4 ms·
My main concern is, if an attacker has the ability to nmap against my private IP range, they're already in the network and I'm already pwned. Am I missing somet
by zrobotics 2y ago
My main concern is, if an attacker has the ability to nmap against my private IP range, they're already in the network and I'm already pwned. Am I missing something here? Plus, with this tool running I would lose the ability to run nmap scans, which are a super useful diagnostic tool.
I do have a honeypot machine setup, but that's mainly as a last line of intrusion detection than an active defense (plus, it was a fun way to spend a Friday afternoon). I've seen proposals for similar systems before and while the idea is interesting I just don't think it accomplishes anything useful. My honeypot also doesn't accomplish anything truly useful, but it also doesn't negatively affect the network by not allowing me to run scans.
- TacticalCoder 2y agoI think an honeypot is always a good idea and it sure helps to know that you're being targeted but... > My main concern is, if an attacker has the ability to nmap against my private IP range For a start I consider that chinese IoT shits and SmartTVs are attackers. So the attackers are already in my network. And if they're not, they've got very easy targets: these IoT (Internet-of-(Insecure-and-Shitty-)Things) devices. Note that you can run several LANs too. I've got 192.168.x. and 10.x.x.x. One is way more secure than the other (no WiFi device on the more secure one, a very strict firewall in between the two LANs, etc.). Heck, even my ISP by default hands a router that separates the home LAN and the "guests" LAN. A nmap from 192.168.x.x shall not give any result for stuff on 10.x.x.x and vice-versa. You can do it by configuring trunking / VLANs or physically. Mine is just physical: unmanaged switches, a few of them on one LAN, another one dedicated to the more secure LAN. The box that does the routing between the two LANs only does two things: firewalling and routing traffic. Nothing else. No SSH port open. No ports open whatsoever. No nothing. Firewalling and routing and that's it. > ... they're already in the network and I'm already pwned. Not really though. You should be able to work properly and securely if your main computer isn't compromised. It should really be no different than using a laptop from a public place.