DaemonForums  

Go Back   DaemonForums > OpenBSD > OpenBSD Packages and Ports

OpenBSD Packages and Ports Installation and upgrading of packages and ports on OpenBSD.

Reply
 
Thread Tools Display Modes
  #1   (View Single Post)  
Old 10th February 2016
e1-531g e1-531g is offline
ISO Quartermaster
 
Join Date: Mar 2014
Posts: 628
Default Honeypot : Which package lets me imitate OpenSSH?

Hello,
I would like to imitate a few services on a few ports
for outside world. If one connects to lets say 22 TCP
port I would like him to not connect to real OpenSSH,
still make him thinking that he connects to real OpenSSH
and only need to guess valid password.
Maybe even imitate Windows services. Based on that
I would like to block IP and log that.
The part with pf to block IP I am able to do,
but I don't know if there exists something like that in ports,
which lets me imitate various popular services.
Reply With Quote
  #2   (View Single Post)  
Old 10th February 2016
jggimi's Avatar
jggimi jggimi is offline
More noise than signal
 
Join Date: May 2008
Location: USA
Posts: 7,983
Default

You'll find net/honeyd in packages. The Honeyd project website has an example configuration that includes a simulated ssh.

Disclaimer: I've never used this tool, and can't comment on its use/function/safety/security.
Reply With Quote
  #3   (View Single Post)  
Old 10th February 2016
hanzer's Avatar
hanzer hanzer is offline
Real Name: Adam Jensen
just passing through
 
Join Date: Oct 2013
Location: EST USA
Posts: 314
Thumbs up

Quote:
Originally Posted by jggimi View Post
You'll find net/honeyd in packages. The Honeyd project website has an example configuration that includes a simulated ssh.

Disclaimer: I've never used this tool, and can't comment on its use/function/safety/security.
Nice reference, Thanks!

There is an interesting Military/Cyberwar perspective/presentation on that technology/technique at: "Confessions of a Cyber Spy Hunter: Eric Winsborrow at TEDxVancouver", [specifically] about time - 16:40 - but the entire talk is worth watching, IMHO
Reply With Quote
  #4   (View Single Post)  
Old 11th February 2016
hanzer's Avatar
hanzer hanzer is offline
Real Name: Adam Jensen
just passing through
 
Join Date: Oct 2013
Location: EST USA
Posts: 314
Default

Here's a talk given by Lance Spitzner, the founder of the Honeynet Project: "HNW2015 - Lance Spitzner - The Honeynet Project: Then and Now". I had to stop watching at 6:00.
Reply With Quote
Reply

Tags
honeypot, pf, port trap


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
OpenSSH 7.0 has been released. e1-531g News 0 11th August 2015 08:03 PM
Backdoor in wireless DSL routers lets attacker reset router, get admin J65nko News 3 6th January 2014 12:30 AM
Google Lets You Manage Your Digital Life From Beyond the Grave Beastie News 1 16th April 2013 10:30 PM
Xen lets KVM overtake J65nko News 0 23rd June 2011 06:18 AM
OpenSSH 5.4 Release J65nko News 0 9th March 2010 08:48 PM


All times are GMT. The time now is 07:33 PM.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
Content copyright © 2007-2010, the authors
Daemon image copyright ©1988, Marshall Kirk McKusick