update honeytrap.conf for tcp/8080 passthru

This commit is contained in:
Marco Ochse 2016-02-08 15:20:33 +01:00
parent cbccc7c83f
commit 0acc5a4a21

View file

@ -2,7 +2,7 @@
# T-Pot # # T-Pot #
# Honeytrap upstart script # # Honeytrap upstart script #
# # # #
# v16.03.5 by mo, DTAG, 2016-02-08 # # v16.03.6 by mo, DTAG, 2016-02-08 #
######################################################## ########################################################
description "Honeytrap" description "Honeytrap"
@ -21,7 +21,7 @@ pre-start script
mkdir -p /data/honeytrap/log/ /data/honeytrap/attacks/ /data/honeytrap/downloads/ mkdir -p /data/honeytrap/log/ /data/honeytrap/attacks/ /data/honeytrap/downloads/
chmod 760 /data/honeytrap/ -R chmod 760 /data/honeytrap/ -R
chown tpot:tpot /data/honeytrap/ -R chown tpot:tpot /data/honeytrap/ -R
/sbin/iptables -w -A INPUT -p tcp --syn -m state --state NEW -m multiport ! --dports 21,22,42,80,135,443,445,1433,3306,5060,5061,8081,9200,64295,64296 -j NFQUEUE /sbin/iptables -w -A INPUT -p tcp --syn -m state --state NEW -m multiport ! --dports 21,22,42,80,135,443,445,1433,3306,5060,5061,8080,8081,9200,64295,64296 -j NFQUEUE
end script end script
script script
/usr/bin/docker run --name honeytrap --cap-add=NET_ADMIN --net=host --rm=true -v /data/honeytrap:/data/honeytrap -v /data/ews:/data/ews dtagdevsec/honeytrap:latest1603 /usr/bin/docker run --name honeytrap --cap-add=NET_ADMIN --net=host --rm=true -v /data/honeytrap:/data/honeytrap -v /data/ews:/data/ews dtagdevsec/honeytrap:latest1603
@ -31,5 +31,5 @@ post-start script
sleep $(((RANDOM % 5)+5)) sleep $(((RANDOM % 5)+5))
end script end script
post-stop script post-stop script
/sbin/iptables -w -D INPUT -p tcp --syn -m state --state NEW -m multiport ! --dports 21,22,42,80,135,443,445,1433,3306,5060,5061,8081,9200,64295,64296 -j NFQUEUE /sbin/iptables -w -D INPUT -p tcp --syn -m state --state NEW -m multiport ! --dports 21,22,42,80,135,443,445,1433,3306,5060,5061,8080,8081,9200,64295,64296 -j NFQUEUE
end script end script