PDA

View Full Version : gatesweeper: firewall with a honeypot?


areyousure
October 31st, 2006, 01:35 AM
i came across this firewall product gatesweeper at http://www.gatesweeper.com/ which intrigues me with a built-in feature: honeypot, and its description goes:

Our unique, rule-based "Bouncer" program module redirects the hacker to our exclusive “HoneyPot”. The “HoneyPot” is an isolated server at our Command and Control Center that will collect information about the hacker as evidence to be used later in possible prosecution. While the hacker thinks he has entered your system, he is actually redirected to ours and becomes caught in the "HoneyPot".

anyone already tried it? and how is the honeypot supposed to work?

Stem
October 31st, 2006, 06:59 AM
I have not (yet) used this firewall, but I have used "Honeypots".

http://en.wikipedia.org/wiki/Honeypot_(computing)


Do be aware that this firewall as a yearly subscription.

Also:- just a note for users who dont like the firewall sending any data out to the vendors servers:-
-{ Quote: "GATESWEEPER collects the user’s machine’s IP, and certain information in order to provide the software distributor companies with proper information regarding its functioning" }-

areyousure
November 1st, 2006, 08:07 AM
yeah, sending out personal data back to the vendor is really a big issue for me. but i'm wondering if the vendor's server is the only honeypot to direct attacks and suspicious data to.

pretty expensive firewall, costs 50 bucks, much more than OP and ZA.

Stem
November 1st, 2006, 08:49 AM
-{ Quote: "yeah, sending out personal data back to the vendor is really a big issue for me. but i'm wondering if the vendor's server is the only honeypot to direct attacks and suspicious data to. " }-Have a read of the disclaimer http://www.gatesweeper.com/download.php

-{ Quote: "pretty expensive firewall, costs 50 bucks, much more than OP and ZA." }-This is a yearly charge, this will be due to using their servers as honypot.

aigle
November 1st, 2006, 09:16 AM
Are these honeypots really effective?

Stem
November 1st, 2006, 09:31 AM
-{ Quote: "Are these honeypots really effective?" }-Honypots are virtual servers, such as HTTP(web) or pop3(MAIL) or all/any. Some have traps, some are there just to log all the activity of the attack.
-{ Quote: "A honeypot is an internet attached server which is expressly set up to act as a decoy to lure potential hackers, crackers and script kiddies. Once attracted the intruder's activities is studied and monitored to determine the vulnerabilities of the system, thereby learning where the system needs to be redesigned to ensure complete impregnability.

Honeypots are designed to mimic systems which appeal to an intruder but at the same time limits the access to an entire network. This guarantees the hacker can be caught and stopped while trying to obtain root access to the system. Most honeypots are installed inside firewalls so that they can be better controlled. A firewall in a honeypot works in the opposite way that a normal firewall functions: instead of restricting what comes into a system from the Internet, the honeypot firewall allows all traffic to come in from the Internet and restricts what the system sends back out. " }-

smith2006
November 14th, 2006, 10:50 PM
Is Global Investment International Corp (the registrant of gatesweeper.com according to WHOIS) a reliable name in the security industry?

EDIT:

There is a whole forum dedicated to this company - Here (http://www.setbb.com/xcorp/) :D

Longboard
November 15th, 2006, 12:36 AM
lol
they've upset some peeples.
Maybe steer clear?

smith2006
November 15th, 2006, 02:16 AM
-{ Quote: "lol
they've upset some peeples.
Maybe steer clear?" }-

;D

Another (http://www.wallstraits.com/community/viewthread.php?tid=285) one for you.