LinuxQuestions.org
Visit the LQ Articles and Editorials section
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices

Reply
 
LinkBack Search this Thread
Old 09-30-2004, 04:37 PM   #1
servnov
Member
 
Registered: Sep 2004
Distribution: Slackware 10.2
Posts: 276

Rep: Reputation: 30
explain honeypot and tarpit?


Can someone please explain to me what is the difference between honeypot/honeynet and a tarpit? Any other info about them is welcome. heh.
 
Old 09-30-2004, 05:25 PM   #2
m00t00
Member
 
Registered: Sep 2004
Distribution: Slackware 10, Gentoo
Posts: 292

Rep: Reputation: 30
Honeypot: fake machine. It is usually vulnerable to some blatlantly obvious security flaw, so as to trap would be crackers into breaking into it. Most honeypots are also equipped with extensive logging software.

Tarpit: Fake machine. It is designed to slow things down, such as port scans.
 
Old 09-30-2004, 05:43 PM   #3
CroMagnon
Member
 
Registered: Sep 2004
Location: New Zealand
Distribution: Debian
Posts: 899

Rep: Reputation: 33
A honeypot is configured insecurely by design. The idea is to fool attackers into compromising an easy target, so the owners can track what attackers use to break into systems (so that holes can be found and plugged), and also to learn what methods are employed to cover their tracks (i.e to identify rootkits and such).

A tarpit introduces a delay in each connection attempt, often increasing with more attempts from the same host. For example, you might have your mail server introduce a small delay if a machine connects more than twice in two seconds. Then if someone is using your mail server to send spam, every subsequent message will take longer and longer to send, making the activity uneconomical for the spammer (theoretically forcing him to give up, but more realistically forcing him to use someone else's server). This does not inconvenience legitimate users of the service, except perhaps in a few specific cases. A mail server is not the only case - it could be used to slow down port scans as m00t00 said, or other services.
 
Old 09-30-2004, 07:53 PM   #4
servnov
Member
 
Registered: Sep 2004
Distribution: Slackware 10.2
Posts: 276

Original Poster
Rep: Reputation: 30
thanks.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are Off
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
*working* kernel based keylogger for honeypot? TotalDefiance Linux - Security 4 11-05-2005 11:25 AM
Advertising honeypot? Dark_Helmet LQ Suggestions & Feedback 17 09-16-2005 05:40 PM
explain. bruse Linux - Newbie 6 09-08-2005 11:48 PM
can someone explain this? SteveGodfrey Linux - Wireless Networking 1 05-28-2004 08:47 AM
can anyone explain this? log Linux - Software 2 06-10-2003 12:30 AM


All times are GMT -5. The time now is 02:41 PM.

Main Menu
 
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
identi.ca: @linuxquestions
Facebook: @linuxquestions
Open Source Consulting | Domain Registration