
Honeyd Resources
Main - News - Forums Honeyd ResearchHoneypot ResourcesHappy Hacking
|
Honeyd Security Advisory 2004-001: Remote Detection Via Simple Probe Packet
From: Niels Provos <provos_at_citi.umich.edu>
Date: Wed, 21 Jan 2004 03:51:46 -0500
-----BEGIN PGP SIGNED MESSAGE-----
Honeyd Security Advisory 2004-001
Topic: Remote Detection Via Simple Probe Packet
Version: All versions prior to Honeyd 0.8
Severity: Identification of Honeyd installations allows an
Details:
Honeyd is a virtual honeypot daemon that can simulate virtual hosts on
A bug in handling NMAP fingerprints caused Honeyd to reply to TCP
Although there are no public exploits known for Honeyd, the detection
Solutions:
A new version of Honeyd has been released to address this issue.
http://www.citi.umich.edu/u/provos/honeyd/
In addition, Honeyd 0.8 drops privileges if permitted by the
Nontheless, it is suggested to run Honeyd in a chroot environment
Thanks To
Anonymous for information about the detection problem.
More Information:
More information on Honeyd can be found at
-----BEGIN PGP SIGNATURE-----
iQEVAwUBQA49IzZ8FqYKL4flAQHbQQf+IvfxPWaXz2tPjfhN8oOkp4JhOdcGcfOw
NB: This is a filtered version of the Honeypots mailing list. Only posts that concern Honeyd are shown here. For more recent discussions visit the forums. | ||||
|
Copyright (c) 1999-2004 by Niels Provos Don't access my pirated music. | |||||