what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

honeyd-2004-001.txt

honeyd-2004-001.txt
Posted Jan 21, 2004
Authored by Niels Provos | Site honeyd.org

Honeyd is vulnerable to remote detection via a simple probe packet. All versions up to 0.8 are susceptible.

tags | advisory, remote
SHA-256 | cde958c21a34416d46b6613084575197d925bacde71a75b0abc1b5d2e44574f6

honeyd-2004-001.txt

Change Mirror Download
-----BEGIN PGP SIGNED MESSAGE-----

Honeyd Security Advisory 2004-001
=================================

Topic: Remote Detection Via Simple Probe Packet

Version: All versions prior to Honeyd 0.8

Severity: Identification of Honeyd installations allows an
adversary to launch attacks specifically against
Honeyd. No remote root exploit is currently known.

Details:
=========

Honeyd is a virtual honeypot daemon that can simulate virtual hosts on
unallocated IP addresses.

A bug in handling NMAP fingerprints caused Honeyd to reply to TCP
packets with both the SYN and RST flags set. Watching for replies, it
is possible to detect IP addresses simulated by Honeyd.

Although there are no public exploits known for Honeyd, the detection
of Honeyd IP addresses may in some cases be undesirable.

Solutions:
==========

A new version of Honeyd has been released to address this issue.
The source code for Honeyd 0.8 can downloaded from

http://www.citi.umich.edu/u/provos/honeyd/

In addition, Honeyd 0.8 drops privileges if permitted by the
configuration file and contains command line flags to force dropping
of privileges.

Nontheless, it is suggested to run Honeyd in a chroot environment
under a sandbox like Systrace.

Thanks To
=========

Anonymous for information about the detection problem.

More Information:
=================

More information on Honeyd can be found at

http://www.honeyd.org/

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.7 (OpenBSD)

iQEVAwUBQA49IzZ8FqYKL4flAQHbQQf+IvfxPWaXz2tPjfhN8oOkp4JhOdcGcfOw
AN8BVgvZxw9+AAv+r6kuuyIZMmJQwp4CfiYqh4b0A8Wq7pWb08g1GGQnnvAmnzgU
yjEJE0H1qm6cd3xftsGA5j+leWM/IfW+BWRPSwBtDqxSRzPGD+Tnkt43zqUE8f5i
+Owg9YDH2rFoomU0xzD5LHjaBDL89Ef8iU6YvRaVI2tix+GeINGUDkW20EtT1727
szP+y8XzsdaU3o+ZkqQ2s0uvJZyr0zzhenhuy9VGM9bvXq7NlcwUWyoJdQU6bZCl
rVZKc8mAjX6gRYLbSf0E5yE9HIxxOdXt9q9U1wRIXoOizn9V2Loanw==
=X/C4
-----END PGP SIGNATURE-----
Login or Register to add favorites

File Archive:

July 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Jul 1st
    27 Files
  • 2
    Jul 2nd
    10 Files
  • 3
    Jul 3rd
    35 Files
  • 4
    Jul 4th
    27 Files
  • 5
    Jul 5th
    18 Files
  • 6
    Jul 6th
    0 Files
  • 7
    Jul 7th
    0 Files
  • 8
    Jul 8th
    28 Files
  • 9
    Jul 9th
    44 Files
  • 10
    Jul 10th
    24 Files
  • 11
    Jul 11th
    25 Files
  • 12
    Jul 12th
    11 Files
  • 13
    Jul 13th
    0 Files
  • 14
    Jul 14th
    0 Files
  • 15
    Jul 15th
    0 Files
  • 16
    Jul 16th
    0 Files
  • 17
    Jul 17th
    0 Files
  • 18
    Jul 18th
    0 Files
  • 19
    Jul 19th
    0 Files
  • 20
    Jul 20th
    0 Files
  • 21
    Jul 21st
    0 Files
  • 22
    Jul 22nd
    0 Files
  • 23
    Jul 23rd
    0 Files
  • 24
    Jul 24th
    0 Files
  • 25
    Jul 25th
    0 Files
  • 26
    Jul 26th
    0 Files
  • 27
    Jul 27th
    0 Files
  • 28
    Jul 28th
    0 Files
  • 29
    Jul 29th
    0 Files
  • 30
    Jul 30th
    0 Files
  • 31
    Jul 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close