Summarized Honeypot Compromises

Wednesday, August 30. 2006
The last blog postings described several honeypot compromises in more detail. In total, there were seven honeypot compromises in the first half of 2006 (diploma thesis of Jan Göbel). The following table summarizes these incidents, together with a brief description of each compromise:

Operating SystemVulnerability usedActions
1Red Hat 8.0weak passwordSSH scans
2Suse 9.1web applicationIRC proxy installation
3Red Hat 8.0web applicationphishing / scanning
4Suse 9.1web applicationphishing
5Red Hat .0weak passworduser-space IRC bot
6Red Hat 8.0weak passwordphishing
7Suse 9.1web applicationnone


The attack vectors used to compromise these honeypots were either weak passwords (SSH brute force scans) or vulnerable web applications. So none of the vulnerabilities present in these rather old Linux distributions were used. In the future, we will examine the threat posed by web applications in more detail, mainly focussing on phpMyAdmin and XMLRPC. So stay tuned for further reports :-)