pen-test
[Top] [All Lists]

Re: How Would I Find the Actual Name of the Honeypot Software via a Pen

To: <staticrez@gmail.com>, <pen-test@securityfocus.com>
Subject: Re: How Would I Find the Actual Name of the Honeypot Software via a Pen Test?
From: "Jay" <jay.tomas@infosecguru.com>
Date: Wed, 20 Jun 2007 14:56:26 -0400
Delivered-to: sp-com-lists@consult.net
Delivered-to: pentest-list2@consult.net
Delivered-to: mailing list pen-test@securityfocus.com
Delivered-to: moderator for pen-test@securityfocus.com
List-help: <mailto:pen-test-help@securityfocus.com>
List-id: <pen-test.list-id.securityfocus.com>
List-post: <mailto:pen-test@securityfocus.com>
List-subscribe: <mailto:pen-test-subscribe@securityfocus.com>
List-unsubscribe: <mailto:pen-test-unsubscribe@securityfocus.com>
Mailing-list: contact pen-test-help@securityfocus.com; run by ezmlm
Resent-date: Wed, 20 Jun 2007 12:59:56 -0600 (MDT)
Resent-from: pen-test-return-1078484418@securityfocus.com
Resent-message-id: <20070620185956.5C333237182@outgoing3.securityfocus.com>
Resent-sender: listbounce@securityfocus.com
Sender: listbounce@securityfocus.com
You may try and fingerprint the bios. This may lead you to determine if its 
vmware etc... or perhaps it can fingerprint the HP if they dont randomize bios 
data.

Jay

----- Original Message -----
From: StaticRez [mailto:staticrez@gmail.com]
To: pen-test@securityfocus.com
Sent: Wed, 20 Jun 2007 11:55:56 -0500
Subject: Re: How Would I Find the Actual Name of the Honeypot Software via a 
Pen Test?

Well, here's a list:

http://www.honeypots.net/honeypots/products

If you can actually tell them the name of the software then you're THE MAN.

I'm assuming that within the honeypot configs, you can pick which
services you'd want to be open. With that in mind, I don't think
there's any way of knowing what the actual software is. And even
assuming you know the OS, unless you're analyzing packets, the
honeypot should be able to "mimic" (to a certain extent) an IIS
server, it could be sitting on a BSD or any linux/unix variant box.

this one might require some social engineering...

staticrez



On 6/19/07, TStark <stark.ironman@gmail.com> wrote:
> Good afternoon,
>
> I'm doing a pen test a new IPS appliance from outside the network,
> while working through the assessment I found that the server
> designated as my target was a honeypot set up by our server team
> rather than a normal server.
>
> I've now been challenged to now tell them the actual name of the
> honeypot software they are using.
>
> So with that, I figure I'd ask the pros, hoping that someone has a
> suggestion other than me low crawling under the raised floor in the
> server room looking for the host server:P
>
>
> Thanks for the help!
>
> Tony
>
> ------------------------------------------------------------------------
> This List Sponsored by: Cenzic
>
> Are you using SPI, Watchfire or WhiteHat?
> Consider getting clear vision with Cenzic
> See HOW Now with our 20/20 program!
>
> http://www.cenzic.com/c/2020
> ------------------------------------------------------------------------
>
>

------------------------------------------------------------------------
This List Sponsored by: Cenzic

Are you using SPI, Watchfire or WhiteHat?
Consider getting clear vision with Cenzic
See HOW Now with our 20/20 program!

http://www.cenzic.com/c/2020
------------------------------------------------------------------------


------------------------------------------------------------------------
This List Sponsored by: Cenzic

Are you using SPI, Watchfire or WhiteHat?
Consider getting clear vision with Cenzic
See HOW Now with our 20/20 program!

http://www.cenzic.com/c/2020
------------------------------------------------------------------------
<Prev in Thread] Current Thread [Next in Thread>