From owner-freebsd-security Thu Sep 27 11: 6: 4 2001 Delivered-To: freebsd-security@freebsd.org Received: from hotmail.com (f135.law3.hotmail.com [209.185.241.135]) by hub.freebsd.org (Postfix) with ESMTP id E3B9737B426 for ; Thu, 27 Sep 2001 11:05:58 -0700 (PDT) Received: from mail pickup service by hotmail.com with Microsoft SMTPSVC; Thu, 27 Sep 2001 11:05:58 -0700 Received: from 170.253.240.1 by lw3fd.law3.hotmail.msn.com with HTTP; Thu, 27 Sep 2001 18:05:58 GMT X-Originating-IP: [170.253.240.1] From: "WebSec WebSec" To: fabre@matranet.com Cc: will@physics.purdue.edu, security@FreeBSD.ORG Subject: LaBrea for BSD? Date: Thu, 27 Sep 2001 18:05:58 +0000 Mime-Version: 1.0 Content-Type: text/html Message-ID: X-OriginalArrivalTime: 27 Sep 2001 18:05:58.0827 (UTC) FILETIME=[0F6C77B0:01C1477F] Sender: owner-freebsd-security@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.org

This solution should only be used in DHCPed environents.  You would have problems if you are to assign a static address in a DHCPed environment anyhow.

 

This could worm but would require some hooks in the ISC DHCP server

code.

There'd still be a problem, though, if you were using fixed IPs and no

DHCP. Here's the scenario: You turn off your workstation; the tarpit claims

its address; you come in next morning and turn it on; your workstation reports

that it is kicking itself off the network because it has ARPed its IP address

and found it in use by someone else. (Windows machines with fixed IPs always

do this; other operating systems might as well.)

--Brett

At 11:43 AM 9/27/2001, WebSec WebSec wrote:

 

>Here is an idea,

>

>How about LaBrea for BSD (installed on a DHCP Server) automatically takes all IPs and releases them as clients request those IPs?

>

>Another idea is that LaBrea server installed on DHCP "informs" LaBrea clients which IPs to emulate....

>

>

>

>Serg Perfi - YDAP security consulting group

 

To Unsubscribe: send mail to majordomo@FreeBSD.org

with "unsubscribe freebsd-security" in the body of the message




The reasonable man adapts himself to the world;
the unreasonable one persists in trying to adapt
the world to himself. Therefore all progress
depends on the unreasonable man.
-- George Bernard Shaw


Get your FREE download of MSN Explorer at http://explorer.msn.com
To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message