Honeypots & Honeynets low interaction and high interaction trap Networks....Honeypots y Honeynets baja interacción y la trampa de alta interacción Red

Honeypot is a set of computers or software whose purpose is to attract attackers, pretending to be weak or vulnerable systems to attack. It is a security tool used to collect information on the attackers and their techniques. Honeypots can distract the attackers of the most important machines of the system quickly and warn the system administrator of an attack, and allows a thorough examination of the attacker, during and after the attack on the honeypot.
Some honeypots are programs that pretend to be limited to operating systems or programs that do not exist in reality and they are known as low-interaction honeypots are used primarily as a security measure.
Others however are working on real operating systems and are able to gather much more information, usually for their research and are known as high-interaction honeypots.
In the group of high-interaction honeypot, we are also with the honeynet
To create a low-interaction honeypot (and very, very, very simple) we can use the following:

A Windows (alleged victim)
The program netcat
A computer (Windows or Linux) as the attacker
Two text files with the following contents:

File 'serweb.txt':
PlayStation WebServer Version 1.1
Playboy Playgirls and Games
Connecting ....
File 'sertelnet.txt'
Trying telnet.acme.es ...
Connected to telnet.acme.es.
Escape character is'^]'.
220 telnet.acme.ESMTP Postfix
Netcat PORTS FOR USING SIMULATED
Netcat allows through shell and a simple syntax to open ports TCP / UDP to a host (left netcat to listen) with a shell to a port in particular (for example to connect to the CMD or the bash shell Linux remotely) and force connections UDP / TCP (eg useful for tracking or port to transfer files bit by bit between two teams).
On Windows machines, and once installed Netcat, CMD to open two windows with the following commands:
Ventana1:
c: \> nc-l-p 80logweb.txt
Pretend to be a web server that will respond serweb.txt the file when someone connects. When the attacker enter commands stored in the file logweb.txt

Ventana2:
c: \> nc-l-p 23 logtelnet.txt
Pretend to be a web server that will respond telnet.txt the file when someone connects. When the attacker enter commands stored in the file logtelnet.txt
A homemade solution of this, there are various programs in this regard, we will see some very simple as the following:

HoneyBOT

This simple program allows to simulate all ports TCP / UDP that are not in use on your computer, open Honeybot and pretending to be a server or service running on the program, see the following examples are illustrative




SPECT

This program is the most comprehensive low-interaction honeypots, operating systems and simulates 14 ports and plenty of custom commands is the best by far, is that payment ;-)




KFSENSOR

Also one of the best, like Specter is business, but notes in its remote management capabilities, editing services, programming responses to a connection, central integrated alerts and databases for the detection of motor-based attacks signatures. Its price is around $ 600.



Nepenthes

Emulate vulnerabilities allows to collect information on possible attacks.

t designed to capture and emulate the use of worms
.
As there are many possible ways of spreading worms, Nepenthes is modular and has ability to download files, and generate events as not emulate vulnerabilities. It is open source and some complex parameter, use qemu.



Google Hack Honeypot
.
GHH is a "Google Hack" honeypot. It is designed to detect attackers that use search engines as a hacking tool against your resources. GHH implements simulated environments. Curious as a learning system



Honeyd - WINHONEYD

Honeyd is open source and runs on virtually any platform, Winhoneyd is free and works on windows with the exception of the configuration tool which is pay. Honeyd is a small daemon that creates virtual hosts on a network.
The devices can be configured to run arbitrary services, and be adapted so that seem to be running certain operating systems. Honeyd enables a single host to have several directions, including up to 65,536 - a LAN for network simulation.


project.honeynet.org
Honeynet Project

.............................................................
Honeypot es un conjunto de computadoras o software cuyo objetivo es atraer a los atacantes, simulando ser sistemas vulnerables o débiles para atacar. Es una herramienta de la seguridad se utilizan para recopilar información sobre los atacantes y sus técnicas. Honeypots pueden distraer a los atacantes de los más importantes equipos del sistema rápida y avisar al administrador del sistema de un ataque, y permite un examen detallado de la atacante, durante y después del ataque contra el honeypot.
Honeypots son algunos programas que pretenden ser limitada a los sistemas operativos o programas que no existen en realidad y que son conocidos como Honeypots de baja interacción son utilizados principalmente como una medida de seguridad.
Sin embargo, otros están trabajando en sistemas operativos reales y son capaces de reunir mucha más información, por lo general para su investigación y que se conoce como interacción de alta honeypots.
En el grupo de los honeypot de alta interacción, también con la honeynet
Para crear un honeypot de baja interacción (y muy, muy, muy simple) se puede utilizar el siguiente:

Un equipo con Windows (presunta víctima)
El programa netcat
Un ordenador (Windows o Linux), como el atacante
Dos archivos de texto con el siguiente contenido:

Archivo 'serweb.txt':
PlayStation WebServer Versión 1.1
Playboy Playgirls y Juegos
Conexión ....
Archivo 'sertelnet.txt'
Tratando telnet.acme.es ...
Conectado a telnet.acme.es.
Carácter de escape es'^]'.
220 telnet.acme.ESMTP Postfix
Netcat PUERTOS PARA USAR SIMULADO
Netcat permite a través de depósito y una sintaxis simple para abrir los puertos TCP / UDP a un host (a la izquierda para escuchar netcat), con un depósito a un puerto en particular (por ejemplo, para conectarse a la CMD o la shell bash de Linux remotamente) y forzar conexiones UDP / TCP (útil por ejemplo para el seguimiento o el puerto para la transferencia de archivos poco a poco entre los dos equipos).
En máquinas Windows, y una vez instalado Netcat, CMD para abrir dos ventanas con los siguientes comandos:
Ventana1:
c: \> nc-l-p 80logweb.txt
Pretende ser un servidor web que responda serweb.txt el archivo cuando alguien se conecta. Cuando el atacante introducir comandos almacenados en el fichero logweb.txt

Ventana2:
c: \> nc-l-p 23 logtelnet.txt
Pretende ser un servidor web que responda telnet.txt el archivo cuando alguien se conecta. Cuando el atacante introducir comandos almacenados en el fichero logtelnet.txt
Una solución casera de este, hay varios programas en este sentido, vamos a ver algunas muy sencillas como las siguientes:

HoneyBOT

Este sencillo programa permite simular todos los puertos TCP / UDP que no están en uso en el ordenador, abra Honeybot y fingiendo ser un servidor o servicio que se ejecutan en el programa, consulte los siguientes ejemplos son ilustrativos




SPECT

Este programa es el más completo Honeypots de baja interacción, sistemas operativos y simula 14 puertos y un montón de órdenes es el mejor con diferencia, es que el pago ;-)




KFSENSOR

También uno de los mejores, como Specter es comercial, pero señala en sus capacidades de gestión remota, servicios de edición, programación de las respuestas a una conexión, el centro integrado de bases de datos y alertas para la detección de ataques basados en motor de las firmas. Su precio es de alrededor de $ 600



Nepenthes

Emular vulnerabilidades permite recoger información sobre posibles ataques.

No diseñado para capturar y emular el uso de gusanos
Como hay muchas posibles formas de propagación de gusanos, Nepenthes es modular y tiene capacidad para descargar archivos, y generar eventos que no emular vulnerabilidades. Es de código abierto y complejo de algunos parámetros, el uso qemu.



Google Hack Honeypot
.
GHH es un "Google Hack" honeypot. Está diseñado para detectar los atacantes que utilizan los motores de búsqueda como herramienta de hacking contra tus recursos. GHH implementa ambientes simulados. Curioso como un sistema de aprendizaje



Honeyd - WINHONEYD

Honeyd es de código abierto y funciona en prácticamente cualquier plataforma, Winhoneyd es libre y trabaja en las ventanas, con la excepción de la herramienta de configuración que es de pago. Honeyd es un pequeño demonio que crea hosts virtuales en una red.
Los dispositivos pueden ser configurados para ejecutar servicios arbitrarios, y se adaptarán de forma que parecen estar ejecutando ciertos sistemas operativos. Honeyd permite a un único host tener varios sentidos, incluido un máximo de 65.536 - de una simulación de la red LAN.

project.honeynet.org
Honeynet Project

No hay comentarios:

Protected by Copyscape Original Article Checker