[KLUG Members] LaBrea

Mike Morrett members@kalamazoolinux.org
Mon, 06 Jan 2003 21:34:18 -0500


Anyone tried "LaBrea"?

http://www.hackbusters.net/

"LaBrea is a way to combat both port scanners and worms such as Code Red
and Nimda. The original network administrator's "LaBrea" creates phantom
machines which hold scanners and worms in a sort of "tarpit", luring them
in, and holding onto their communications with what they think are real
machines."

http://www.eweek.com/article2/0,3959,2385,00.asp

"LaBrea--LaBrea is a freeware application from developer Tom Liston, and
it's the only tool available that actually lets businesses fight back
against Nimda and other damaging worms and Trojans. This simple but
revolutionary tool sits on unused IP addresses. When a worm attempts to
connect, LaBrea sends false response information that traps the worm and
prevents it from attacking other systems."

Mike
--
cat /dev/coffee | /dev/cup | /dev/mouth | /dev/nose > /dev/keyboard