Monday, July 18, 2011

LaBrea: "Sticky" Honeypot and IDS

LaBrea takes over unused IP addresses, and creates virtual servers that are attractive to worms, hackers, and other denizens of the Internet. The program answers connection attempts in such a way that the machine at the other end gets "stuck", sometimes for a very long time.

Grab a chair and listen while Tom Liston talks about LaBrea.

What you probably want

This is the SourceForge LaBrea web site.

Here is where you can:

Download the latest version
Report a bug
Get some help
See the project news
To see the whole shebang: LaBrea Project Summary

and here is Tom Liston's personal web site: Hackbusters Home Page

Supported platforms

The latest version of LaBrea has been tested on:

FreeBSD
Linux
Solaris
Windows (98/2K)
LaBrea uses autoconf / automake as well as Dug Song's libdnet, it should easily port to other platforms.

(Of course, if you believe that, I have a bridge I want to sell you ...)

Documentation

FAQ - Frequently asked questions from the labrea mailing list
README - Overview of program function and use
labrea(1) manpage - Program cmd-line parameters
labrea.conf(5) manpage - Configuration file
md5 checksums
Gpg signing key: keyid 42BBF360, fingerprint D825 6818 BDA3 EF10 F933 CBD6 F2BF 7977 42BB F360
Third party links

Michael's LaBrea::Tarpit module for perl is cool. Check it out: here. (But see our FAQ page for more information.)

Being on the Bleeding edge

Like to live dangerously? You want to be right up there with the latest and greatest?

Then you just will not be happy until you have your very own CVS copy of the LaBrea sources:

cvs -d :pserver:anonymous@cvs.sf.net:/cvsroot/LaBrea get LaBrea

But maybe you just want to browse the source code: labrea cvs web access