GHH - The "Google Hack" Honeypot
- http://ghh.sourceforge.net/
- GHH emulates a vulnerable web application by allowing itself to be indexed by search engines. It is hidden from casual page viewers, but is found through the use of a crawler or search engine.
Honeyd
- http://www.citi.umich.edu/u/provos/honeyd/
- Small daemon that creates virtual hosts on a network (honeypot). Can be used as a virtual honeynet, for network monitoring, or as a spam trap. For *BSD, GNU/Linux, and Solaris.
Honeynet.BR
- http://www.honeynet.org.br/
- Brazilian Honeypots Alliance. Includes tools to summaries honeyd logs, mydoom.pl (A perl script which emulates the backdoor installed by the Mydoom virus), and an OpenBSD LiveCD Honeypot.
Honeypots
- http://www.honeypots.net/
- Information covering intrusion detection and prevention systems, research and production honeypots, and incident handling. Also provides general overview of network security issues.
Impost
- http://impost.sourceforge.net/
- Impost can either act as a honey pot and take orders from a Perl script controlling how it responds and communicates with connecting clients; or it can operate as a packet sniffer and monitor incoming data to specified destination port supplied by the command-line arguments (pre-release version available).
New Zealand Honeynet project
- http://www.nz-honeynet.org
- Papers and information on honeypots, especially application layer, e.g. PHP applications, from the New Zealand branch of the Honeynet project (http://www.honeynet.org/).
The Bait and Switch Honeypot System
- http://baitnswitch.sourceforge.net/
- A system that redirects all hostile traffic from your production systems to a honeypot that is a partial mirror of your production system. Once switched, the would-be hacker is unknowingly attacking your honeypot instead of the real data.
The Team Cymru Darknet Project
- http://www.cymru.com/Darknet/
- A Darknet is a portion of routed, allocated IP space in which no active services or servers seemingly reside. However, there is in fact include at least one server for real-time analysis or post-event network forensics.
UK Honeynet Project
- http://www.ukhoneynet.org/
- Provides information surrounding security threats and vulnerabilities active in the wild on UK networks. Home of Honeysnap, tool to analyse Honeywall pcap files and extract summary information.
WebMaven (Buggy Bank)
- http://www.mavensecurity.com/webmaven
- WebMaven is an intentionally broken web application. It is intended to be used in a safe legal environment (your own host) as a training tool, as a basic benchmark platform to test web application security scanners and as a Honeypot.
fakeAP
- http://www.blackalchemy.to/project/fakeap/
- Generates thousands of counterfeit 802.11b access points for use as part of a honeypot or to confuse Wardrivers, NetStumblers, Script Kiddies, and other undesirables.
mwcollect
- http://www.mwcollect.org
- A solution to collect worms and other autonomous spreading malware in a non-native environment like FreeBSD or Linux. Some people consider it a next generation honeypot, however computers running mwcollect cannot actually be infected with the malware.
spank
- http://spank.sourceforge.net/
- A collection of programs to deploy, run and analyse network and host simulations in IP networks.