Re: Honeypot server?

From: Jeff Cochran (jcochran.nospam_at_naplesgov.com)
Date: 12/15/03


Date: Mon, 15 Dec 2003 19:06:55 GMT

On Fri, 12 Dec 2003 12:28:20 -0800, "ExAdmin" <iamspam@abuse.net>
wrote:

>Has anyone ever set up a 'honeypot' server on their network? I've heard it's
>good to put a server/workstation out there with zero security settings and
>maximum audit logging to catch worms and hackers. I'd like to set something
>like this up on my network. but not sure where to set the auditing and
>logging...

First, don't. :)

Honeypots are nice for security auditing and planning, but pretty
useless as actual deterrents and/or traps. Unless you have the
knowledge to deal with this (which you don't if you're asking about
where to set logging and auditing) then all you're doing is opening up
another system for hackers.

Better for you would be to concentrate on securing what you have, and
setting up an intrusion detection system if you really want to do a
honey pot. They aren't the same, but at your skill level you will
have enough trouble with an IDS.

Actually, first start auditing and logging on your standard network
issues. Audit unsuccesful logon attempts for a start.

Jeff



Relevant Pages

  • Re: Security logging stopped
    ... login successes and failure events was turned on in the RAS server settings. ... enable auditing on your RAS server: ... Note that to enable logging of access to files or registry settings, ... security properties in Windows Explorer or the REGEDT32 registry editor. ...
    (microsoft.public.security)
  • Re: track user logons
    ... including user actions such as logging on and logging off, and the success and failure of key ... Before you enable auditing, it will be important for you to define exactly ... For example, if you decide to audit account logon sessions, you need to consider what the information ... Your security administrators group might be interested in logging failed logon events ...
    (microsoft.public.windowsxp.security_admin)
  • Re: File access auditing fills security log too fast
    ... security guides at www.nsa.gov/snac and in the windows 2003 security guide ... NIST tell you to enable way too much auditing. ... don't forbid users from logging in when the logs fill up. ... The latest MS windows 2003 security guide above ...
    (microsoft.public.security)
  • Re: audit user activity
    ... you can set filter to view the Security log for a particular user. ... Microsoft CSS Online Newsgroup Support ... This newsgroup only focuses on SBS technical issues. ... Right-click Small Business Server Auditing Policy and click Edit. ...
    (microsoft.public.windows.server.sbs)
  • RE: VMWare poor guest isolation design
    ... So, the only risk is the from your hosting company's admins, and any ... and then common security practices of logging & auditing applies. ...
    (Bugtraq)