Sunday, March 31, 2002

Babysteps With A Honeypot

"This document describes the build and running of my first honeypot. It was based heavily on the work done by Lance Spitzner and his colleagues of the HoneyNet project. The aim of my first deployment was to start gaining some experience in the handling of honeypot technologies, rather than concentrate on actual hacker activity." - Mark Cooper

Incident Analysis of a Compromised RedHat Linux 6.2 Honeypot

"This was the fourth honeypot system I had put into production, my honeypot had been offline for a couple weeks prior to this incident while I made a few changes to the way syslog worked and installed a bash keystroke logger. If you want to learn more details on how I set-up my honeypot then please read my paper describing my particular method of implementation." - Stephen Holcroft

Design Of A Default Redhat Server 6.2 Honeypot

"The following paper is a description of how I have designed and implemented a honeypot system. The paper describes how the honeypot is used to capture data in layers using different techniques. The aim of the honeypot is to discover the techniques and tactics used by blackhats (hackers) to compromise computer systems. The methods used are similar to themethods used by the Honeynet Project." - Stephen Holcroft