Risk Associated with BOF
As a low-interaction honeypot, BOF adds very little risk. There is really nothing for the attacker to interact with or exploit. At the time of this writing, there are no known exploits for the application. The actual application is very small in size—98 Kbytes—meaning there is very little code involved. As such, this limits the potential for vulnerabilities. The risk lies in the system on which BOF is installed. You must make sure that the system is itself secured. An attacker may not be able to exploit any services on BOF but may be able to exploit any Windows exploits that exist on the system itself. As such, best practices must be applied to the base operating system.
However, BOF does have a high risk of detection ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access