Sebek-WIN32 v3.0.4 Jun 17 2008 10:03AM
forensicist gmail com (2 replies)
Re: Sebek-WIN32 v3.0.4 Jul 01 2008 06:38PM
Blarnum, Seamus (crpyt0k1d yahoo com)
Re: Sebek-WIN32 v3.0.4 Jun 17 2008 12:26PM
Jamie Riden (jamie riden gmail com)
2008/6/17 <forensicist (at) gmail (dot) com [email concealed]>:
> I have scanned Sebek-WIN32 v3.0.3 & Sebek-WIN32 v3.0.4 but both are infected and AV detected it as a Malware.

Hi there,

Can you tell us which AV software you are using, and what malware it
claims to detect?

I guess it's just detecting it as a generic rootkit-type package.

> Also, when I restarted my PC1 after installation of Sebek-WIN32 v3.0.3 and restarted my PC2 after installation of Sebek-WIN32 v3.0.4, BLUE screen error occur.
> I am using Win 2003 server Enterprise Edition with Sp2 and HoneyNet CD-ROM roo-1.4.hw-20080423134017.

I doubt it's been tested with Win 2K3 Enterprise Edition, because EE
1) is expensive and 2) has features which aren't particularly needed
for honeypots.

I wouldn't run AV software at the same time as sebek, if that's what
you're doing. If so, try disabling the AV and see what happens.

Hopefully someone can say if they've got it working with plain Win 2K3 or not.

Jamie Riden / jamesr (at) europe (dot) com [email concealed] / jamie (at) honeynet.org (dot) uk [email concealed]
UK Honeynet Project: http://www.ukhoneynet.org/

[ reply ]


Privacy Statement
Copyright 2010, SecurityFocus