mirror of
https://github.com/telekom-security/tpotce.git
synced 2025-04-29 11:48:52 +00:00
29 lines
1.2 KiB
Text
29 lines
1.2 KiB
Text
![]() |
########################################################
|
||
|
# T-Pot Community Edition #
|
||
|
# Honeytrap upstart script #
|
||
|
# #
|
||
|
# v0.50 by mo, DTAG, 2015-01-27 #
|
||
|
########################################################
|
||
|
|
||
|
description "Honeytrap"
|
||
|
author "mo"
|
||
|
start on started docker and filesystem
|
||
|
stop on runlevel [!2345]
|
||
|
respawn
|
||
|
pre-start script
|
||
|
# Remove any existing honeytrap containers
|
||
|
myCID=$(docker ps -a | grep honeytrap | awk '{ print $1 }')
|
||
|
if [ "$myCID" != "" ];
|
||
|
then docker rm $myCID;
|
||
|
fi
|
||
|
/sbin/iptables -w -A INPUT -p tcp --syn -m state --state NEW -m multiport ! --dports 21,22,42,80,135,443,445,1433,3306,5060,5061,64295,64296 -j NFQUEUE
|
||
|
end script
|
||
|
script
|
||
|
# Delayed start to avoid rapid respawning
|
||
|
sleep $(((RANDOM % 5)+5))
|
||
|
/usr/bin/docker run --name honeytrap --cap-add=NET_ADMIN --net=host --rm=true -v /data/honeytrap dtagdevsec/honeytrap
|
||
|
end script
|
||
|
post-stop script
|
||
|
/sbin/iptables -w -D INPUT -p tcp --syn -m state --state NEW -m multiport ! --dports 21,22,42,80,135,443,445,1433,3306,5060,5061,64295,64296 -j NFQUEUE
|
||
|
end script
|