suggestions for this honeypot
this is what i have:
a hardened xp pro install using DSL modem and kerio personal firewall. Virtual pc installed with a standard xp pro install using the virtual switch networking option.
i prefer virtual pc. I can't understand the networking in vmware.
I tried it using analogx port forwarding to forward ports 445 and 5000 from the host to the virtual pc. which did forward lots of traffic but even though i was using some tools from winternals. regmon, filemon, tcpmon, process explorer. i couldnt really tell what was going on.
on the host i have commview sniffer but i wasnt using it at the time. I did download the windows port of snort but i havent installed it yet. am a bit scared of snort tbh.
any thoughts on what might be better? i mean within the criteria of using virtual pc.