<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Infosanity&#039;s Blog &#187; Honeypot</title>
	<atom:link href="http://blog.infosanity.co.uk/category/honeypot/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.infosanity.co.uk</link>
	<description>Offensive and Defensive IT Security</description>
	<lastBuildDate>Fri, 03 Feb 2012 10:21:18 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='blog.infosanity.co.uk' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://1.gravatar.com/blavatar/f0350d3bea8a050ccac1e7c2b067d03b?s=96&#038;d=http%3A%2F%2Fs2.wp.com%2Fi%2Fbuttonw-com.png</url>
		<title>Infosanity&#039;s Blog &#187; Honeypot</title>
		<link>http://blog.infosanity.co.uk</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://blog.infosanity.co.uk/osd.xml" title="Infosanity&#039;s Blog" />
	<atom:link rel='hub' href='http://blog.infosanity.co.uk/?pushpress=hub'/>
		<item>
		<title>HoneyD network architecture</title>
		<link>http://blog.infosanity.co.uk/2012/01/31/honeyd-network-architecture/</link>
		<comments>http://blog.infosanity.co.uk/2012/01/31/honeyd-network-architecture/#comments</comments>
		<pubDate>Tue, 31 Jan 2012 21:00:56 +0000</pubDate>
		<dc:creator>Andrew Waite</dc:creator>
				<category><![CDATA[honeyd]]></category>
		<category><![CDATA[Honeypot]]></category>
		<category><![CDATA[InfoSec]]></category>
		<category><![CDATA[Lab]]></category>

		<guid isPermaLink="false">http://blog.infosanity.co.uk/?p=1150</guid>
		<description><![CDATA[I was recently asked about the network configuration I use for my honeyd sensor. As I now have a pretty(ish) network diagram showing my setup as a result, decided sharing is caring.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.infosanity.co.uk&amp;blog=8614004&amp;post=1150&amp;subd=infosanity&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I was recently asked about the network configuration I use for my <a title="Starting with HoneyD" href="http://blog.infosanity.co.uk/2010/01/19/starting-with-honeyd/">honeyd</a> sensor. I had thought I&#8217;d already written about this so initially went to find the article on <a title="Basic HoneyD configuration" href="http://blog.infosanity.co.uk/2010/04/17/basic-honeyd-configuration/">honeyd configuration</a>; but my memory was wrong and the original post only covered configuring the guest systems, not the honeyd host itself. So, as I now have a pretty(ish) network diagram showing my setup I may as well correct the earlier omission.</p>
<p>&lt;DISCLAIMER: This may not be the best network design for running honeyd, this is merely how my environment is configured and it works for me as a research platform. As usual, your mileage may vary, especially if your use-case differs from my own&gt;</p>
<p><a href="http://infosanity.files.wordpress.com/2012/01/honeyd-networkarchitecture-2.png"><img class="aligncenter size-full wp-image-1152" title="honeyd-NetworkArchitecture-2" src="http://infosanity.files.wordpress.com/2012/01/honeyd-networkarchitecture-2.png?w=600&#038;h=204" alt="" width="600" height="204" /></a></p>
<p>As can be seen, the design has three distinct network segments:</p>
<ul>
<li>Publicly route-able IPs</li>
<li>Internal network for honeypot hosts</li>
<li>Virtual network for honeyd guest systems. These IP addresses sit on loopback interface on the host, with a static route on the firewall to pass all virtual traffic to the honeyd host.</li>
</ul>
<p>Using a perimeter firewall with NAT/PAT capabilities allows easy switching between emulated systems and services if your public IP resources are limited; a large network of guests can be configured in advance and left static, then a quick firewall change is all that is required to expose different systems to the world.</p>
<p>Additionally, as much as honeypot systems are designed to be compromised and collect information of malicious attacks (or perhaps more correctly, because of this) , low-interaction systems like honeyd is designed to avoid full compromise. If something goes wrong and the host system gets fully compromised, a (sufficiently configured) perimeter firewall provides some control of outgoing traffic, limiting the attackers options for using the honeypot sensor to attack other systems.</p>
<p>Not much to it really; if you use an different setup and/or can suggest ways to improve the setup let me know, always looking to improve my systems where possible.</p>
<p>&#8211; Andrew Waite</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/infosanity.wordpress.com/1150/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/infosanity.wordpress.com/1150/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/infosanity.wordpress.com/1150/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/infosanity.wordpress.com/1150/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/infosanity.wordpress.com/1150/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/infosanity.wordpress.com/1150/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/infosanity.wordpress.com/1150/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/infosanity.wordpress.com/1150/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/infosanity.wordpress.com/1150/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/infosanity.wordpress.com/1150/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/infosanity.wordpress.com/1150/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/infosanity.wordpress.com/1150/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/infosanity.wordpress.com/1150/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/infosanity.wordpress.com/1150/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.infosanity.co.uk&amp;blog=8614004&amp;post=1150&amp;subd=infosanity&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.infosanity.co.uk/2012/01/31/honeyd-network-architecture/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/78c9d658d90cad982bfc9af08a2ff8dd?s=96&#38;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif&#38;r=G" medium="image">
			<media:title type="html">Infosanity</media:title>
		</media:content>

		<media:content url="http://infosanity.files.wordpress.com/2012/01/honeyd-networkarchitecture-2.png" medium="image">
			<media:title type="html">honeyd-NetworkArchitecture-2</media:title>
		</media:content>
	</item>
		<item>
		<title>Starting with Artillery</title>
		<link>http://blog.infosanity.co.uk/2011/10/16/1098/</link>
		<comments>http://blog.infosanity.co.uk/2011/10/16/1098/#comments</comments>
		<pubDate>Sun, 16 Oct 2011 10:54:19 +0000</pubDate>
		<dc:creator>Andrew Waite</dc:creator>
				<category><![CDATA[Artillery]]></category>
		<category><![CDATA[Honeypot]]></category>

		<guid isPermaLink="false">http://blog.infosanity.co.uk/?p=1098</guid>
		<description><![CDATA[announced the alpha release of a new honeypot, Artillery.

Artillery is a combination of a honeypot, file monitoring and integrity, alerting, and brute force prevention tool. It’s extremely light weight, has multiple different methods for detecting specific attacks and eventually will also notify you of insecure nix configurations.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.infosanity.co.uk&amp;blog=8614004&amp;post=1098&amp;subd=infosanity&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>On Friday I arrived home looking forward to a well-earned rest; unfortunately Dave Kennedy seemed to have other ideas for my weekend as he <a title="@dave_rel1k announces Artillery" href="http://twitter.com/#!/dave_rel1k/status/124896502761013249">announced</a> the alpha release of a new honeypot, <a title="Secmaniac - artillery release post" href="http://www.secmaniac.com/blog/2011/10/14/new-tool-release-artillery-for-linux-protection/">Artillery</a>.</p>
<blockquote><p>Artillery is a combination of a honeypot, file monitoring and integrity, alerting, and brute force prevention tool. It’s extremely light weight, has multiple different methods for detecting specific attacks and eventually will also notify you of insecure nix configurations.</p></blockquote>
<p>Installation of Artillery is currently really simple, download via svn, run the installer script, edit the config file (if necessary) and run:</p>
<blockquote><p>$svn co http://svn.secmaniac.com/artillery artillery/</p>
<p>$./installer.py</p>
<p>$nano config</p>
<p>$./artillery.py</p></blockquote>
<p><em>N.B. don&#8217;t make the same daft error I made initially by editing the files in the svn download. Once the installer.py script has been run, cd to /var/artillery.</em></p>
<p>Artillery goes beyond typical honeypots, as it actively blocks remote clients and protects the system it&#8217;s running on. Artillery listens on a number of common ports (configurable, look at the PORTS variable), if it receives a connection on any of the fake ports it permanently blocks the source IP address by adding a DROP rule to iptables.</p>
<p>From my experience Artillery gets results REALLY quickly. After getting the system online I performed a quick test from another host under my control and starting writing up this post; in the time it&#8217;s taken to write the content above Artillery has already added 8 addresses  to iptables:</p>
<blockquote>
<pre>Chain INPUT (policy ACCEPT)
target     prot opt source                                destination
DROP       all  --  host-31-42-163-53.pois.com.ua         anywhere
DROP       all  --  net242.187.188-2.oren.ertelecom.ru    anywhere
DROP       all  --  94-21-36-156.pool.digikabel.hu        anywhere
DROP       all  --  89.122.216.109                        anywhere
DROP       all  --  ras.beamtele.net                      anywhere
DROP       all  --  dsl5401A8C9.pool.t-online.hu          anywhere
DROP       all  --  catv-178-48-151-67.catv.broadband.hu  anywhere
DROP       all  --  176.14.205.91                         anywhere</pre>
</blockquote>
<p>Other functionality included in Artillery mirrors that of Tripwire, monitoring the contents of different directories (again, configurable) and generating alerts if the contents of the directories and files changes.</p>
<p>I really like the premise of Artillery, and Dave in his usual fashion is coding like a madman adding fixes and new functionality (new version, 0.1.1 was released 24hrs after initial announcement). I&#8217;d be wary where you set this system up to test it though due to the automatic lockout; if Artillery is on a remote system, and you connect to a dummy port from your location to test you&#8217;ve just been locked out of your own server ;)</p>
<p>Looking forward to seeing Artillery mature, thanks Dave.</p>
<p>&#8211;Andrew Waite</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/infosanity.wordpress.com/1098/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/infosanity.wordpress.com/1098/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/infosanity.wordpress.com/1098/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/infosanity.wordpress.com/1098/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/infosanity.wordpress.com/1098/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/infosanity.wordpress.com/1098/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/infosanity.wordpress.com/1098/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/infosanity.wordpress.com/1098/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/infosanity.wordpress.com/1098/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/infosanity.wordpress.com/1098/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/infosanity.wordpress.com/1098/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/infosanity.wordpress.com/1098/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/infosanity.wordpress.com/1098/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/infosanity.wordpress.com/1098/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.infosanity.co.uk&amp;blog=8614004&amp;post=1098&amp;subd=infosanity&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.infosanity.co.uk/2011/10/16/1098/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/78c9d658d90cad982bfc9af08a2ff8dd?s=96&#38;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif&#38;r=G" medium="image">
			<media:title type="html">Infosanity</media:title>
		</media:content>
	</item>
		<item>
		<title>Kippo &#8211; Clearing pass.db</title>
		<link>http://blog.infosanity.co.uk/2011/06/26/kippo-clearing-pass-db/</link>
		<comments>http://blog.infosanity.co.uk/2011/06/26/kippo-clearing-pass-db/#comments</comments>
		<pubDate>Sun, 26 Jun 2011 23:40:00 +0000</pubDate>
		<dc:creator>Andrew Waite</dc:creator>
				<category><![CDATA[Honeypot]]></category>
		<category><![CDATA[Kippo]]></category>

		<guid isPermaLink="false">http://blog.infosanity.co.uk/?p=1053</guid>
		<description><![CDATA[Very quick post to highlight a process for clearing all entries from your pass.db file.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.infosanity.co.uk&amp;blog=8614004&amp;post=1053&amp;subd=infosanity&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Very quick post to highlight a process for clearing all entries from your <a title="Kippo – pass.db" href="http://blog.infosanity.co.uk/2011/06/20/kippo-pass-db/">pass.db</a> file. I had thought that this would take a bit of quick scripting utilising the list and remove modes from the passdb.py utility script. Turns out it&#8217;s even easier; simply pass a non-existent file to passdb.pyass.db parameter and it&#8217;ll create a fresh database file, no questions asked.</p>
<p>For example:</p>
<blockquote><p>/opt/kippo/utils/passdb.py /opt/kippo/data/idontexistyet.db add testpassword</p></blockquote>
<p>Will create a new database file with a single entry of &#8216;testpassword&#8217; (this can be removed once you&#8217;ve established everything works). N.B. even with a blank pass.db, kippo will provide access to the password(s) configured in kippo.cfg.</p>
<p>Not sure yet if clearing the database will net any interesting results, only time will tell&#8230;..</p>
<p>&#8211;Andrew Waite</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/infosanity.wordpress.com/1053/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/infosanity.wordpress.com/1053/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/infosanity.wordpress.com/1053/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/infosanity.wordpress.com/1053/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/infosanity.wordpress.com/1053/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/infosanity.wordpress.com/1053/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/infosanity.wordpress.com/1053/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/infosanity.wordpress.com/1053/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/infosanity.wordpress.com/1053/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/infosanity.wordpress.com/1053/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/infosanity.wordpress.com/1053/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/infosanity.wordpress.com/1053/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/infosanity.wordpress.com/1053/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/infosanity.wordpress.com/1053/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.infosanity.co.uk&amp;blog=8614004&amp;post=1053&amp;subd=infosanity&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.infosanity.co.uk/2011/06/26/kippo-clearing-pass-db/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/78c9d658d90cad982bfc9af08a2ff8dd?s=96&#38;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif&#38;r=G" medium="image">
			<media:title type="html">Infosanity</media:title>
		</media:content>
	</item>
		<item>
		<title>Kippo &#8211; pass.db</title>
		<link>http://blog.infosanity.co.uk/2011/06/20/kippo-pass-db/</link>
		<comments>http://blog.infosanity.co.uk/2011/06/20/kippo-pass-db/#comments</comments>
		<pubDate>Mon, 20 Jun 2011 18:32:39 +0000</pubDate>
		<dc:creator>Andrew Waite</dc:creator>
				<category><![CDATA[Honeypot]]></category>
		<category><![CDATA[InfoSec]]></category>
		<category><![CDATA[Kippo]]></category>

		<guid isPermaLink="false">http://blog.infosanity.co.uk/?p=1027</guid>
		<description><![CDATA[After a few weeks running my daily <a title="Reviewing Kippo Logs" href="http://blog.infosanity.co.uk/2011/05/23/reviewing-kippo-logs/">Kippo review script</a> I've noticed that whilst I'm still mostly receiving several logins per day, it's rare for a connection to actually interact with my emulated system. So I started trying to investigate what was causing the trend.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.infosanity.co.uk&amp;blog=8614004&amp;post=1027&amp;subd=infosanity&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>After a few weeks running my daily <a title="Reviewing Kippo Logs" href="http://blog.infosanity.co.uk/2011/05/23/reviewing-kippo-logs/">Kippo review script</a> I&#8217;ve noticed that whilst I&#8217;m still mostly receiving several logins per day, it&#8217;s rare for a connection to actually interact with my emulated system. (For those new here, Kippo is a medium interaction honeypot emulating an SSH daemon, get started <a title="Starting with Kippo (SSH Honeypot)" href="http://blog.infosanity.co.uk/2010/07/06/starting-with-kippo/">here</a>). So I started trying to investigate what was causing the trend.</p>
<p>One of Kippo&#8217;s features is the password database. Basically once an intruder gains access to the shell if they try to change the password or add a different account the system adds the password to the list of allowed. This then allows connections to log into the shell with the new password. Kippo ships with a small utility script to interact with the password database:</p>
<pre>@kippo01:/opt/kippo-svn/utils$ ./passdb.py
Usage: passdb.py &lt;pass.db&gt; &lt;add|remove|list&gt; [password]</pre>
<p>My pass.db file contains 26 entries added by malicious &#8216;users&#8217;; I&#8217;m still analysing the contents in detail, but it looks like the Bad Guys(tm) are paying attention to user education 101 and using long, complex passwords.</p>
<p>Using the password used to log into the system, I&#8217;ve had a new (to me) way to link disparate logins. For example the query below linked connections spanning two months, originating from multiple source IP address, across three different continents (according to WHOIS records).</p>
<p><strong>Source IPs for same user (based on pass)</strong></p>
<pre>SELECT sessions.id AS Session, sessions.ip AS Source, auth.password AS Password, auth.timestamp AS Time
FROM sessions, auth
WHERE
sessions.id = auth.session
AND auth.success = 1
AND auth.password = 'mariusbogdan';</pre>
<p>Similarly I looked for a connection between multiple successful logins from the same source IP address. The query below provided a list of report offenders:</p>
<p><strong>Successful logins from same source</strong></p>
<pre>SELECT COUNT(sessions.ip) AS Num, sessions.ip AS Source
FROM sessions, auth
WHERE
auth.success = 1
AND auth.session = sessions.id
GROUP BY sessions.ip
ORDER BY COUNT(sessions.ip) desc
LIMIT 25;</pre>
<p>My summary from this is that Kippo is receiving a lower level of &#8216;interesting&#8217; connections the longer the system is operational, as attackers login to check if they&#8217;ve maintained access to an &#8217;0wned&#8217; resource, without utilising the resource. I&#8217;m intending to clear my pass.db to remove existing access; hopefully this will return to more interesting connections and I&#8217;m also curious to see if any of my current tenants return from either the same source location(s) and/or re-using passwords (and proving me wrong with previous comment about user education).</p>
<p>&#8211;Andrew Waite</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/infosanity.wordpress.com/1027/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/infosanity.wordpress.com/1027/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/infosanity.wordpress.com/1027/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/infosanity.wordpress.com/1027/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/infosanity.wordpress.com/1027/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/infosanity.wordpress.com/1027/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/infosanity.wordpress.com/1027/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/infosanity.wordpress.com/1027/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/infosanity.wordpress.com/1027/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/infosanity.wordpress.com/1027/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/infosanity.wordpress.com/1027/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/infosanity.wordpress.com/1027/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/infosanity.wordpress.com/1027/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/infosanity.wordpress.com/1027/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.infosanity.co.uk&amp;blog=8614004&amp;post=1027&amp;subd=infosanity&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.infosanity.co.uk/2011/06/20/kippo-pass-db/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/78c9d658d90cad982bfc9af08a2ff8dd?s=96&#38;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif&#38;r=G" medium="image">
			<media:title type="html">Infosanity</media:title>
		</media:content>
	</item>
		<item>
		<title>Reviewing Kippo Logs</title>
		<link>http://blog.infosanity.co.uk/2011/05/23/reviewing-kippo-logs/</link>
		<comments>http://blog.infosanity.co.uk/2011/05/23/reviewing-kippo-logs/#comments</comments>
		<pubDate>Mon, 23 May 2011 09:30:38 +0000</pubDate>
		<dc:creator>Andrew Waite</dc:creator>
				<category><![CDATA[Honeypot]]></category>
		<category><![CDATA[Kippo]]></category>

		<guid isPermaLink="false">http://blog.infosanity.co.uk/?p=1012</guid>
		<description><![CDATA[When I first started running Kippo almost a year ago I had no difficulty getting motivated to log into the honeypot, check for new connections and generally get a feel for what my victims visitors have been up to. Slowly I'd check the logs less frequently, so I built a quick script to provide a daily review of activity.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.infosanity.co.uk&amp;blog=8614004&amp;post=1012&amp;subd=infosanity&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>When I first started running Kippo almost a <a title="Starting with Kippo (SSH Honeypot)" href="http://blog.infosanity.co.uk/2010/07/06/starting-with-kippo/">year ago</a> I had no difficulty getting motivated to log into the honeypot, check for new connections and generally get a feel for what my <del>victims</del> visitors have been up to. As time went by, sessions started to follow familiar patterns and some days would get no hits. Slowly I&#8217;d check the logs less frequently, and when I did I&#8217;d get an ever increasing backlog to review, decreasing my motivation further.</p>
<p>Recently I got annoyed with myself, my system was ticking along in the background but I was gaining no benefit from it. So in a moment of madness I dusted off my bash and built a quick script to provide a daily review of activity on my system. Essentially this does two things, lists session interaction and files downloaded within the last 24hours.</p>
<p>I&#8217;ve had the routine running daily for around a week; for days there was minmal activity on my system, either no logins at all, or logins with immediate disconnects. Today was different, and marked the first success of the script. Delivered to my morning inbox, along with the rest of my regular quick tasks and RSS feed as an interesting session. Malicious user connects, downloads a scanner (archive contents looks like <a title="Example of post exploit utilities (SSH scanners)" href="http://blog.infosanity.co.uk/2010/07/21/example-of-post-exploit-utilities/">gosh</a>), an irc bot (looks like <a title="EnergyMech IRC bot" href="http://www.energymech.net/">EnergyMech</a> derivative); and when attempts to run toolkit fail, downloads and runs three (yes, three, paranoia is strong with this one) log cleaners.</p>
<p>Example (snipped) output:</p>
<blockquote>
<pre>:~$ /opt/kippo-svn/kippo-sessions.sh
***Sessions***
---START:/opt/kippo-svn/log/tty/20110519-220029-5503.log---
www-dev:~# w
 22:00:38 up 14 days,  3:53,  1 user,  load average: 0.08, 0.02, 0.01
USER     TTY      FROM              LOGIN@   IDLE   JCPU   PCPU WHAT
root     pts/0    77.210.18.212     22:00    0.00s  0.00s  0.00s w
<strong>&lt;SNIP&gt;</strong>
***DOWNLOADS***
/opt/kippo-svn/dl/20110519220445_http___eduteam_home_ro_mech_gz: gzip compressed data, from Unix, last modified: Sun Oct  4 17:46:52 2009
<strong>&lt;SNIP&gt;</strong></pre>
</blockquote>
<p>The script can be downloaded <a title="Kippo-sessions.sh - Log Review" href="http://www.infosanity.co.uk/resources/scripts/kippo/kippo-sessions.sh">here</a>, as usual it&#8217;s released under the <a title="Beerware License" href="http://www.infosanity.co.uk/resources/beerware-license.txt">Beerware License</a></p>
<p>&#8211;Andrew Waite</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/infosanity.wordpress.com/1012/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/infosanity.wordpress.com/1012/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/infosanity.wordpress.com/1012/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/infosanity.wordpress.com/1012/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/infosanity.wordpress.com/1012/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/infosanity.wordpress.com/1012/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/infosanity.wordpress.com/1012/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/infosanity.wordpress.com/1012/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/infosanity.wordpress.com/1012/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/infosanity.wordpress.com/1012/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/infosanity.wordpress.com/1012/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/infosanity.wordpress.com/1012/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/infosanity.wordpress.com/1012/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/infosanity.wordpress.com/1012/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.infosanity.co.uk&amp;blog=8614004&amp;post=1012&amp;subd=infosanity&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.infosanity.co.uk/2011/05/23/reviewing-kippo-logs/feed/</wfw:commentRss>
		<slash:comments>9</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/78c9d658d90cad982bfc9af08a2ff8dd?s=96&#38;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif&#38;r=G" medium="image">
			<media:title type="html">Infosanity</media:title>
		</media:content>
	</item>
		<item>
		<title>Tales from the Kippo Logs: &#8216;hackers&#8217; with poor opsec&#8230;</title>
		<link>http://blog.infosanity.co.uk/2011/01/01/tales-from-the-kippo-logs-hackers-with-poor-opsec/</link>
		<comments>http://blog.infosanity.co.uk/2011/01/01/tales-from-the-kippo-logs-hackers-with-poor-opsec/#comments</comments>
		<pubDate>Sat, 01 Jan 2011 10:39:35 +0000</pubDate>
		<dc:creator>Andrew Waite</dc:creator>
				<category><![CDATA[Exploit]]></category>
		<category><![CDATA[Honeypot]]></category>
		<category><![CDATA[InfoSec]]></category>
		<category><![CDATA[Kippo]]></category>

		<guid isPermaLink="false">http://blog.infosanity.co.uk/?p=923</guid>
		<description><![CDATA[Running through my morning routine of catching up with email, twitter, etc. I came across this post showing Sequal7's first hits on a Kippo installation. In addition to making amusing reading, it gave me a nudge to check back on the InfoSanity Kippo sensor.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.infosanity.co.uk&amp;blog=8614004&amp;post=923&amp;subd=infosanity&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Running through my morning routine of catching up with email, twitter, etc. I came across <a title="O RLY?" href="https://seventhoctober.net/2010/04/o-rly/" target="_blank">this post</a> showing Sequal7&#8242;s first hits on a Kippo installation. In addition to making amusing reading, it gave me a nudge to check back on the InfoSanity Kippo sensor. Initially I was looking to see if the same individual had stumbled across my sensor; they hadn&#8217;t at least not from the information I have available.</p>
<p>However, when checking if the newly changed password matched anything in my database I found a new &#8216;realm&#8217; entry in the &#8216;input&#8217; table, &#8216;ssh&#8217;. This got me curious, one of my &#8216;guests&#8217; decided to hit another system whilst logged in to mine; ssh&#8217;ing to another IP, accepting the certificate and providing the password to said system (I&#8217;m assuming).</p>
<p>It should also be worth noting that by this point the user had already failed to notice that input hadn&#8217;t returned to their own system. After (attempting) to change my sensor&#8217;s root password (to &#8216;yahoo&#8217;, really) the user exited, but was caught out by Kippo&#8217;s trick of clearing the terminal and changing prompt to &#8216;localhost&#8217;, in total I viewed a ~20 minute terminal session of the user trying to compromise other systems, and failing in the same manner.</p>
<p>My assumption is that the user was running through a list of vulnerable systems identified by SSH scanners similar to the kit I <a title="Example of post exploit utilities (SSH scanners)" href="http://blog.infosanity.co.uk/2010/07/21/example-of-post-exploit-utilities/">wrote about earlier</a> (it wasn&#8217;t the same gosh.tgz kit, but first glance shows similar functionality). From this I feel it&#8217;s safe to assume that the systems connected to in the logs available are those of other (probably 0wned) systems, rather than anything connected to my guest. Likewise it is probable that the source connection is also a compromised third party rather than belonging to by guest.</p>
<p><strong>e.tgz </strong><strong>:</strong><br />
For the curious, archive contents:</p>
<blockquote><p>e/<br />
e/exp_moosecox.c<br />
e/funny.jpg<br />
e/exp_powerglove.so<br />
e/exp_ingom0wnar.c<br />
e/pwnkernel.c<br />
e/exp_cheddarbay.so<br />
e/exp_powerglove.c<br />
e/exp_ingom0wnar.so<br />
e/exp_therebel.so<br />
e/run_nonnull_exploits.sh<br />
e/exp_paokara.so<br />
e/exp_framework.h<br />
e/exp_moosecox.so<br />
e/exp_wunderbar.c<br />
e/exp_cheddarbay.c<br />
e/run_null_exploits.sh<br />
e/exploit.c<br />
e/exp_therebel.c<br />
e/exp_vmware.so<br />
e/exp_vmware.c<br />
e/exp_wunderbar.so<br />
e/exploit<br />
e/exp_paokara.c</p></blockquote>
<p>Whilst investigating the individual exploits and files; I came across <a href="http://scienceforums.com/topic/20248-ridiculous-26-exploit/" target="_blank">this post</a>, indicating &#8216;my&#8217; archive is a known fire and forget post exploit kit. <em>Here be Skiddies&#8230;</em></p>
<p>&#8211;Andrew Waite</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/infosanity.wordpress.com/923/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/infosanity.wordpress.com/923/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/infosanity.wordpress.com/923/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/infosanity.wordpress.com/923/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/infosanity.wordpress.com/923/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/infosanity.wordpress.com/923/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/infosanity.wordpress.com/923/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/infosanity.wordpress.com/923/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/infosanity.wordpress.com/923/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/infosanity.wordpress.com/923/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/infosanity.wordpress.com/923/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/infosanity.wordpress.com/923/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/infosanity.wordpress.com/923/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/infosanity.wordpress.com/923/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.infosanity.co.uk&amp;blog=8614004&amp;post=923&amp;subd=infosanity&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.infosanity.co.uk/2011/01/01/tales-from-the-kippo-logs-hackers-with-poor-opsec/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/78c9d658d90cad982bfc9af08a2ff8dd?s=96&#38;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif&#38;r=G" medium="image">
			<media:title type="html">Infosanity</media:title>
		</media:content>
	</item>
		<item>
		<title>Dionaea with p0f</title>
		<link>http://blog.infosanity.co.uk/2010/12/04/dionaea-with-p0f/</link>
		<comments>http://blog.infosanity.co.uk/2010/12/04/dionaea-with-p0f/#comments</comments>
		<pubDate>Sat, 04 Dec 2010 17:08:54 +0000</pubDate>
		<dc:creator>Andrew Waite</dc:creator>
				<category><![CDATA[Dionaea]]></category>
		<category><![CDATA[Honeypot]]></category>

		<guid isPermaLink="false">http://blog.infosanity.co.uk/?p=899</guid>
		<description><![CDATA[Working my way through the compilation instructions from Dionaea whilst building up my latest sensor I was reminded of some optional functionality that I'd always intended to implement, but never found the time. First on my list was p0f (that's a zero).<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.infosanity.co.uk&amp;blog=8614004&amp;post=899&amp;subd=infosanity&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Working my way through the compilation instructions from Dionaea whilst building up my <a title="Dionaea in the key of U(buntu)" href="http://blog.infosanity.co.uk/2010/12/04/dionaea-in-the-key-of-ubuntu/">latest sensor</a> I was reminded of some optional functionality that I&#8217;d always intended to implement, but never found the time. First on my list was p0f (that&#8217;s a zero).</p>
<p>From p0f&#8217;s <a title="p0f - coredump.cx" href="http://lcamtuf.coredump.cx/p0f.shtml">homepage</a>:</p>
<blockquote><p>P0f v2 is a versatile passive OS fingerprinting tool. P0f can identify the operating system on:</p>
<p>- machines that connect to your box (SYN mode),<br />
- machines you connect to (SYN+ACK mode),<br />
- machine you <strong>cannot</strong> connect to (RST+ mode),<br />
- machines whose communications you can observe.</p>
<p>P0f can also do many other tricks, and can detect or measure the following:</p>
<p>- firewall presence, NAT use (useful for policy enforcement),<br />
- existence of a load balancer setup,<br />
- the distance to the remote system and its uptime,<br />
- other guy&#8217;s network hookup (DSL, OC3, avian carriers) and his ISP.</p></blockquote>
<p>Setting p0f up on the sensor should have been straightforward;</p>
<ul>
<li>Install with: <em>apt-get install p0f</em></li>
<li>Run p0f as suggested in dionaea.conf: <em>sudo p0f -i any -u root -Q /tmp/p0f.sock -q -l</em></li>
<li>And edit dionaea.conf&#8217;s ihandler section to enable p0f</li>
</ul>
<p>This mostly worked, watching the p0f output it was correctly (I&#8217;m assuming) providing stats about connecting systems. The problem was that p0f info wasn&#8217;t getting saved into Dionaea&#8217;s logsqlite database, dionaea-error.log was reporting the below error with each connection:</p>
<blockquote><p>[04122010 13:48:44] connection connection.c:827-warning: Could not connect un:///tmp/p0f.sock:0 (Permission denied)</p></blockquote>
<p>Which seemed odd, /tmp/p0f.sock was showing as globally readable. Re-reading the Dionaea compilation instructions I noticed a comment about p0f struggling with IPv6 so has problems it Dionaea is listening on ::, which mine was. Problem solved, I edited dionaea.conf so that Listen mode was set to &#8220;manual&#8221;, and provided the interface/IP details of my network connection. Only this didn&#8217;t solve my problem&#8230;</p>
<p>Head thoroughly hurting I swallowed my ego and asked for assistance on the <a href="http://sourceforge.net/mailarchive/forum.php?thread_name=007701cb93c6$87bd02f0$973708d0$%40infosanity.co.uk&amp;forum_name=nepenthes-devel">mailing list</a>, and promptly (thanks again Ryan) got a <a href="http://sourceforge.net/mailarchive/message.php?msg_id=26699222">reply</a> that provided a functional workaround.</p>
<p>So, why go to the effort? Main purpose behind running honeypot systems (for me) is to get a better idea understanding of what threats are actively targeting systems in the wild. At first glance the information provided by p0f can quickly help evaluate the attacking system; what OS? what connection type? is it local?</p>
<p>With the limited (few hours) of data I&#8217;ve already collected heres a sample of the info you can gather:</p>
<p><strong>last 5 connections:</strong></p>
<table>
<tbody>
<tr>
<td>p0f</td>
<td>connection</td>
<td>p0f_genre</td>
<td>p0f_link</td>
<td>p0f_detail</td>
<td>p0f_uptime</td>
<td>p0f_tos</td>
<td>p0f_dist</td>
<td>p0f_nat</td>
<td>p0f_fw</td>
</tr>
<tr>
<td>328</td>
<td>822</td>
<td>Windows</td>
<td>IPv6/IPIP</td>
<td>2000 SP4, XP SP1+</td>
<td>-1</td>
<td></td>
<td>17</td>
<td>0</td>
<td>0</td>
</tr>
<tr>
<td>327</td>
<td>821</td>
<td>Windows</td>
<td>IPv6/IPIP</td>
<td>2000 SP4, XP SP1+</td>
<td>-1</td>
<td></td>
<td>17</td>
<td>0</td>
<td>0</td>
</tr>
<tr>
<td>326</td>
<td>820</td>
<td>Windows</td>
<td></td>
<td>2000 SP4, XP SP1+</td>
<td>-1</td>
<td></td>
<td>14</td>
<td>0</td>
<td>0</td>
</tr>
<tr>
<td>325</td>
<td>819</td>
<td>Windows</td>
<td></td>
<td>2000 SP4, XP SP1+</td>
<td>-1</td>
<td></td>
<td>14</td>
<td>0</td>
<td>0</td>
</tr>
<tr>
<td>324</td>
<td>818</td>
<td>Linux</td>
<td>pppoe (DSL)</td>
<td>2.4-2.6</td>
<td>5</td>
<td></td>
<td>13</td>
<td>0</td>
<td>0</td>
</tr>
</tbody>
</table>
<p>SQL Query:</p>
<blockquote><p>select *<br />
from p0fs<br />
order by<br />
connection desc<br />
limit 5;</p></blockquote>
<p><strong>Breakdown by OS</strong></p>
<table>
<tbody>
<tr>
<th>count</th>
<th>OS</th>
</tr>
<tr>
<td>324</td>
<td>Windows</td>
</tr>
<tr>
<td>24</td>
<td></td>
</tr>
<tr>
<td>17</td>
<td>Linux</td>
</tr>
</tbody>
</table>
<p>SQL Query:</p>
<blockquote><p>select count(p0f_genre) as count, p0f_genre as OS<br />
from p0fs<br />
group by p0f_genre<br />
order by count(p0f_genre) desc;</p></blockquote>
<p>Umm, so most systems spreading malware are (likely) infected Windows systems. No great surprise there&#8230;</p>
<p><strong>Connectivity Types</strong></p>
<table>
<tbody>
<tr>
<th>Count</th>
<th>Connectivity</th>
</tr>
<tr>
<td>153</td>
<td>IPv6/IPIP</td>
</tr>
<tr>
<td>149</td>
<td>ethernet/modem</td>
</tr>
<tr>
<td>40</td>
<td>pppoe (DSL)</td>
</tr>
<tr>
<td>21</td>
<td></td>
</tr>
<tr>
<td>12</td>
<td>(Google/AOL)</td>
</tr>
<tr>
<td>5</td>
<td>GPRS, T1, FreeS/WAN</td>
</tr>
<tr>
<td>3</td>
<td>PIX, SMC, sometimes wireless</td>
</tr>
<tr>
<td>2</td>
<td>sometimes DSL (2)</td>
</tr>
<tr>
<td>2</td>
<td>sometimes DSL (4)</td>
</tr>
</tbody>
</table>
<p>SQL Query:</p>
<blockquote><p>select count(p0f_link), p0f_link<br />
from p0fs<br />
group by p0f_link<br />
order by count(p0f_link) desc;</p></blockquote>
<p><strong>Summary</strong></p>
<p>Unfortunately the the information provided by p0f isn&#8217;t an exact science, and as devices and systems are constantly changing it&#8217;s only going to be as accurate as it&#8217;s latest signatures/fingerprints. But setup is fairly quick, and the information and insight provided fairly interesting. So why not give it a go?</p>
<p>&#8211;Andrew Waite</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/infosanity.wordpress.com/899/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/infosanity.wordpress.com/899/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/infosanity.wordpress.com/899/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/infosanity.wordpress.com/899/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/infosanity.wordpress.com/899/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/infosanity.wordpress.com/899/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/infosanity.wordpress.com/899/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/infosanity.wordpress.com/899/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/infosanity.wordpress.com/899/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/infosanity.wordpress.com/899/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/infosanity.wordpress.com/899/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/infosanity.wordpress.com/899/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/infosanity.wordpress.com/899/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/infosanity.wordpress.com/899/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.infosanity.co.uk&amp;blog=8614004&amp;post=899&amp;subd=infosanity&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.infosanity.co.uk/2010/12/04/dionaea-with-p0f/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/78c9d658d90cad982bfc9af08a2ff8dd?s=96&#38;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif&#38;r=G" medium="image">
			<media:title type="html">Infosanity</media:title>
		</media:content>
	</item>
		<item>
		<title>Introducing InfoSanity&#8217;s Dionaea Muscipula&#8230;</title>
		<link>http://blog.infosanity.co.uk/2010/12/04/introducing-infosanitys-dionaea-muscipula/</link>
		<comments>http://blog.infosanity.co.uk/2010/12/04/introducing-infosanitys-dionaea-muscipula/#comments</comments>
		<pubDate>Sat, 04 Dec 2010 13:18:16 +0000</pubDate>
		<dc:creator>Andrew Waite</dc:creator>
				<category><![CDATA[Dionaea]]></category>

		<guid isPermaLink="false">http://blog.infosanity.co.uk/?p=892</guid>
		<description><![CDATA[InfoSanity's new Dionaea Muscipula....<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.infosanity.co.uk&amp;blog=8614004&amp;post=892&amp;subd=infosanity&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://en.wikipedia.org/wiki/Venus_Flytrap"><img class="aligncenter size-full wp-image-893" title="Dionaea Muscipula" src="http://infosanity.files.wordpress.com/2010/12/2010-12-04-13-09-30.jpg?w=600&#038;h=450" alt="" width="600" height="450" /></a>&#8211;Andrew Waite</p>
<p>(p.s. sorry, couldn&#8217;t resist&#8230;)</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/infosanity.wordpress.com/892/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/infosanity.wordpress.com/892/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/infosanity.wordpress.com/892/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/infosanity.wordpress.com/892/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/infosanity.wordpress.com/892/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/infosanity.wordpress.com/892/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/infosanity.wordpress.com/892/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/infosanity.wordpress.com/892/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/infosanity.wordpress.com/892/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/infosanity.wordpress.com/892/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/infosanity.wordpress.com/892/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/infosanity.wordpress.com/892/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/infosanity.wordpress.com/892/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/infosanity.wordpress.com/892/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.infosanity.co.uk&amp;blog=8614004&amp;post=892&amp;subd=infosanity&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.infosanity.co.uk/2010/12/04/introducing-infosanitys-dionaea-muscipula/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/78c9d658d90cad982bfc9af08a2ff8dd?s=96&#38;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif&#38;r=G" medium="image">
			<media:title type="html">Infosanity</media:title>
		</media:content>

		<media:content url="http://infosanity.files.wordpress.com/2010/12/2010-12-04-13-09-30.jpg" medium="image">
			<media:title type="html">Dionaea Muscipula</media:title>
		</media:content>
	</item>
		<item>
		<title>Dionaea in the key of U(buntu)</title>
		<link>http://blog.infosanity.co.uk/2010/12/04/dionaea-in-the-key-of-ubuntu/</link>
		<comments>http://blog.infosanity.co.uk/2010/12/04/dionaea-in-the-key-of-ubuntu/#comments</comments>
		<pubDate>Sat, 04 Dec 2010 10:59:21 +0000</pubDate>
		<dc:creator>Andrew Waite</dc:creator>
				<category><![CDATA[Dionaea]]></category>
		<category><![CDATA[Honeypot]]></category>
		<category><![CDATA[Lab]]></category>

		<guid isPermaLink="false">http://blog.infosanity.co.uk/?p=886</guid>
		<description><![CDATA[arkus keeps adding great features and functionality to Dionaea, when I read the post introducing a new web interface carniwwwhore I couldn't help thinking I'd got lucky timing, start of a weeks vacation and no real plan for what to do with it. I've struggled previously with some of my Dionaea setups, largely because my system was running Debian, whilst Dionaea was built under Ubuntu; doesn't cause too many problems, just a bit of google-fu, headscratching and stupidity that could have been avoided. From this background I looked through the carniwwwhore pre-reqs with dread, plenty of version requirements that weren't upto date with my Debian setup; so it's time to bite the bullet and build a fresh system with Ubuntu.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.infosanity.co.uk&amp;blog=8614004&amp;post=886&amp;subd=infosanity&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Markus keeps adding great features and functionality to <a title="Dionaea - Carnivore.it" href="http://dionaea.carnivore.it">Dionaea</a>, when I read the post introducing a new web interface <a title="Carniwwwhore" href="http://carnivore.it/2010/11/27/carniwwwhore">carniwwwhore</a> I couldn&#8217;t help thinking I&#8217;d got lucky timing, start of a week&#8217;s vacation and no real plan for what to do with it. I&#8217;ve struggled previously with some of my Dionaea setups, largely because my system was running Debian, whilst Dionaea was built under Ubuntu; doesn&#8217;t cause too many problems, just a bit of google-fu, headscratching and stupidity that could have been avoided.</p>
<p>From this background I looked through the carniwwwhore pre-reqs with dread, plenty of version requirements that weren&#8217;t upto date with my Debian setup; so it&#8217;s time to bite the bullet and build a fresh system with Ubuntu. Unlike some of my previous setups, installation/compilation worked flawless, working on the same distro as the lead dev definitely makes life easier. If you&#8217;re looking for a fresh Dionaea installation, go with Ubuntu, you won&#8217;t regret it.</p>
<p>&#8211;Andrew Waite</p>
<p>(oh, and carniwwwhore? Vacation got the better of me so it&#8217;s added to the to-do list; watch this space&#8230;)</p>
<p>&nbsp;</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/infosanity.wordpress.com/886/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/infosanity.wordpress.com/886/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/infosanity.wordpress.com/886/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/infosanity.wordpress.com/886/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/infosanity.wordpress.com/886/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/infosanity.wordpress.com/886/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/infosanity.wordpress.com/886/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/infosanity.wordpress.com/886/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/infosanity.wordpress.com/886/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/infosanity.wordpress.com/886/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/infosanity.wordpress.com/886/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/infosanity.wordpress.com/886/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/infosanity.wordpress.com/886/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/infosanity.wordpress.com/886/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.infosanity.co.uk&amp;blog=8614004&amp;post=886&amp;subd=infosanity&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.infosanity.co.uk/2010/12/04/dionaea-in-the-key-of-ubuntu/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/78c9d658d90cad982bfc9af08a2ff8dd?s=96&#38;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif&#38;r=G" medium="image">
			<media:title type="html">Infosanity</media:title>
		</media:content>
	</item>
		<item>
		<title>SSH hardening with Breakinguard</title>
		<link>http://blog.infosanity.co.uk/2010/10/21/ssh-hardening-with-breakinguard/</link>
		<comments>http://blog.infosanity.co.uk/2010/10/21/ssh-hardening-with-breakinguard/#comments</comments>
		<pubDate>Thu, 21 Oct 2010 20:13:30 +0000</pubDate>
		<dc:creator>Andrew Waite</dc:creator>
				<category><![CDATA[Honeypot]]></category>
		<category><![CDATA[InfoSec]]></category>
		<category><![CDATA[Kippo]]></category>

		<guid isPermaLink="false">http://blog.infosanity.co.uk/?p=822</guid>
		<description><![CDATA[Attacks against SSH services are regularly seen in the wild. Even if you follow best practices for securing the service, the malicious scans will utilise resources available to your environment; CPU, bandwidth etc. In sufficient volume legitimate operation may be impacted as the server rejects failed login attempts.
This is where utilities like Breakinguard come into their own. Basically Breakinguard monitors log files for signs of malicious activity, and once a single source has triggered enough alerts blocks all connections from the source location.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.infosanity.co.uk&amp;blog=8614004&amp;post=822&amp;subd=infosanity&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>As proven by the logs generated by <a title="[IS] - Kippo Stats" href="http://blog.infosanity.co.uk/2010/07/21/initial-kippo-honeypot-stats/">Kippo honeypot</a> sensors have shown, attacks against SSH services are regularly seen in the wild. Even if you follow <a title="[IS] - Basic SSH Hardening" href="http://blog.infosanity.co.uk/2010/07/24/basic-ssh-server-hardening/">best practices</a> for securing the service, the malicious scans will utilise resources available to your environment; CPU, bandwidth etc. In sufficient volume legitimate operation may be impacted as the server rejects failed login attempts.</p>
<p>This is where utilities like <a title="Breakinguard - About" href="http://breakinguard.sourceforge.net/about.html">Breakinguard</a> come into their own. Basically Breakinguard monitors log files for signs of malicious activity, and once a single source has triggered enough alerts blocks all connections from the source location. Other utilities (most notably <a title="fail2ban" href="http://www.fail2ban.org/wiki/index.php/Main_Page">fail2ban</a>) perform the same activities, but I&#8217;m partial to Breakinguard due to it&#8217;s small size and simple configuration (and from knowing the author <img src='http://s1.wp.com/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' />  ).</p>
<p>Installation is straightforward, and for the most part automated. Once downloaded and extracted installation is handled by the configure script. On Debian based systems this will install the pre-requisite Perl modules and transfer the utilities components to the standard locations:</p>
<ul>
<li>breakinguard script &#8211; /usr/local/sbin/breakinguard</li>
<li>config &#8211; /etc/breakinguard.conf</li>
<li>init script &#8211; /etc/init.d/breakinguard</li>
</ul>
<p>Once installed you need to edit your configuration. The breakinguard.conf file is fairly self explanatory, I normally edit:</p>
<ul>
<li>$alert_email -&gt; set to the email address that you want to receive notifications of blocked attacks. On a publicly accessible system these alerts can be high volume, you may want to use a specific email account or at least setup some auto-move rules in your email client to avoid your inbox being spammed.</li>
<li>$number_of_attempts -&gt; This specifies the number of malicious log entries need to be generated by a specific IP address before the source is blocked. Due to the timing of the Breakinguard route this isn&#8217;t always an exact science, the default of 5 does a good job of avoid false positives whilst still blocking an attack in it&#8217;s infancy.</li>
<li>$log_to_watch -&gt; selects the logfile to monitor for signs of malicious activity. /var/log/auth.log is the obvious choice on a Debian based system.</li>
<li>@safe_ips -&gt; This array allows you to specify a number of trusted networks that will not be blocked, regardless of the number of times the they trigger alerts in the logs. This is useful for insuring that you don&#8217;t get locked out of your own systems in the event your keyboard &#8216;breaks&#8217;. On higher end systems with hardware remote management systems (iLo, DRAC, etc.) or virtual systems that provide remote access to the &#8216;physical&#8217; console I leave this list to local subnet only and use the alternative options to access the server if I do lock myself out.</li>
<li>$DEBUG -&gt; set to 1 by default, this runs the utility in test mode without actually blocking malicious sources, perfect for testing configuration before going live. Once you&#8217;re good to set set $DEBUG to 0 and wait for the attacks to start. Example testing in debug mode is below:</li>
</ul>
<div id="attachment_861" class="wp-caption aligncenter" style="width: 610px"><a href="http://infosanity.files.wordpress.com/2010/10/breakinguard-debugmode.png"><img class="size-full wp-image-861" title="Breakinguard-DebugMode" src="http://infosanity.files.wordpress.com/2010/10/breakinguard-debugmode.png?w=600&#038;h=174" alt="Breakinguard - Debug Mode" width="600" height="174" /></a><p class="wp-caption-text">Breakinguard - Debug Mode</p></div>
<p>Blocking and unblocking of malicious sources is handled via iptables. Once the $number_of_attempts limit is hit Breakinguard will run the $block_command (configurable in /etc/breakinguard.conf) which by default is &#8216;/sbin/iptables -I INPUT -s %s -j DROP&#8217;, with %s being replaced with the attacking IP. After a configurable timeout ($block_length), the $unblock_command removes the restriction.</p>
<p>You can see the IP addresses currently blocked as they are listed in /var/run/breakinguard/, alternatively listing the current iptables configuration will show sources currently being blocked, for example:</p>
<div id="attachment_863" class="wp-caption aligncenter" style="width: 610px"><a href="http://infosanity.files.wordpress.com/2010/10/breakinguard-iptables.png"><img class="size-full wp-image-863" title="Breakinguard-iptables" src="http://infosanity.files.wordpress.com/2010/10/breakinguard-iptables.png?w=600&#038;h=145" alt="Breakinguard iptables" width="600" height="145" /></a><p class="wp-caption-text">Breakinguard iptables</p></div>
<p>Download Breakinguard <a title="Breakinguard - Sourceforge Download" href="http://sourceforge.net/projects/breakinguard/files/">here</a></p>
<p>&#8211;Andrew Waite</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/infosanity.wordpress.com/822/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/infosanity.wordpress.com/822/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/infosanity.wordpress.com/822/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/infosanity.wordpress.com/822/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/infosanity.wordpress.com/822/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/infosanity.wordpress.com/822/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/infosanity.wordpress.com/822/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/infosanity.wordpress.com/822/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/infosanity.wordpress.com/822/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/infosanity.wordpress.com/822/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/infosanity.wordpress.com/822/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/infosanity.wordpress.com/822/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/infosanity.wordpress.com/822/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/infosanity.wordpress.com/822/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.infosanity.co.uk&amp;blog=8614004&amp;post=822&amp;subd=infosanity&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.infosanity.co.uk/2010/10/21/ssh-hardening-with-breakinguard/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/78c9d658d90cad982bfc9af08a2ff8dd?s=96&#38;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif&#38;r=G" medium="image">
			<media:title type="html">Infosanity</media:title>
		</media:content>

		<media:content url="http://infosanity.files.wordpress.com/2010/10/breakinguard-debugmode.png" medium="image">
			<media:title type="html">Breakinguard-DebugMode</media:title>
		</media:content>

		<media:content url="http://infosanity.files.wordpress.com/2010/10/breakinguard-iptables.png" medium="image">
			<media:title type="html">Breakinguard-iptables</media:title>
		</media:content>
	</item>
	</channel>
</rss>
