[luau] Incident Analysis of a Compromised Redhat Linux 6.2 Honeypot

Kev kevg at hawaii.rr.com
Mon May 6 08:38:18 PDT 2002


Anyone know if the BASH Keylogger patch could work for Mandrake 8.2 with
BASH ver. 2.05 or could the code be adjusted?  Does anyone know of a
better method?
 
On Thu, 2002-05-02 at 18:56, Dean Fujioka wrote:
> Woah... I guess I'd better do some reading on Ethereal, snort, etc..... I
> suppose i have an unintentional honeypot 8)
> 
> dean
> 
> ----- Original Message -----
> From: <cpaul at telemetrybox.org>
> To: <luau at videl.ics.hawaii.edu>
> Sent: Thursday, May 02, 2002 7:55 AM
> Subject: [luau] Incident Analysis of a Compromised Redhat Linux 6.2 Honeypot
> 
> 
> > Interesting Forensics.
> >
> > http://www.lucidic.net/whitepapers/sholcroft-4.1-2002.html
> >
> > --
> > "The human brain is like an enormous fish - it is flat and slimy and has
> gills through which it can see." - Monty Python
> > GPG key: http://linefeed.org/~epsas/epsas.asc
> > fingerprint: 4819 FBE0 5BE3 83FE E788  1AA4 A91C 5FB0 E3FF 4F9D
> > _______________________________________________
> > LUAU mailing list
> > LUAU at videl.ics.hawaii.edu
> > http://videl.ics.hawaii.edu/mailman/listinfo/luau
> >
> 
> _______________________________________________
> LUAU mailing list
> LUAU at videl.ics.hawaii.edu
> http://videl.ics.hawaii.edu/mailman/listinfo/luau





More information about the LUAU mailing list