Honeytrap is a network security tool written to observe attacks against network services. As a low-interactive honeypot, it collects information regarding known or unknown network-based attacks and uses plugins for automated analysis.
Be the first to post a text review of honeytrap. Rate and review a project by clicking thumbs up or thumbs down in the right column.
Honeytrap 1.0.0 comes with a totally revised configuration concept which makes module handling much more flexible. The system was also redesigned to put more tasks into modules. Analysis plugins can now create "virtual attacks" which can be further processed with other plugins. This release also introduces 3 new plugins: o htm_httpDownload invokes an external program to retrieve files via HTTP o htm_ClamAV scans downloaded binaries using the ClamAV anti virus engine o htm_SaveFile stores attack information in directories on a harddrive
Version 1.0.0 - Improved configure script - New plugin: Basic http download wrapper - VNC plugin redesigned to generate virtual attacks - Safe signal delivery and handling using per-process pipes - New configuration concept with hierarchically organized file format - Default port configuration can be set to "ignore", "normal" or "mirror" - New plugin: libclamav-based virus scanner module - New plugin: Saving attack data in files is performed by a module now - malloc(NULL) segfault bug in tftpDownload plugin fixed - Try to download from the attacking host in case of failed ftp connect()s - Improved connection request handling in the nfq stream monitor - Reconfiguration on SIGHUP fixed - Log addressed destination
Version 1.0.0 - Improved configure script - New plugin: Basic http download wrapper - VNC plugin redesigned to generate virtual attacks - Safe signal delivery and handling using per-process pipes - New configuration concept with hierarchically organized file format - Default port configuration can be set to "ignore", "normal" or "mirror" - New plugin: libclamav-based virus scanner module - New plugin: Saving attack data in files is performed by a module now - malloc(NULL) segfault bug in tftpDownload plugin fixed - Try to download from the attacking host in case of failed ftp connect()s - Improved connection request handling in the nfq stream monitor - Reconfiguration on SIGHUP fixed - Log addressed destination
Honeytrap 0.7.0 introduces priorities for plugins, a nfnetlink_queue-based network stream monitor and sha512 hashing support. Other changes include lots of fixes and performance improvements. The compile process should be more stable now.
Be the first person to add a text review.
Copyright © 2010 Geeknet, Inc. All rights reserved. Terms of Use
Thanks for your rating!
Would you also like to write a review?
Thanks for your review!
Get credit for your review by logging in via OpenID. Click your account provider: