Category Archive: Honeypots

Feb 16 2012

New version of Kippo-Graph: 0.6.4

This is the release of a new version of Kippo-Graph, fixing some issues. Updating is recommended. There was some errors on some of the charts concerning the date values. The SQL query I’ve been using didn’t work correctly with the coming of a new year, plus the custom function I’ve been using for parsing had …

Continue reading »

Feb 13 2012

Kippo is being detected by Metasploit

So… I saw a new issue today in Kippo’s website that was posted some days ago. It seems that Kippo is not only recognizable by a human attacker (see: Kippo reveals itself with ‘w’ and ‘uptime’ commands), but also without actually hacking into it. Apparently, a Metasploit Framework‘s module can detect a Kippo installation. The …

Continue reading »

Video

The Last HOPE: Ghetto IDS and Honeypots for the Home User

Jan 28 2012

New version of Kippo-Graph: 0.6.3

I’m pleased to release yet another updated version of Kippo-Graph: 0.6.3. It includes: New data for the Kippo-Input component: passwd, executed scripts and interesting commands tables. Two more graphs (successes per day and human activity bar chart) and fixes to others. Download it from here: kippo-graph-0.6.3 MD5 Checksum: 3B40524D0AC157C82661582014AB5BE0 SHA-1 Checksum: 31D0A2872BD346529E2D5535266822F7861E0C1E CHANGES: Version 0.6.3: …

Continue reading »

Jan 19 2012

Some Kojoney results

top10_commands

I had my Kojoney SSH Honeypot running for about a week or so. The operation was smooth, I didn’t experience any crashes and the logging function keeps enough interesting data. Since I’ll be moving on to other systems/projects soon, I thought I should share some data before ending its operation. The honeypot.log file has grown …

Continue reading »

Jan 10 2012

Kojoney SSH Honeypot, installation (CentOS) and configuration

I decided to give the second well-known SSH honeypot a try, the software that Kippo was inspired by: Kojoney. It is a low interaction honeypot that emulates the SSH service, and it’s written in Python like Kippo. I’m using a system with CentOS 5 32-bit installed, but the following should work for higher versions as …

Continue reading »

Jan 08 2012

Some Dionaea statistics

dionaea-overview

I thought I should share some statistics from the Dionaea honeypot, after ~4 days of operation. My dionaea.log file is around 135MB, the SQLite database is around 68MB, and the system downloaded 45MB of malware. Automatic uploading to VirusTotal did not work for some reason though. Using Infosanity’s script , here is the output: And …

Continue reading »

Page 13 of 16« First...1112131415...Last »