Configuring a High Interactivity SSH HoneyPot
robertputt.co.uk
robertputt.co.uk
The problem with honeypots is that they generally only attract very generic attacks, so they are only interesting for people who want to research the current attack landscape.
Targeted attacks only go for valuable resources, so you'd have to make your honeypot looks valuable.
So if you have an SSH honeypot inside your network, use 'git' or 'scm' or so as part of the hostname, and hope that people will think they can find source code there.
By putting a honeypot inside your network, you tune out the noise of generic, automated attacks. So you get a much higher signal/noise ratio.
We managed to get close to that, but we didn't get the session keys part :(
I've often thought about doing this, but it seems like a wildly bad idea for someone like me who doesn't work in the field.
Anyone here who isn't a security expert tried this? How did it go?
Disclaimer: I am a wanna-be security hobbiest, at best.
You have nothing to lose. But please don't start mindlessly executing the various payloads people/bots will leave at this box.
Beacuse life thought me to never think that you are smarter than others.
This got me thinking about setting all my hostnames to "honeypot" and randomly printing fake HonSSH logs in all SSH connections.
Security by... mimicking?
If an attack is automated (where it may not consider the hostname at all) it will have no effect.
If it is a targeted attack, the attacker will most likely be well versed in the behaviour of default honeypots. As such if you're machine behaves differently (as it almost always will) the attacker will not be deterred. One example of this includes response time of a failed SSH login -- a HP might reply sub-seconds faster than a real system (especially true in industrial environments).