jongleur_kit writes "Today I received the latest in a series of scam phone calls. This time it was the "ammyy scam," in which the scammer tries to get you to install a remote access program. After playing dumb for a while to see how they operate I had to stop there and confront them on their nefarious methods (they get you to open your Windows event log and tell you that the errors and warnings are undelete-able "viruses" and hence you need their services). At that point they immediately hung up.
I was frustrated that I couldn't go further with this and collect more information on the scammers. I have an MSc in Computer Science, and I think it would be a fun project to create a honeypot for just such instances.
I assume a good honeypot would involve a VM and some active (nmap) scanning and also some passive (p0f) scanning, ideally with the ability to record sequences of actions on my box if I let them in.
Can anyone point me to a good forum or how-to guide on this, or give some advice in this thread? What would a good setup include?
Finally, I am a US citizen now living in the UK, and I have no idea what the legal context is here. What are the rules in the UK regarding entrapment, etc.? What if I were to run a few of these and post information (like IP addresses, phone numbers, etc.) in a blog post? Is that legal here?
Thanks
PS: I'm cross-posting this over at Reddit under user name abplayer."