Oct 09 2006
obichbiche googlemail com
Hi All,

I?ve attacked my own virtual honeypot running a windows XP box (In VMware workstation5.5), I took a word document of 38KB from there, when I check in walleye I can see that Sebek recorded the intrusion and even the size of the packet which is what I would expect, but the thing is when I try to reconstruct the packets to get the word file from there using the Pcap file provided by Walleye for the flow in question, the size of the packet is reduced to half in certain occasions.

My question is: does Sebek record all the information and take only a fraction of the flow and send it to Honeywall or it does encapsulate everything?







