8 ms·
Cowrie: a medium-interaction SSH and Telnet honeypot
- iforgotpassword 7y agoI want to give this a try. Years ago I stumbled upon a similar project written in python which I don't remember the name of, but something about its handshake must have been fishy as most clients disconnected again right away without trying to authenticate. (The initial version string sent by the server looked fine but I wasn't motivated enough to dig any further.)
- spydum 7y agoYou might be thinking of kippo? Honeypots are fun to think about and toy with - I just never have any idea what to do with the logs and data?
- mnky9800n 7y agoWrite a report or paper or blog or something about it I guess.
- achillean 7y agoThe major use case for them nowadays is to help filter out the noise in your alerts. See for example a company such as GreyNoise (https://www.greynoise.io https://www.greynoise.io) to help companies focus on real attacks and not just background noise/ automated attacks.
- yjftsjthsd-h 7y agoAlternatively, run on your internal network and alert on every attempt....
- iforgotpassword 7y agoYes that's the one! Toying around was exactly my plan. See if any interesting sessions show up. I have a couple ideas like trying to automatically group or classify them but there are way too many things on my "would be cool to try" todo list already..
- bediger4000 7y agoI believe kippo is the ancestor of Cowrie.
- tastroder 7y agoThat's likely an artifact of the client side I'd think. While not most of them, a significant portion of clients exhibited similar behaviour on mine. Disconnects before the handshake were quite common (due to simple port scanning), others seemed to perform the handshake for discovery without actually completing/attempting a login. I've chalked that up to things looking for vulnerable server versions (e.g. home routers). About the only interesting thing I've seen on mine was login attempts using a single compromised key instead of the old brigade of admin/admin password attempts. Although I guess that might just be some known backdoor of some popular network equipment that I was not aware of at the time.
- segfaultbuserr 7y ago> records the interactions of hackers Before you get too excited, I would say that a common mistake of inexperienced sysadmins is assuming all those brute-force attempts in the logs are results of those "hackers" and "crackers", it's not, not even a scriptkid. All you can get by running a honeypot, like this one, is pretty boring activities by soulless, ancient worms and viruses, or automatic global Internet scanners running 24x7, not humans. Most of those are not even worth your time to block (e.g. if you only use strong password or pubkey, there are few reasons to fail2ban). It's nothing personal. Any machine will be port scanned, vuln probed, brute forced, blindly hit with ancient "1 shot" exploits (e.g. ?file=../../../etc/passwd ). This is how the Internet works. Another lesson is: never run any unsecured webserver/service on the public Internet, never ever, not even for debugging, period. Don't listen 0.0.0.0:80 if you have just installed your PHP management system, don't reset your forgotten MySQL password by disabling privilege checking before turning off networking first, if you just installed a new VPS with root password 123456 in a morning, don't wait until afternoon, change it immediately, etc. The reason is exact the opposite, not because of "hackers" but those stupid worms. Ordinary life is boring: if you run a webserver with password 123456 (e.g. for debugging an issue on a disposable server - just for 20 minutes, you think, then you forgot it), you won't (or unlikely) to see someone hacking into your system, but it's a certainty that one of those stupid worms/viruses would infect your machine within hours, sometimes it's as quick as having your lunch. And it probably won't do much damage, but you would spend your time to reinstall the system again...
- mergy 7y agoIndeed. After running this for a few weeks, most of the playbacks where a couple of seconds and consisted of a script that, once it obtained access, would just try and pull down payload sitting on a vulnerable host (in my case on the OVH Euro ISP) and then try to trigger a cron setup and exec in stealth mode on linux. Rarely did I ever get an interactive shell show someone trying to move through the process. When I did, it was fun to watch. I would say automated 1-2 sec script attacks outnumbered human logins 1000 to 1.
- segfaultbuserr 7y ago
- mergy 7y agoCaution for folks: I ran this for a few weeks and it was very informative. You see how simple many attacks really are, how many corporate assets are comprimised, and where most of the source attacking countries are. But, there is a downside. The downside is any site you put it on will be flagged and attacked 100x more since it registers as a vulnerable destination. After turning it off, the deluge of attacks for the site continues and I ended-up rigging a fail2ban setup to just deny if a destination port is hit. (See >> https://mergy.org/2019/08/setting-up-a-killswitch-for-attacks-with-ufw-and-fail2ban-on-ubuntu-linux/ https://mergy.org/2019/08/setting-up-a-killswitch-for-attack...) But, it is fun and interesting to see. Highly recommend but know the legacy on that as well.
- gchamonlive 7y agoYou should not put this alongside your site, at least not sharing resources. You should apply forwarding rules to separate this into a different vlan or vpc (ip based routing for instance) and completely isolate this from your site, while the two ssh destinations would be indistinguishable from the outside, preferably behind a load balancer with a firewall to mitigate ddos attacks and just log different attack types
- mergy 7y agoHere is what a playmaker session looks like if you are interested https://vimeo.com/345068825/86f8c8f97e https://vimeo.com/345068825/86f8c8f97e
- LinuxBender 7y agoAgreed, it's mostly old bots trying to take over wordpress sites and serve malware. That's about it. For a while, I gathered attempted usernames. I created accounts for all the usernames, set a null password on my chroot sftp server. I was really hoping they would try to upload something interesting. Nope. If they can't get a standard shell, they just keep retrying in a loop, forever. I've had the same bots hitting my server every few minutes for several years. No harm, no foul, I let them have at it.
- rob2996 7y agofascinating
- CliffStoll 7y agoWish that this were available 33 years ago...
- HocusLocus 7y agoMr. Cuckoo's Egg, I presume? Well met!!! I really enjoyed your sleuthing tale in the age of modemy Compuserve and Telenet-with-an-e ... which I also did some exploring on. The telephone NPA plus a couple digits was an explorer's dream. Hope you are doing well in this whacky 21st century.
- veddox 7y agoWell, I daresay you created your own :-D A bit more complex than this one, too... Didn‘t know you visit HN - I‘m a great fan of your book!
- cordite 7y agoany examples of replay logs on asciinema or even youtube? Just curious about what these look like
- mergy 7y agoI played back a friend banging on my cowrie setup a while back. Here you go. https://vimeo.com/345068825/86f8c8f97e https://vimeo.com/345068825/86f8c8f97e
- HocusLocus 7y agoI opened up port 23 telnet and had it connect immediately to a playable Crowther & Woods' original adventure, YOU ARE STANDING AT THE END OF A ROAD BEFORE A SMALL BRICK BUILDING. AROUND YOU IS A FOREST. A SMALL STREAM FLOWS OUT OF THE BUILDING AND DOWN A GULLY. In a year and a half I had logged over a million probes. No humans at all. I would have known because they would have typed something to do with the game or tried to play it. So I must conclude no one is checking the logs of the worms either.
- j88439h84 7y agoThat's a really interesting idea for a test, thanks for sharing that.
- HocusLocus 7y agoYes it was fun to do, though disappointing in the end. To help throttle attacks and give the right historical ambiance I limited output to 30 characters per second... just like I first played the Fortran 77 version of C&W Adventure on a Texas Instruments Silent 700 with acoustic coupler.
- CliffStoll 7y agoWow -- you've impressed me! (and yep, I also played adventure on a Silent 700...)
- HocusLocus 7y agoKeep the roll all together on the ground and feed the thermal paper in again to print upside-down on the other margin! Good times. Saw your old calculator video with the 'sonic spiral memory'. I had NO IDEA such a thing existed! There is great value in the doggedly determined engineering of yesteryear, and there are some among the young who continue to carry the torch. Check this out if you have not seen it, Apollo Guidance Computer Restoration https://www.youtube.com/playlist?list=PL-_93BVApb59FWrLZfdlisi_x7-Ut_-w7 https://www.youtube.com/playlist?list=PL-_93BVApb59FWrLZfdli...
- IanGabes 7y agoMy team and i run some different honeypot solutions, and we base a lot of them off of cowrie. As pointed out by previous comments, most interactions are not so interesting, except for the fact that many cowrie based honeypots imitating IoT devices have their attackers running a simple script that pulls down a number of second stage binaries, for a variety of cpu architectures. One downside to running software like cowrie is that generally speaking crawlers like shodan will be able to figure out that you are running a honeypot, and will have you fingerprinted in a hurry. A better strategy for increasing the cost of an attack is actually implementing something i read about on HN called a ssh tarpit, where one can "hang" an incoming ssh connection indefinitely. A lot of the attacks on honeypots are automated, so instead of having a 3 second attack, one can waste the attackers time for about 30s to 1m on average as these scripts have very generous timeouts (and sometimes no timeouts at all).
- tastroder 7y ago> ssh tarpit Interesting, like slow request attacks in reverse? Is that actually useful for something? It seems like that would just needlessly burn resources on your end. The majority of attacks on my instance seem to have come from other infected routers/devices/etc. that pretty much perform these attacks for free.
- IanGabes 7y agoDepends on your goals! If you are defending a network, increasing the cost of attack is something we actively try to optimize for. It costs me next to nothing to hold a socket open and send a keep alive every 15 seconds or so, in addition to the extra threat intel from the initial connection. You might have a point, and maybe i should try to turn these subjective feelings into harder metrics in terms of cost, but we have figured at this point it has a net good. If we slow the scanning down by a magnitude, in my opinion its a good thing!
- tastroder 7y agoAh, sure, if it works why not, I would have expected most scans being too distributed for this to have noticable impact. Thanks for the explanation.
- deleted 7y ago[deleted]