Honeytrap 1.0.0 Released

Oct 29, 2007

Version 1.0.0 of the honeypot daemon Honeytrap has been released. It has a completely reworked configuration mechanism and new plugins.

The GPL'd program registers attacks against TCP services. When a request arrives from an unknown port, Honeytrap dynamically launches a server process to handle it. This avoids the need for the software to continually bind thousands of ports. Connection monitors based on Libpcap, Netfilter/Iptables or Netfilter_Queue handle the bindings. Honeytrap will run in various modes, including a proxy mode where it forwards connections and sniffs traffic. The daemon comprises two parts. The program core collects data and can load plugins at runtime for analysis purposes. Plugins currently available store strings and malware from attacks, and special extensions are available for identifying FTP and TFTP commands. In addition to this, there is a parser for attacks on VNC servers, a pluging that decodes Base 64 encoded exploits, and a module that identifies attacks heuristically using similarity checks. Honeytrap 1.0.0 is available as a source code archive on the Sourceforge download servers. The subversion repository for the project also supports access to the current sources. In addition to this, the download page has Xen templates and Qemu images for the virtual Honeytrap server.

Related content

  • DoS Attack Exploit in BIND 9

    A specially crafted dynamic update message to a DNS zone for which the server is a master can raise havoc in BIND 9. An active remote exploit is already "in wide circulation."

  • Honeynet

    Security-conscious admins can use a honeynet to monitor, log, and analyze intrusion techniques.

  • Firewall Logfile Analyzers

    Netfilter firewalls create highly detailed logfiles that nobody really wants to inspectmanually. Logfile analysis tools like IPtables Log Analyzer,Wallfire Wflogs,and FWlogwatch help administrators keep track of developments and filter for importantmessages.

  • Intrusion Detection

    The Prelude security information management system receives both host- and network-based IDS messages and displays them in an easy web interface. We show you how to set it up.

  • Security Lessons

    Are your systems secure against DNS attacks? We'll show you why they matter and help you determine whether you are vulnerable.

comments powered by Disqus

Issue 163/2014

Buy this issue as a PDF

Digital Issue: Price $9.99
(incl. VAT)

News