It's secure, they can't break out of the jail.
It's rate limited to prevent them causing much damage to anyone.
It's easy to observe every thing they type and do in the jail from the host.
It's secure, they can't break out of the jail.
It's rate limited to prevent them causing much damage to anyone.
It's easy to observe every thing they type and do in the jail from the host.
security.bsd.see_other_gids
security.bsd.see_other_uids
The above are the two sysctl's you want to enable.
A simple ps will show you all the shells that are in a jail.
Tue 19 7:19PM priyanka.setecastronomy ~> ps -x
PID TT STAT TIME COMMAND
30308 - S 0:00.05 sshd: oracle@pts/0 (sshd)
Now you have the tty he/she is on (pts/0). There are many ways to get that including ps so use whatever method you prefer to get the tty.
Fire up watch to snoop on the tty.
Tue 19 7:48PM priyanka.setecastronomy ~> doas watch pts/0
And boom, you can watch the ankle biter do his/her thing.
You can do this on the host as described, because that is how pam_jail works. But if you prefer for some reason to make an actual jail with VNET etc and do this simply forward ssh on the host to the jail's IP. If you do rate limiting you will already be configuring pf or ipfw anyway so an extra line to forward 22 to the jail host is not big deal.
Yeah this is a crappy write-up but it's spur of the moment and in a HN reply post so it's worth the price paid.
I'm happy to answer questions or help you if you get stuck anyway I can just message me. It's pretty simple to do.
If this is in a corporate setting I would consult with legal before doing this. The world is a whacky place these days, and if the ankle biter does something evil from your honeypot jail you may be liable.
I would sit there and watch that.
Oh, look honey, this one's trying to use GNU options! Here's one who thinks he's on Ubuntu! Wow, I didn't know VIM could do _that_!
Love those references. If you have not seen it yet go watch Sneakers (1992). I am getting old - I remember when it was fresh :-)
* Download a large file (e.g. XP SP3) from Microsofts servers to test bandwidth * Download IP scanners and trying to run them (in order to find new hosts to attack) * Download botnet code that connects to some C2 server
Tools they download were often downloaded as source, which they then tried to compile in order to run it.
Searching for e.g. 'youtube kippo' will get you videos of honeypot sessions.