Kippo: Unterschied zwischen den Versionen

Aus Xinux Wiki
Zur Navigation springen Zur Suche springen
Zeile 34: Zeile 34:
 
=start=
 
=start=
 
*./start.sh
 
*./start.sh
 +
=netstat=
 +
*netstat -lntp
 +
tcp 0 0 0.0.0.0:22 0.0.0.0:* LISTEN 22627/python
  
 
 
tcp 0 0 0.0.0.0:22 0.0.0.0:* LISTEN 22627/python
 
 
=Links=
 
=Links=
 
*https://bruteforce.gr/installing-kippo-ssh-honeypot-on-ubuntu.html
 
*https://bruteforce.gr/installing-kippo-ssh-honeypot-on-ubuntu.html
 
*https://thelosingedgeblog.wordpress.com/2016/02/15/kippo-kali-pi/
 
*https://thelosingedgeblog.wordpress.com/2016/02/15/kippo-kali-pi/

Version vom 27. August 2016, 15:52 Uhr

Before we begin

Change standard ssh Port =Install some packets

  • apt-get install python-dev openssl python-openssl python-pyasn1 python-twisted git authbind

Adduser and change visudo that kippo can list users

  • adduser kippo
  • visudo

add

kippo ALL=(ALL:ALL) ALL

under the “root” user. =create fil and change some rights?

  • touch /etc/authbind/byport/22
  • chown kippo:kippo /etc/authbind/byport/22
  • chmod 777 /etc/authbind/byport/22

We have to install an older version of Python Twisted

manually because of issues with the current version of Twisted and Kippo. I can’t recall the error at the moment, but I’ll see if I can find it in the logs later.

At this point we enter the system as ‘kippo’ user and go to the /home directory.

  • sudo - kippo

Download the latest Kippo version from GitHub

change port

  • cd kippo
  • sed -e "/ssh_port =/s/2222/22/" kippo.cfg.dist > kippo.cfg

Finally, change the Kippo start script

  • sed -i.bak -e "/kippo.tac/s/twistd/authbind --deep &/" start.sh

start

  • ./start.sh

netstat

  • netstat -lntp
tcp 0 0 0.0.0.0:22 0.0.0.0:* LISTEN 22627/python

Links