tpotce/installer/data/upstart/honeytrap.conf

36 lines
1.5 KiB
Text
Raw Normal View History

2015-01-27 16:46:52 +00:00
########################################################
2015-12-08 14:47:39 +00:00
# T-Pot #
2015-01-27 16:46:52 +00:00
# Honeytrap upstart script #
# #
2016-02-08 11:21:03 +00:00
# v16.03.5 by mo, DTAG, 2016-02-08 #
2015-01-27 16:46:52 +00:00
########################################################
description "Honeytrap"
author "mo"
2015-12-11 12:29:12 +00:00
start on started docker and filesystem
2015-01-27 16:46:52 +00:00
stop on runlevel [!2345]
respawn
pre-start script
# Remove any existing honeytrap containers
myCID=$(docker ps -a | grep honeytrap | awk '{ print $1 }')
if [ "$myCID" != "" ];
2015-08-07 20:32:15 +00:00
then docker rm -v $myCID;
2015-01-27 16:46:52 +00:00
fi
# Remove any data from previous container
2016-02-08 11:21:03 +00:00
rm -rf /data/honeytrap/* || true
mkdir -p /data/honeytrap/log/ /data/honeytrap/attacks/ /data/honeytrap/downloads/
chmod 760 /data/honeytrap/ -R
chown tpot:tpot /data/honeytrap/ -R
2016-01-27 09:46:01 +00:00
/sbin/iptables -w -A INPUT -p tcp --syn -m state --state NEW -m multiport ! --dports 21,22,42,80,135,443,445,1433,3306,5060,5061,8081,9200,64295,64296 -j NFQUEUE
2015-01-27 16:46:52 +00:00
end script
script
/usr/bin/docker run --name honeytrap --cap-add=NET_ADMIN --net=host --rm=true -v /data/honeytrap:/data/honeytrap -v /data/ews:/data/ews dtagdevsec/honeytrap:latest1603
2015-01-27 16:46:52 +00:00
end script
post-start script
# Delay next start to avoid rapid respawning
sleep $(((RANDOM % 5)+5))
end script
2015-01-27 16:46:52 +00:00
post-stop script
2016-01-27 09:46:01 +00:00
/sbin/iptables -w -D INPUT -p tcp --syn -m state --state NEW -m multiport ! --dports 21,22,42,80,135,443,445,1433,3306,5060,5061,8081,9200,64295,64296 -j NFQUEUE
2015-01-27 16:46:52 +00:00
end script