«Windows IT Pro» , 04, 2004 390

Windows

. (honeypot) , , .

(honeypot) , , . — , . (, -), .

, . . , Honeynet Project (http://www.honeynet.org) , (, «» « ») . , , , . , , , .

— , , . (Intrusion Detection Systems, IDS), . — , , .

, . , Windows , . Windows, UNIX/Linux. Windows, UNIX/Linux . , Windows. , Windows UNIX/Linux. , Windows , UNIX/Linux. , Windows, , .

. (, Windows Server 2003, Microsoft Exchange Server, Microsoft IIS) . — , . , , , .

, , , . , . , , , . UNIX/Linux , ( — data-control mechanism), Windows .

, . , . , .

, , (simple port listener). , . , , (, SYN). , . , .

, SMTP FTP. , . , , (banner service). , TCP- 25 (SMTP) Exchange. , , (simple) (standard) . , FTP- 21 , . , , , .

, IIS FTP, . , . , , , . , . , . , .

, , Windows Windows. (, « » — tarpit, ) , .

: Honeyd-WIN32 0.5, KFSensor KeyFocus, Network Security Software (NETSEC) SPECTER 7.0 VMware ( EMC) Workstation 4.0. . 1 , Windows, . .

  • Windows. Windows (RPC) 135, NetBIOS 137, 138, 139 445, , Windows. , Exchange 25 (SMTP), 110 (POP3), 113 (NNTP, Network News Transfer Protocol — ) 143 (IMAP). IIS 20 21 (FTP), 25, 80 (HTTP) 443 (HTTP Secure-HTTPS). Windows 2000 Server 53 (DNS), 68 (DHCP), 88 (Kerberos), 1433 1434 (Microsoft SQL Server) 3389 (Windows 2000 Server Terminal Services). . , Web- IIS, Apache, SMTP Exchange, sendmail. Microsoft.
  • . , . . : , ; ; — ; , ?
  • . . , . . — . , .
  • . . , , SMS (Short Message Service — ). — , .

Honeyd-WIN32

Honeyd-WIN32 — Windows Honeyd, UNIX . 2002 ., UNIX/Linux . Honeyd , . . Honeyd for UNIX/Linux http://www.honeyd.org. 2003 . Honeyd Windows. Honeyd 0.8, Honeyd-WIN32 0.5 . , .

, , Honeyd-WIN32 IP. Honeyd-WIN32 IP- (personality). IP-, Honeyd-WIN32 Address Resolution Protocol (ARP), Internet Control Message Protocol (ICMP), TCP UDP , . TCP, Time to Live (TTL), , , Honeyd-WIN32 . Honeyd-WIN32 , Xprobe2 ( ) Network Mapper (Nmap) Insecure.org, . , , , , - Windows 2000 Server, Windows NT Server 4.0, IP-. IP- Honeyd-WIN32 IP-, -. -.

Honeyd-WIN32 . , IP- . Honeyd-WIN32 Windows, UNIX, Linux, Sun Solaris Sun Microsystems, FreeBSD IOS Software Cisco Systems. Honeyd-WIN32 UDP TCP, , ( ). . , , , -. , , , -.

Honeyd-WIN32 . WinPcap ( Windows, http://winpcap.polito.it), Honeyd-WIN32, IP-. Honeyd-WIN32 , Honeyd-WIN32, , , . , Perl UNIX/Linux. , .

, IDS ( , ) ( ). Honeyd-WIN32 Snort (http://www.snort.org) IDS Ethereal (http://www.ethereal.com). , , , — Windows . , Honeyd-WIN32 — , , , Honeyd .

, Honeyd-WIN32 , Windows. Honeyd-WIN32 , . Windows, , , ( ). Honeyd-WIN32 — , , .

, ( 1). , , . , .

1. Honeyd-Win32

Honeyd-WIN32 — Windows. . , , Honeyd-WIN32 , . - Windows.

KFSensor

KFSensor — , Windows. Honeyd-WIN32, KFSensor — . Honeyd-WIN32, KFSensor 77 (58 TCP 19 UDP). Windows, KeyFocus « », , . — . . .

KFSensor IIS, FTP, Telnet Exchange. IIS Under construction. 25 Exchange, SMTP. Exchange, POP3 IMAP, - . KFSensor Terminal Services RDP, Symantec pcAnywhere, Citrix MetaFrame, Virtual Network Computing (VNC), WinGate . . pcAnywhere , -, .

2. KFSensor?s GUI

KFSensor NetBIOS Windows RPC, Windows. , , KFSensor — , . KFSensor Windows.

KFSensor . , , , . 2, . KFSensor ( ), , Windows . UNIX/Linux , , . Windows , Windows, Kiwi Syslog Daemon Kiwi Enterprises, http://www.kiwisyslog.com. KFSensor . KFSensor , , . . , .

KFSensor , .

  • KFSensor , Honeyd-WIN32. , , KFSensor IP , , . . ( .). , 256 , Honeyd-WIN32 IP-.
  • , KFSensor IP-, -. Honeyd-WIN32 IP- .
  • KFSensor , , Honeyd-WIN32 .
  • KFSensor , .
  • KeyFocus . , .

KFSensor 990 . - . KFSensor , Windows , .

SPECTER

SPECTER , Windows. SPECTER , .

SPECTER , ( 3). , 800x600. , Close Minimize, Windows. , Web- SPECTER .

3. SPECTER?s GUI

SPECTER 14 ( Windows, XP, Windows 2000, NT Windows 98, Windows 2003) , . SPECTER 11 (. . ) : DNS, Finger, FTP, POP3, IMAP4, HTTP, Secure Shell (SSH), SMTP, Sun RPC, Telnet (generic trap). (Finger, SSH Sun RPC) Windows. SPECTER , « »: NetBus, SubSeven Back Orifice 2000 (BO2K).

; , , , . , SPECTER -. , . , , .

, SMTP, FTP, HTTP POP Windows. , . : Open ( ), Secure ( ), Failing ( ), Strange ( ) Aggressive ( , , ). .

SPECTER, , , . — , finger, traceroute portscan. , . .

SPECTER , . , SPECTER . , . SPECTER , . . , . , , . , . « ».

SPECTER . , , , , , .

SPECTER . Windows, , . — . — 599 . 899 . .

VMware Workstation

, VMware Workstation (honeynet). 4 VMware Workstation. VMware Workstation , . . Windows (Windows 2003, XP, Windows 2000 NT) Linux.

4. VMware Workstation?s GUI

VMware Workstation .

  • , . , , , .
  • .
  • , , , .
  • - — .

, , VMware Workstation — , , . , IP . , , . , VMware Workstation, .

  • (299 . ), . .
  • , ( ) .
  • VMware Workstation , . , , .
  • VMware Workstation, . , , .

* , , . , .

, (IDS). UNIX (, , ), Windows. , , Windows .

, 990 ., KFSensor. KFSensor — , Windows; . Windows . , KFSensor — NetBIOS Windows RPC.

Honeyd-WIN32 — , , . IP Windows — . - , , NetBIOS Honeyd-WIN32 .

SPECTER — . — (14) . SPECTER , , . .

VMware Workstation — , . , . . .


— . CPA, MCSE, CNE, A+ «Malicious Mobile Code: Virus Protection for Windows» (- O?Reilly & Associates). : roger@rogeragrimes.com


Honeyd-WIN32 0.5

http://www.securityprofiling.com/honeyd/honeyd.shtml

: .

. . . .

. . . Windows.


KFSensor

KeyFocus — http://www.keyfocus.net

: 990 . 5465 . 10 .

. .

Windows .

. . .


SPECTER 7.0

Network Security Software — http://www.specter.com

: 899 . ( ); 399 . ; — 99 . (1 ).

. , .

. . 14 . .


() , . , , , , . , . , , . , http://www.honeypots.net/honeypots/links legal.


VMware Workstation 4.0

VMware — http://www.vmware.com

: 299 . 329 . .

.

.

. . , .

1 2 3 4


27/12/2011 1


«Windows IT Pro»

:

«Windows IT Pro»

c