diff --git a/installer/etc/tpot/elkbase.tgz b/installer/etc/tpot/elkbase.tgz index a3af3138..343c94a2 100644 Binary files a/installer/etc/tpot/elkbase.tgz and b/installer/etc/tpot/elkbase.tgz differ diff --git a/installer/etc/tpot/kibana-objects.tgz b/installer/etc/tpot/kibana-objects.tgz index 26d733ad..f56e57e7 100644 Binary files a/installer/etc/tpot/kibana-objects.tgz and b/installer/etc/tpot/kibana-objects.tgz differ diff --git a/installer/etc/tpot/logrotate/logrotate.conf b/installer/etc/tpot/logrotate/logrotate.conf index 7b57608b..f0120e92 100644 --- a/installer/etc/tpot/logrotate/logrotate.conf +++ b/installer/etc/tpot/logrotate/logrotate.conf @@ -23,6 +23,7 @@ /data/p0f/log/p0f.json /data/suricata/log/*.log /data/suricata/log/*.json +/data/vnclowpot/log/vnclowpot.log { su tpot tpot copytruncate diff --git a/installer/etc/tpot/systemd/tpot.service b/installer/etc/tpot/systemd/tpot.service index c38c0b00..5f21ad22 100644 --- a/installer/etc/tpot/systemd/tpot.service +++ b/installer/etc/tpot/systemd/tpot.service @@ -34,7 +34,7 @@ ExecStartPre=/sbin/iptables -w -A INPUT -s 127.0.0.1 -j ACCEPT ExecStartPre=/sbin/iptables -w -A INPUT -d 127.0.0.1 -j ACCEPT ExecStartPre=/sbin/iptables -w -A INPUT -p tcp -m multiport --dports 64295:64303,7634 -j ACCEPT ExecStartPre=/sbin/iptables -w -A INPUT -p tcp -m multiport --dports 20:23,25,42,69,80,135,443,445,1433,1723,1883,1900 -j ACCEPT -ExecStartPre=/sbin/iptables -w -A INPUT -p tcp -m multiport --dports 3306,5060,5061,5601,27017 -j ACCEPT +ExecStartPre=/sbin/iptables -w -A INPUT -p tcp -m multiport --dports 3306,5060,5061,5601,5900,27017 -j ACCEPT ExecStartPre=/sbin/iptables -w -A INPUT -p tcp -m multiport --dports 1025,50100,8080,8081,9200 -j ACCEPT ExecStartPre=/sbin/iptables -w -A INPUT -p tcp --syn -m state --state NEW -j NFQUEUE @@ -49,7 +49,7 @@ ExecStopPost=/sbin/iptables -w -D INPUT -s 127.0.0.1 -j ACCEPT ExecStopPost=/sbin/iptables -w -D INPUT -d 127.0.0.1 -j ACCEPT ExecStopPost=/sbin/iptables -w -D INPUT -p tcp -m multiport --dports 64295:64303,7634 -j ACCEPT ExecStopPost=/sbin/iptables -w -D INPUT -p tcp -m multiport --dports 20:23,25,42,69,80,135,443,445,1433,1723,1883,1900 -j ACCEPT -ExecStopPost=/sbin/iptables -w -D INPUT -p tcp -m multiport --dports 3306,5060,5061,5601,27017 -j ACCEPT +ExecStopPost=/sbin/iptables -w -D INPUT -p tcp -m multiport --dports 3306,5060,5061,5601,5900,27017 -j ACCEPT ExecStopPost=/sbin/iptables -w -D INPUT -p tcp -m multiport --dports 1025,50100,8080,8081,9200 -j ACCEPT ExecStopPost=/sbin/iptables -w -D INPUT -p tcp --syn -m state --state NEW -j NFQUEUE diff --git a/installer/install.sh b/installer/install.sh index daad977a..f567b8e9 100755 --- a/installer/install.sh +++ b/installer/install.sh @@ -451,6 +451,7 @@ mkdir -p /data/conpot/log \ /data/spiderfoot \ /data/suricata/log /home/tsec/.ssh/ \ /data/p0f/log \ + /data/vnclowpot/log \ /etc/tpot/elk /etc/tpot/compose /etc/tpot/systemd \ /usr/share/tpot/bin 2>&1 | dialog --title "[ Creating some files and folders ]" $myPROGRESSBOXCONF touch /data/spiderfoot/spiderfoot.db 2>&1 | dialog --title "[ Creating some files and folders ]" $myPROGRESSBOXCONF