3 ms·
> It is likely with these tell-tale signs and strange configuration not many hackers will stumble across the host, and if they do they’ll probably quit our righ
by duck2 10y ago
> It is likely with these tell-tale signs and strange configuration not many hackers will stumble across the host, and if they do they’ll probably quit our right away.
This got me thinking about setting all my hostnames to "honeypot" and randomly printing fake HonSSH logs in all SSH connections.
Security by... mimicking?
- robputt796 10y agoNot sure if this is a good idea or not, security by obscurity never really fools anyone in my opinion... Anyway I think that the HonSSH logs are not visible to the attacker, they are on the man in the middle node so hence the hacker doesn't get to see them, for the most part it looks very very similar to a legitimate SSH connection.
- 010001001010 10y agoI'd agree this probably isn't a great idea, -- it may attract unnecessary attention which would have not already been there. If an attack is automated (where it may not consider the hostname at all) it will have no effect. If it is a targeted attack, the attacker will most likely be well versed in the behaviour of default honeypots. As such if you're machine behaves differently (as it almost always will) the attacker will not be deterred. One example of this includes response time of a failed SSH login -- a HP might reply sub-seconds faster than a real system (especially true in industrial environments).