[plug] Building a "minefield/tarpit" for worms
Senectus .
senectus at gmail.com
Wed May 31 11:42:58 WST 2006
On 31/05/06, Bernd Felsche <bernie at innovative.iinet.net.au> wrote:
> "Senectus ." <senectus at gmail.com> writes:
> >On 31/05/06, Daniel J. Axtens <danielax at gmail.com> wrote:
>
> >> As Daniel pointed out, this sort of thing is called a honeypot - just
> >> googling honeypot will get you started. There is also a honeypots
> >> mailing list on securityfocus.
>
> >Unless it's for research purposes, I fail to see why this is a good idea...
>
> I don't actually want to attract probes. I just to blow their legs
> off if they tread on my minefield. :-)
>
> That should reduce their ability to probe other machines.
But in all reality a honey pot just wastes your bandwidth. I don't
think a trojan/virus has been created in years that doesn't multicast
it's scans.. so even though I thinks it's found a way in on your
system it's going to keep looking elsewhere anyhow. in the mean time
your bandwidth gets eaten up by a resistant piece of code trying to
solidify it's infection.
seem very futile to me.
at least that's my understanding of it
--
www.modmeup.net
Ubuntu Dapper 6.06
The less you know, the more you believe. - Bono
More information about the plug
mailing list