|
Honeypot Mirroring .edu domains under .eu / Active Threat |
|
|
|
Source: SANS - Posted by Benjamin D. Thomas
|
he .eu top-level domain is relatively new and in the build-up phase and had a co-worker notice something fun.
When ssh'ing to a local server, he typo'd and finished the DNS name as .eu, it connected with an SSH handshake (it was a new server so the key warning wasn't considered a big deal) and took a password. The individual immediately recognized the problem when the password wasn't accepted and we investigated.
It appears any DNS name at ourdomain.eu would resolve to this machine. Not only that, but the machine in question was hosting at least 7 other domains under .eu that would map to an educational institution. For instance, for "fake" educational institution at ufoo.edu you could search for ufoo.eu and get a response to this machine.
Read this full article at SANS
Powered by AkoComment! |