From owner-freebsd-security Thu Sep 27 10:44: 2 2001 Delivered-To: freebsd-security@freebsd.org Received: from hotmail.com (f43.law3.hotmail.com [209.185.241.43]) by hub.freebsd.org (Postfix) with ESMTP id 7610037B421 for ; Thu, 27 Sep 2001 10:43:49 -0700 (PDT) Received: from mail pickup service by hotmail.com with Microsoft SMTPSVC; Thu, 27 Sep 2001 10:43:49 -0700 Received: from 170.253.240.1 by lw3fd.law3.hotmail.msn.com with HTTP; Thu, 27 Sep 2001 17:43:48 GMT X-Originating-IP: [170.253.240.1] From: "WebSec WebSec" To: fabre@matranet.com Cc: will@physics.purdue.edu, security@FreeBSD.ORG Subject: Re: LaBrea for BSD? Date: Thu, 27 Sep 2001 17:43:48 +0000 Mime-Version: 1.0 Content-Type: text/html Message-ID: X-OriginalArrivalTime: 27 Sep 2001 17:43:49.0036 (UTC) FILETIME=[F6CE76C0:01C1477B] Sender: owner-freebsd-security@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.org

Here is an idea,

How about  LaBrea for BSD (installed on a DHCP Server) automatically takes all IPs and releases them as clients request those IPs? 

Another idea is that LaBrea server installed on DHCP "informs" LaBrea clients which IPs to emulate....

 

Serg Perfi  - YDAP security consulting group

To: fabre@matranet.com

cc: will@physics.purdue.edu, security@FreeBSD.ORG

Date: 09/27/2001 01:01 PM

From: owner-freebsd-security@FreeBSD.ORG

Subject: Re: LaBrea for BSD?

 

At 09:05 AM 9/27/2001, Laurent Fabre wrote:

>I thought about it yup but....

>The fact is I need to capture something lower than IP, just because

>we need to monitor ARP request in order to acquire new IP addresses.

Automatic acquisition of unused IPs is, IMHO, a bad idea. If you're

assigning addresses via DHCP, it just plain won't work; the honeypot

will acquire addresses that your DHCP server still thinks can be

assigned. And since every Windows client tries to ARP its own address

as it starts up (in an attempt to make sure it's not stepping on

someone else), a machine that has been turned off for the night

will refuse to get on the Net in the morning if its address has

been claimed.

I'd prefer to specify the addresses to watch, thank you....

--Brett

 

To Unsubscribe: send mail to majordomo@FreeBSD.org

with "unsubscribe freebsd-security" in the body of the message




The reasonable man adapts himself to the world;
the unreasonable one persists in trying to adapt
the world to himself. Therefore all progress
depends on the unreasonable man.
-- George Bernard Shaw


Get your FREE download of MSN Explorer at http://explorer.msn.com
To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message