also hoping to find one that will automatically send me an email once someone connects to it (which this might I just only spent a day going through its tools).

No comments:
Post a Comment