
Virtual Honeypots 165
unzip and then download and install the ADMsniff and use it to
sniff telnet sessions. The goal from the WhiteHat’s perspective is
to be able to effectively monitor all of this activity by using xtail to
monitor the VMware REDO virtual disk fi le. Further capture the
live network/attacker activity.
Figure 6.13 shows both the VMware Guest OS Linux Desktop
honeypot system and the Windows 2000 Host OS system with the
cygwin/Xtail applications running.
Figure 6.13 VMware Guest Linux OS with Cygwin/Xtail Application Monitoring.
Figure displays the data captured by Xtail when the fi le called
ADMsniff.tar.gz was unzipped within ...