Summarized Honeypot Compromises
| Operating System | Vulnerability used | Actions | |
|---|---|---|---|
| 1 | Red Hat 8.0 | weak password | SSH scans |
| 2 | Suse 9.1 | web application | IRC proxy installation |
| 3 | Red Hat 8.0 | web application | phishing / scanning |
| 4 | Suse 9.1 | web application | phishing |
| 5 | Red Hat .0 | weak password | user-space IRC bot | 6 | Red Hat 8.0 | weak password | phishing |
| 7 | Suse 9.1 | web application | none |
The attack vectors used to compromise these honeypots were either weak passwords (SSH brute force scans) or vulnerable web applications. So none of the vulnerabilities present in these rather old Linux distributions were used. In the future, we will examine the threat posed by web applications in more detail, mainly focussing on phpMyAdmin and XMLRPC. So stay tuned for further reports :-)


