1
00:00:06,210 --> 00:00:07,590
- [Instructor] In this
segment, we're gonna take

2
00:00:07,590 --> 00:00:10,290
a look at a very simple honeypot.

3
00:00:10,290 --> 00:00:13,530
Now, just as a refresher, there
are two types of honeypots:

4
00:00:13,530 --> 00:00:16,380
high interaction honeypots,
which are live systems,

5
00:00:16,380 --> 00:00:20,010
and low interaction honeypots
that imitate services

6
00:00:20,010 --> 00:00:22,950
that frequently attract
attacker attention,

7
00:00:22,950 --> 00:00:27,180
such as FTP, HTTP, and Telnet.

8
00:00:27,180 --> 00:00:28,440
Now, we're going to use

9
00:00:28,440 --> 00:00:30,790
an applet called BackOfficer Friendly

10
00:00:32,010 --> 00:00:35,100
to configure a low interaction honeypot,

11
00:00:35,100 --> 00:00:37,980
and we're gonna configure
BackOfficer Friendly

12
00:00:37,980 --> 00:00:42,540
to imitate FTP, Telnet, and HTTP services,

13
00:00:42,540 --> 00:00:44,640
as well as fake replies.

14
00:00:44,640 --> 00:00:46,320
But before we do that, I wanna prove

15
00:00:46,320 --> 00:00:49,320
to you that I'm actually
not running those services

16
00:00:49,320 --> 00:00:50,910
on this workstation.

17
00:00:50,910 --> 00:00:53,250
So, I'm gonna use Angry IP Scanner,

18
00:00:53,250 --> 00:00:55,440
and I'm just gonna do a quick port scan.

19
00:00:55,440 --> 00:00:57,510
And I've configured the port scan only

20
00:00:57,510 --> 00:01:00,150
to look for ports one through 100.

21
00:01:00,150 --> 00:01:02,460
And that's because the
ports that we're actually

22
00:01:02,460 --> 00:01:06,450
going to be imitating
ports 21, 23, and 80.

23
00:01:06,450 --> 00:01:09,153
So if they were open, they
would show in this scan.

24
00:01:10,290 --> 00:01:11,763
Our scan is complete.

25
00:01:13,230 --> 00:01:16,290
I did a port scan on the
local host, and you can see

26
00:01:16,290 --> 00:01:18,150
where it says ports in that range.

27
00:01:18,150 --> 00:01:20,823
It's gonna be one to 100, not available.

28
00:01:22,410 --> 00:01:25,320
Now I'm gonna come back up
to BackOfficer Friendly,

29
00:01:25,320 --> 00:01:26,153
and I'm gonna say,

30
00:01:26,153 --> 00:01:27,990
Listen for FTP.
(computer chiming)

31
00:01:27,990 --> 00:01:28,823
I'm going to say

32
00:01:28,823 --> 00:01:30,660
Listen for HTTP,
(computer chiming)

33
00:01:30,660 --> 00:01:33,210
and Listen for Telnet.
(computer chiming)

34
00:01:33,210 --> 00:01:36,303
I'm also gonna say fake some replies.

35
00:01:37,650 --> 00:01:39,630
So now, BackOfficer Friendly is

36
00:01:39,630 --> 00:01:43,770
a low interaction honeypot that is seeming

37
00:01:43,770 --> 00:01:45,870
to be available and listening

38
00:01:45,870 --> 00:01:49,563
on ports 21, 23, and 80.

39
00:01:50,490 --> 00:01:52,923
So, let's go ahead and re-scan the range.

40
00:01:56,143 --> 00:01:57,930
(computer chiming)
And if you look up

41
00:01:57,930 --> 00:02:01,530
at the warning from BackOfficer Friendly,

42
00:02:01,530 --> 00:02:02,363
the warning screen,
(computer chiming)

43
00:02:02,363 --> 00:02:04,350
what you'll see is it just got a request

44
00:02:04,350 --> 00:02:07,500
for an FTP connection,
a Telenet connection,

45
00:02:07,500 --> 00:02:10,323
and an HTPP request connection.

46
00:02:11,910 --> 00:02:15,840
And if I come down to my
port scanner, it now appears

47
00:02:15,840 --> 00:02:20,790
that ports 21, 23, and 80 are all active.

48
00:02:20,790 --> 00:02:22,170
That means they're listening

49
00:02:22,170 --> 00:02:27,170
for FTP, Telnet, and HTTP requests.

50
00:02:29,400 --> 00:02:30,840
Let me show this to you another way.

51
00:02:30,840 --> 00:02:33,570
I'm gonna come over to my command prompt,

52
00:02:33,570 --> 00:02:36,480
and I'm going to launch an FTP session.

53
00:02:36,480 --> 00:02:41,077
I'm gonna say open 192.168.0.191.

54
00:02:43,350 --> 00:02:44,340
(computer chiming)

55
00:02:44,340 --> 00:02:46,050
It tells me that I'm connected,

56
00:02:46,050 --> 00:02:48,210
but then tells me that
service is unavailable,

57
00:02:48,210 --> 00:02:50,610
and the connection was
closed by the remote host.

58
00:02:50,610 --> 00:02:54,330
And if you look in the BackOfficer
Friendly warning screen,

59
00:02:54,330 --> 00:02:55,230
you'll see that there was

60
00:02:55,230 --> 00:03:00,230
an FTP connection from 192.168.0.191

61
00:03:00,360 --> 00:03:04,230
Now, the connection closed by
remote host was a fake reply.

62
00:03:04,230 --> 00:03:07,353
If I come back to my options,
and I turn off fake reply,

63
00:03:09,030 --> 00:03:10,620
and I do this again.

64
00:03:10,620 --> 00:03:11,841
I'm gonna

65
00:03:11,841 --> 00:03:12,791
open 192.168.0.191,

66
00:03:17,074 --> 00:03:18,360
(computer chiming)
And this time,

67
00:03:18,360 --> 00:03:20,190
I'm gonna get the connection

68
00:03:20,190 --> 00:03:24,480
to 191.600.191, connection
closed by remote host.

69
00:03:24,480 --> 00:03:26,430
So I get a different message.

70
00:03:26,430 --> 00:03:29,220
The top message was
because I had fake replies.

71
00:03:29,220 --> 00:03:32,583
The bottom was because I don't
have fake replies enabled.

72
00:03:34,350 --> 00:03:36,930
Honeypots are a deception technique

73
00:03:36,930 --> 00:03:40,080
that allows security defenders to predict

74
00:03:40,080 --> 00:03:43,020
and understand attacker behavior patterns.

75
00:03:43,020 --> 00:03:46,470
Now, honeypots vary based on
design and deployment models,

76
00:03:46,470 --> 00:03:48,540
but what they all have in common is

77
00:03:48,540 --> 00:03:50,910
that they're intended to look legitimate

78
00:03:50,910 --> 00:03:53,190
to attract attackers.

79
00:03:53,190 --> 00:03:55,443
And that, my friends, is a closer look.
