Monkey.org Developments
Honeyd Mailing List: Re: Net Bios script for noneyd

Support Honeyd

Search:
Keywords:

Search Amazon

 
 

Re: Net Bios script for noneyd

From: <Valdis.Kletnieks_at_vt.edu>
Date: Mon May 17 12:29:41 2004

On Mon, 17 May 2004 17:31:28 +0200, Sumit Siddharth <Sumit.Siddharth_at_eurecom.fr> said:
> SInce the ports 139,137 and 445 are most commonly targetted by the
> hackers I dont understand why we dont have any support (script ) for
> these ports on honeyd.Instead of closing these ports it will really
> good to have some script running on them so that we can get more
> information about the hacker/attack tool.

Most likely, none of the programmers involved wanted to go anywhere near that
can of worms.... ;)

The problem is that it's fiendishly difficult to actually emulate the SMB/CIFS
protocol well enough to be useful while staying legal regarding
reverse-engineering (See the Samba project for an example). The other choice
is to just emulate it enough for the "well-known" exploits to "work" - and a
quick perusal of the vast number of Nessus plug-ins for those ports will
explain why nobody wants to go THAT route....


  • application/pgp-signature attachment: stored
Received on Mon May 17 2004 - 12:29:41 PDT
Search For Information
Google
Search WWW Search www.honeyd.org

NB: This is a filtered version of the Honeypots mailing list. Only posts that concern Honeyd are shown here. For more recent discussions visit the forums.