ENG ITA

# Ethical Hacker & ICT Security Specialist

Honeypot

In informatica, una honeypot (letteralmente: "barattolo di miele") è un sistema o componente hardware/software usato come esca al fine di studiare ed analizzare gli attacchi informatici in tempo reale.

Solitamente consiste in uno o più siti o servizi che sembrano essere parte della rete e che contengono informazioni preziose per un attaccante, ma che in realtà sono ben isolati e non contegono dati reali, ma forniscono a chi li amministra tutti i dettagli degli attacchi informatici subiti.

Il valore primario di una honeypot è quindi l'informazione che essa dà sulla natura e la frequenza di eventuali attacchi subiti.

Se sei curioso di scoprire questo mondo, guarda le statistiche degli attacchi in tempo reale che ora dopo ora vengono rilevati dalla mia rete di honeypot:

Dizionari live

E' possibile scaricare dizionari di password, nomi utente e coppie user/pass estrapolati dagli attacchi verso il servizio SSH:

Tutte le statistiche della honeypot di seguito:

SSH

×
Last 50 commands executed
DateCommandSource
2018-09-24 23:13:54cat /proc/cpuinfo36.233.25.233 Taiwan
2018-09-24 23:13:49ps -x36.233.25.233 Taiwan
2018-09-24 23:13:44free -m36.233.25.233 Taiwan
2018-09-24 23:13:39uname36.233.25.233 Taiwan
2018-09-24 23:13:34unset HISTORY HISTFILE HISTSAVE HISTZONE HISTORY HISTLOG WATCH ; history -n ; export HISTFILE=/dev/null ; export HISTSIZE=0; export HISTFILESIZE=0 ; rm -rf /var/log/wtmp ; rm -rf /var/log/lastlog ; rm -rf /var/log/secure ; rm -rf /var/log/xferlog ; rm -rf /var/log/messages ; rm -rf /var/run/utmp ; touch /var/run/utmp ; touch /var/log/messages ; touch /var/log/wtmp ; touch /var/log/messages ; touch /var/log/xferlog ; touch /var/log/secure ; touch /var/log/lastlog ; rm -rf /var/log/maillog ; touch /var/log/maillog ; rm -rf /root/.bash_history ; touch /root/.bash_history ; history -r 36.233.25.233 Taiwan
2018-09-24 22:57:28uname -a113.119.196.164 China
2018-09-24 22:51:12cat /proc/cpuinfo122.166.191.100 India
2018-09-24 22:51:07ps -x122.166.191.100 India
2018-09-24 22:51:02free -m122.166.191.100 India
2018-09-24 22:50:57uname122.166.191.100 India
2018-09-24 22:50:52unset HISTORY HISTFILE HISTSAVE HISTZONE HISTORY HISTLOG WATCH ; history -n ; export HISTFILE=/dev/null ; export HISTSIZE=0; export HISTFILESIZE=0 ; rm -rf /var/log/wtmp ; rm -rf /var/log/lastlog ; rm -rf /var/log/secure ; rm -rf /var/log/xferlog ; rm -rf /var/log/messages ; rm -rf /var/run/utmp ; touch /var/run/utmp ; touch /var/log/messages ; touch /var/log/wtmp ; touch /var/log/messages ; touch /var/log/xferlog ; touch /var/log/secure ; touch /var/log/lastlog ; rm -rf /var/log/maillog ; touch /var/log/maillog ; rm -rf /root/.bash_history ; touch /root/.bash_history ; history -r 122.166.191.100 India
2018-09-24 22:04:45cat /proc/cpuinfo117.73.2.84 China
2018-09-24 22:04:39ps -x117.73.2.84 China
2018-09-24 22:04:35free -m117.73.2.84 China
2018-09-24 22:04:30uname117.73.2.84 China
2018-09-24 22:04:25unset HISTORY HISTFILE HISTSAVE HISTZONE HISTORY HISTLOG WATCH ; history -n ; export HISTFILE=/dev/null ; export HISTSIZE=0; export HISTFILESIZE=0 ; rm -rf /var/log/wtmp ; rm -rf /var/log/lastlog ; rm -rf /var/log/secure ; rm -rf /var/log/xferlog ; rm -rf /var/log/messages ; rm -rf /var/run/utmp ; touch /var/run/utmp ; touch /var/log/messages ; touch /var/log/wtmp ; touch /var/log/messages ; touch /var/log/xferlog ; touch /var/log/secure ; touch /var/log/lastlog ; rm -rf /var/log/maillog ; touch /var/log/maillog ; rm -rf /root/.bash_history ; touch /root/.bash_history ; history -r 117.73.2.84 China
2018-09-24 21:41:10free -m122.116.157.53 Taiwan
2018-09-24 21:41:03cat /proc/cpuinfo122.116.157.53 Taiwan
2018-09-24 21:40:57ps -x122.116.157.53 Taiwan
2018-09-24 21:40:52uname122.116.157.53 Taiwan
2018-09-24 21:40:47unset HISTORY HISTFILE HISTSAVE HISTZONE HISTORY HISTLOG WATCH ; history -n ; export HISTFILE=/dev/null ; export HISTSIZE=0; export HISTFILESIZE=0;122.116.157.53 Taiwan
2018-09-24 19:06:39uname -a91.134.140.32 France
2018-09-24 18:23:16uname -a36.67.59.193 Indonesia
2018-09-24 18:14:15uname -a36.67.59.193 Indonesia
2018-09-24 18:07:15free -m119.90.39.158 China
2018-09-24 18:07:08cat /proc/cpuinfo119.90.39.158 China
2018-09-24 18:07:02ps -x119.90.39.158 China
2018-09-24 18:06:58uname119.90.39.158 China
2018-09-24 18:06:52unset HISTORY HISTFILE HISTSAVE HISTZONE HISTORY HISTLOG WATCH ; history -n ; export HISTFILE=/dev/null ; export HISTSIZE=0; export HISTFILESIZE=0;119.90.39.158 China
2018-09-24 17:37:22uname -a35.237.134.53 United States
2018-09-24 17:35:48free -m162.243.161.158 United States
2018-09-24 17:35:43free -m162.243.161.158 United States
2018-09-24 17:35:39cat /proc/cpuinfo162.243.161.158 United States
2018-09-24 17:35:34cat /proc/cpuinfo162.243.161.158 United States
2018-09-24 17:35:30ps -x162.243.161.158 United States
2018-09-24 17:35:25uname162.243.161.158 United States
2018-09-24 17:35:21ps -x162.243.161.158 United States
2018-09-24 17:35:16unset HISTORY HISTFILE HISTSAVE HISTZONE HISTORY HISTLOG WATCH ; history -n ; export HISTFILE=/dev/null ; export HISTSIZE=0; export HISTFILESIZE=0;162.243.161.158 United States
2018-09-24 17:35:12uname162.243.161.158 United States
2018-09-24 17:35:07unset HISTORY HISTFILE HISTSAVE HISTZONE HISTORY HISTLOG WATCH ; history -n ; export HISTFILE=/dev/null ; export HISTSIZE=0; export HISTFILESIZE=0;162.243.161.158 United States
2018-09-24 16:34:59uname -a78.128.113.160 Bulgaria
2018-09-24 16:31:58uname -a78.128.113.160 Bulgaria
2018-09-24 13:17:01uname -a67.169.149.151 United States
2018-09-24 12:19:33uname -a115.220.4.77 China
2018-09-24 11:38:35free -m89.120.94.226 Romania
2018-09-24 11:38:30cat /proc/cpuinfo89.120.94.226 Romania
2018-09-24 11:38:24ps -x89.120.94.226 Romania
2018-09-24 11:38:20uname89.120.94.226 Romania
2018-09-24 11:38:16unset HISTORY HISTFILE HISTSAVE HISTZONE HISTORY HISTLOG WATCH ; history -n ; export HISTFILE=/dev/null ; export HISTSIZE=0; export HISTFILESIZE=0;89.120.94.226 Romania
2018-09-24 11:15:29uname -a119.29.98.253 China
×
Last 20 sessions
DateSource
2018-09-24 23:25:07185.66.213.64 Poland
2018-09-24 23:23:42110.141.243.23 Australia
2018-09-24 23:22:385.101.40.149 Russian Federation
2018-09-24 23:18:348.31.198.201 United States
2018-09-24 23:16:16197.50.149.156 Egypt
2018-09-24 23:16:06190.7.154.106 Colombia
2018-09-24 23:15:42173.208.192.22 United States
2018-09-24 23:15:16150.138.183.254 China
2018-09-24 23:13:2536.233.25.233 Taiwan
2018-09-24 23:11:375.101.40.149 Russian Federation
2018-09-24 23:02:40174.117.122.135 Canada
2018-09-24 23:01:10113.119.196.164 China
2018-09-24 23:00:305.101.40.172 Russian Federation
2018-09-24 22:59:47150.138.183.254 China
2018-09-24 22:59:16185.219.132.24 Turkey
2018-09-24 22:57:21113.119.196.164 China
2018-09-24 22:50:44122.166.191.100 India
2018-09-24 22:49:325.101.40.172 Russian Federation
2018-09-24 22:47:40195.201.125.202 Germany
2018-09-24 22:44:17192.187.103.3 United States
×
TOP 15 USER+PASS
CountUsernamePassword
9818 adminadmin123
984 admin
856 adminaerohive
619 ubntubnt
144 adminadmin
110 useruser
99 rootroot
87 rootadmin
60 piraspberry
60 supportsupport
57 piraspberryraspberry993311
54 rootlive
45 12341234
43 adminadmin01
42 0
×
TOP 20 SUCCESSFUL LOGIN IPs
CountSource
1060195.3.147.49 Latvia
555193.201.224.206 Ukraine
16745.225.35.253 Brazil
141159.203.36.38 Canada
1345.188.10.76 Croatia
10254.37.235.210 Poland
80109.236.91.85 Netherlands
79117.4.114.178 Vietnam
6013.58.243.139 United States
5962.244.196.50 Turkey
57204.12.206.98 United States
555.188.87.52 Russian Federation
555.188.87.51 Russian Federation
38192.96.15.40 South Africa
36117.4.0.186 Vietnam
36167.114.210.108 Canada
35153.120.82.247 Japan
335.188.86.211 Ireland
295.196.76.41 France
2938.84.132.236 United States
×
TOP 20 attackers
ConnectionsSource
18245.101.40.150 Russian Federation
140154.175.87.142 United States
1174182.61.56.5 China
11375.101.40.172 Russian Federation
1113195.3.147.49 Latvia
1064111.231.66.173 China
957171.231.51.180 Vietnam
953146.0.77.128 Netherlands
913146.0.77.173 Netherlands
8975.101.40.149 Russian Federation
8315.101.40.100 Russian Federation
8305.101.40.106 Russian Federation
7185.101.40.159 Russian Federation
641146.0.77.174 Netherlands
62654.37.235.210 Poland
61545.225.35.253 Brazil
578193.201.224.206 Ukraine
522192.187.103.6 United States
520173.208.192.22 United States
507192.187.103.4 United States

Se vuoi guardare il codice che genera questa pagina, vai al sito del mio progetto HoneyStats! (github)

Vuoi ancora di più? Seguimi all'interno del laboratorio!