Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
Gas Stations In the Bullseye
Newest First  |  Oldest First  |  Threaded View
SgS125
SgS125,
User Rank: Ninja
7/1/2015 | 9:58:39 AM
Invaluable information gained by honeypot intel
You can't really put a value to the information gained by knowing what your adversary is looking at, trying to find, or simply what tools are used against infrastructures.   It seesm silly that you would not want this intel.

It's not a bear you are coaxing in, its a small blind rodent who scampers around hiding from the light.  Honeypots allow us to gather the information needed to deter the next infestation of vermin.

If we all worked together and shared the intel from honeypots our defenses would have a power multiplier many times greater than the damm hidden zero day expoloits used to further the ill will of many unknown players.

So shine some light and watch the rats scatter,  you won't find a bear among them.
Joe Stanganelli
Joe Stanganelli,
User Rank: Ninja
6/30/2015 | 10:56:16 PM
Legion
Reminds me of the time I was walking down the street and I saw "We are legion" scrawled in chalk on the sidewalk.

Not as many style points for that one.  ;)
Joe Stanganelli
Joe Stanganelli,
User Rank: Ninja
6/30/2015 | 10:51:49 PM
Re: Poking the Bear
They're useful for their purposes, but good point that honeypots can create more risk.

Of course, if you can use the honeypot to then track the attacker down for swift justice -- effectively killing the bear, stuffing it, and displaying it at your home -- you potentially deter other bears.
RyanSepe
RyanSepe,
User Rank: Ninja
6/30/2015 | 10:53:22 AM
Re: Poking the Bear
I'm sure it is. Like everything it has its benefits as well as its detriments. There are multiple ideologies on this subject and can't say that any is more right than the other. It was just my opinion that bating criminals isn't always the best practice.
Kelly Jackson Higgins
Kelly Jackson Higgins,
User Rank: Strategist
6/30/2015 | 10:41:59 AM
Re: Poking the Bear
A honeypot is very useful as long as you know what you are doing. 
RyanSepe
RyanSepe,
User Rank: Ninja
6/30/2015 | 10:00:39 AM
Poking the Bear
I understand the utilization of honeypots and honeynets however I'm can't say I'm an advocate. It's like seeing a bear and instead of trying to scare it away with loud noises you lure it with honey into your basement to avoid it being in the main levels of your house or yard. Most likely you'll aggravate the bear/malicious intender and you run a higher risk of them messing up your house/network or worse.


Edge-DRsplash-10-edge-articles
I Smell a RAT! New Cybersecurity Threats for the Crypto Industry
David Trepp, Partner, IT Assurance with accounting and advisory firm BPM LLP,  7/9/2021
News
Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours
Robert Lemos, Contributing Writer,  7/7/2021
Commentary
It's in the Game (but It Shouldn't Be)
Tal Memran, Cybersecurity Expert, CYE,  7/9/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Black Hat USA 2022 Attendee Report
Black Hat attendees are not sleeping well. Between concerns about attacks against cloud services, ransomware, and the growing risks to the global supply chain, these security pros have a lot to be worried about. Read our 2022 report to hear what they're concerned about now.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2022-35734
PUBLISHED: 2022-08-16
'Hulu / ????' App for Android from version 3.0.47 to the version prior to 3.1.2 uses a hard-coded API key for an external service. By exploiting this vulnerability, API key for an external service may be obtained by analyzing data in the app.
CVE-2022-36293
PUBLISHED: 2022-08-16
Buffer overflow vulnerability in Nintendo Wi-Fi Network Adaptor WAP-001 All versions allows an attacker with an administrative privilege to execute arbitrary code via unspecified vectors.
CVE-2022-36344
PUBLISHED: 2022-08-16
An unquoted search path vulnerability exists in 'JustSystems JUST Online Update for J-License' bundled with multiple products for corporate users as in Ichitaro through Pro5 and others. Since the affected product starts another program with an unquoted file path, a malicious file may be executed wit...
CVE-2022-36381
PUBLISHED: 2022-08-16
OS command injection vulnerability in Nintendo Wi-Fi Network Adaptor WAP-001 All versions allows an attacker with an administrative privilege to execute arbitrary OS commands via unspecified vectors.
CVE-2022-34156
PUBLISHED: 2022-08-16
'Hulu / ????' App for iOS versions prior to 3.0.81 improperly verifies server certificates, which may allow an attacker to eavesdrop on an encrypted communication via a man-in-the-middle attack.