Login Register


Aggressive Honeypots filter_list
Author
Message
Aggressive Honeypots #1
Source: Alexey Sintsov

This one is a hacking countermeasure. It's reverse-penetration by attacking the attacker when he does not expect an attack.
Not sure if this is bh or wh.

Basically, Sintsov says that he made a regular honeypot. An administrative login, which is fake (plainly does nothing but say that the password is wrong). Then he added a little Java application which collected more information about the attacker's workstation (stuff like username). He stored that stuff on his server. He was even able to see, what kind of attacks the attackers launched. Cool, huh?

This technique allows a webmaster to optimize security of his site by analyzing harmless but real attacks. This is genius~! With the collected info they even could go to the police (in theory) as long as they state somewhere in the privacy info that they collect this information.

For all da hax0rs out there this means: caution. Always.


What do you think about this? Is this the future of basic security measures? Is this a real thread to bh hackers?
Need help? PM me.
Want me to see your post? Quote me.

Liable to change unpredictably and rapidly, especially for the worse.

Reply

RE: Aggressive Honeypots #2
Quote:Is this a real thread to bh hackers?

Only if your attacks servers because they are weak to some vuln you know about.

If you actually performed targeted attacks instead of just trying to 'own' all the weak servers you're unlikely(there are exceptions ofc) to run across a honeypot.

Reply

RE: Aggressive Honeypots #3
per wikipedia

Honeypots can be classified based on their deployment and based on their level of involvement. Based on deployment, honeypots may be classified as:

production honeypots
research honeypots

Production honeypots are easy to use, capture only limited information, and are used primarily by companies or corporations; Production honeypots are placed inside the production network with other production servers by an organization to improve their overall state of security. Normally, production honeypots are low-interaction honeypots, which are easier to deploy. They give less information about the attacks or attackers than research honeypots do.

Research honeypots are run to gather information about the motives and tactics of the Blackhat community targeting different networks. These honeypots do not add direct value to a specific organization; instead, they are used to research the threats that organizations face and to learn how to better protect against those threats.[1] Research honeypots are complex to deploy and maintain, capture extensive information, and are used primarily by research, military, or government organizations.

Based on design criteria, honeypots can be classified as:-

pure honeypots
high-interaction honeypots
low-interaction honeypots

The chances of comming across a honeypot you described is very rare do to the amount of work involved.

There also ways to detect if you are in a honeypot. If I get enough interest I will do a tut on it.

Reply

RE: Aggressive Honeypots #4
Honey pots have been around for like, 15+ years now. The whole point is to capture data.

I didnt watch the video - too long - but there are issues with what you suggest. Reverse hacking a hacker implies that software can hack an attacker. While thats possible to a degree - we all know its not that easy. If it was everyone would be a hacker.

So the only issue is collecting of information. Indeed, thats always possible. Which is why you should know how to hide. properly. This is nothing new.

Reply







Users browsing this thread: 1 Guest(s)