«Windows IT Pro» , 04, 2004 390
Windows
. (honeypot) , , .
(honeypot) , , . — , . (, -), .

, . . , Honeynet Project (http://www.honeynet.org) , (, «» « ») . , , , . , , , .
— , , . (Intrusion Detection Systems, IDS), . — , , .
, . , Windows , . Windows, UNIX/Linux. Windows, UNIX/Linux . , Windows. , Windows UNIX/Linux. , Windows , UNIX/Linux. , Windows, , .
. (, Windows Server 2003, Microsoft Exchange Server, Microsoft IIS) . — , . , , , .
, , , . , . , , , . UNIX/Linux , ( — data-control mechanism), Windows .
, . , . , .
, , (simple port listener). , . , , (, SYN). , . , .
, SMTP FTP. , . , , (banner service). , TCP- 25 (SMTP) Exchange. , , (simple) (standard) . , FTP- 21 , . , , , .
, IIS FTP, . , . , , , . , . , . , .
, , Windows Windows. (, « » — tarpit, ) , .
: Honeyd-WIN32 0.5, KFSensor KeyFocus, Network Security Software (NETSEC) SPECTER 7.0 VMware ( EMC) Workstation 4.0. . 1 , Windows, . .
- Windows. Windows (RPC) 135, NetBIOS 137, 138, 139 445, , Windows. , Exchange 25 (SMTP), 110 (POP3), 113 (NNTP, Network News Transfer Protocol — ) 143 (IMAP). IIS 20 21 (FTP), 25, 80 (HTTP) 443 (HTTP Secure-HTTPS). Windows 2000 Server 53 (DNS), 68 (DHCP), 88 (Kerberos), 1433 1434 (Microsoft SQL Server) 3389 (Windows 2000 Server Terminal Services). . , Web- IIS, Apache, SMTP Exchange, sendmail. Microsoft.
- . , . . : , ; ; — ; , ?
- . . , . . — . , .
- . . , , SMS (Short Message Service — ). — , .
Honeyd-WIN32
Honeyd-WIN32 — Windows Honeyd, UNIX . 2002 ., UNIX/Linux . Honeyd , . . Honeyd for UNIX/Linux http://www.honeyd.org. 2003 . Honeyd Windows. Honeyd 0.8, Honeyd-WIN32 0.5 . , .
, , Honeyd-WIN32 IP. Honeyd-WIN32 IP- (personality). IP-, Honeyd-WIN32 Address Resolution Protocol (ARP), Internet Control Message Protocol (ICMP), TCP UDP , . TCP, Time to Live (TTL), , , Honeyd-WIN32 . Honeyd-WIN32 , Xprobe2 ( ) Network Mapper (Nmap) Insecure.org, . , , , , - Windows 2000 Server, Windows NT Server 4.0, IP-. IP- Honeyd-WIN32 IP-, -. -.
Honeyd-WIN32 . , IP- . Honeyd-WIN32 Windows, UNIX, Linux, Sun Solaris Sun Microsystems, FreeBSD IOS Software Cisco Systems. Honeyd-WIN32 UDP TCP, , ( ). . , , , -. , , , -.
Honeyd-WIN32 . WinPcap ( Windows, http://winpcap.polito.it), Honeyd-WIN32, IP-. Honeyd-WIN32 , Honeyd-WIN32, , , . , Perl UNIX/Linux. , .
, IDS ( , ) ( ). Honeyd-WIN32 Snort (http://www.snort.org) IDS Ethereal (http://www.ethereal.com). , , , — Windows . , Honeyd-WIN32 — , , , Honeyd .
, Honeyd-WIN32 , Windows. Honeyd-WIN32 , . Windows, , , ( ). Honeyd-WIN32 — , , .
, ( 1). , , . , .
|
| 1. Honeyd-Win32 |
Honeyd-WIN32 — Windows. . , , Honeyd-WIN32 , . - Windows.
KFSensor
KFSensor — , Windows. Honeyd-WIN32, KFSensor — . Honeyd-WIN32, KFSensor 77 (58 TCP 19 UDP). Windows, KeyFocus « », , . — . . .
KFSensor IIS, FTP, Telnet Exchange. IIS Under construction. 25 Exchange, SMTP. Exchange, POP3 IMAP, - . KFSensor Terminal Services RDP, Symantec pcAnywhere, Citrix MetaFrame, Virtual Network Computing (VNC), WinGate . . pcAnywhere , -, .
|
| 2. KFSensor?s GUI |
KFSensor NetBIOS Windows RPC, Windows. , , KFSensor — , . KFSensor Windows.
KFSensor . , , , . 2, . KFSensor ( ), , Windows . UNIX/Linux , , . Windows , Windows, Kiwi Syslog Daemon Kiwi Enterprises, http://www.kiwisyslog.com. KFSensor . KFSensor , , . . , .
KFSensor , .
- KFSensor , Honeyd-WIN32. , , KFSensor IP , , . . ( .). , 256 , Honeyd-WIN32 IP-.
- , KFSensor IP-, -. Honeyd-WIN32 IP- .
- KFSensor , , Honeyd-WIN32 .
- KFSensor , .
- KeyFocus . , .
KFSensor 990 . - . KFSensor , Windows , .
SPECTER
SPECTER , Windows. SPECTER , .
SPECTER , ( 3). , 800x600. , Close Minimize, Windows. , Web- SPECTER .
|
| 3. SPECTER?s GUI |
SPECTER 14 ( Windows, XP, Windows 2000, NT Windows 98, Windows 2003) , . SPECTER 11 (. . ) : DNS, Finger, FTP, POP3, IMAP4, HTTP, Secure Shell (SSH), SMTP, Sun RPC, Telnet (generic trap). (Finger, SSH Sun RPC) Windows. SPECTER , « »: NetBus, SubSeven Back Orifice 2000 (BO2K).
; , , , . , SPECTER -. , . , , .
, SMTP, FTP, HTTP POP Windows. , . : Open ( ), Secure ( ), Failing ( ), Strange ( ) Aggressive ( , , ). .
SPECTER, , , . — , finger, traceroute portscan. , . .
SPECTER , . , SPECTER . , . SPECTER , . . , . , , . , . « ».
SPECTER . , , , , , .
SPECTER . Windows, , . — . — 599 . 899 . .
VMware Workstation
, VMware Workstation (honeynet). 4 VMware Workstation. VMware Workstation , . . Windows (Windows 2003, XP, Windows 2000 NT) Linux.
|
| 4. VMware Workstation?s GUI |
VMware Workstation .
- , . , , , .
- .
- , , , .
- - — .
, , VMware Workstation — , , . , IP . , , . , VMware Workstation, .
- (299 . ), . .
- , ( ) .
- VMware Workstation , . , , .
- VMware Workstation, . , , .
* , , . , .
, (IDS). UNIX (, , ), Windows. , , Windows .
, 990 ., KFSensor. KFSensor — , Windows; . Windows . , KFSensor — NetBIOS Windows RPC.
Honeyd-WIN32 — , , . IP Windows — . - , , NetBIOS Honeyd-WIN32 .
SPECTER — . — (14) . SPECTER , , . .
VMware Workstation — , . , . . .
— . CPA, MCSE, CNE, A+ «Malicious Mobile Code: Virus Protection for Windows» (- O?Reilly & Associates). : roger@rogeragrimes.com
Honeyd-WIN32 0.5
http://www.securityprofiling.com/honeyd/honeyd.shtml
: .
. . . .
. . . Windows.
KFSensor
KeyFocus — http://www.keyfocus.net
: 990 . 5465 . 10 .
. .
Windows .
. . .
SPECTER 7.0
Network Security Software — http://www.specter.com
: 899 . ( ); 399 . ; — 99 . (1 ).
. , .
. . 14 . .
() , . , , , , . , . , , . , http://www.honeypots.net/honeypots/links legal.
VMware Workstation 4.0
VMware — http://www.vmware.com
: 299 . 329 . .
.
.
. . , .











