Results 1 to 4 of 4

Thread: Honeypot for Shares in Windows.

  1. #1
    Junior Member
    Join Date
    Jul 2006
    Posts
    2

    Honeypot for Shares in Windows.

    Hello all,

    I'm after some advice if possible, we have a virus/worm that appears to be propagating through our network via Open Shares. Is there a Honeypot that can emulate open shares that I would be able to use to track the source (or victim) connections from? Or is there a better way of doing this?

    Thanks!

  2. #2
    Just Another Geek
    Join Date
    Jul 2002
    Location
    Rotterdam, Netherlands
    Posts
    3,401
    Welcome to AO

    Just take any old computer.. Open a few writable shares, drop some executables in there, hook up a sniffer and wait..
    Oliver's Law:
    Experience is something you don't get until just after you need it.

  3. #3
    Junior Member
    Join Date
    Jul 2006
    Posts
    2
    Thanks for that - I'm downloading Ethereal now.

  4. #4
    Just Another Geek
    Join Date
    Jul 2002
    Location
    Rotterdam, Netherlands
    Posts
    3,401
    Originally posted here by Dove11
    Thanks for that - I'm downloading Ethereal now.
    Good choice

    If the "old computer" can run XP, turn on File and Object auditting and audit any write action to those shares. It's probably easier to read the security eventlog then it is to wade through a couple of megabytes of sniffer data. You'll have a basic time frame to look for..
    Oliver's Law:
    Experience is something you don't get until just after you need it.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •