tweaking, persistence

This commit is contained in:
t3chn0m4g3 2016-03-04 21:47:14 +01:00
parent a7f98902e3
commit 2d5c498860
6 changed files with 55 additions and 34 deletions

View file

@ -2,7 +2,7 @@
# T-Pot # # T-Pot #
# Elasticpot upstart script # # Elasticpot upstart script #
# # # #
# v16.03.4 by ms/mo, DTAG, 2016-02-08 # # v16.03.5 by ms/mo, DTAG, 2016-03-03 #
######################################################## ########################################################
description "ElasticPot" description "ElasticPot"
@ -16,11 +16,14 @@ pre-start script
if [ "$myCID" != "" ]; if [ "$myCID" != "" ];
then docker rm -v $myCID; then docker rm -v $myCID;
fi fi
# Remove any data from previous container # Remove any data from previous container if persistence is not enabled
if ! [ -f /data/persistence.on ];
then
rm -rf /data/elasticpot/* || true rm -rf /data/elasticpot/* || true
mkdir -p /data/elasticpot/log mkdir -p /data/elasticpot/log
chmod 760 /data/elasticpot -R chmod 760 /data/elasticpot -R
chown tpot:tpot /data/elasticpot -R chown tpot:tpot /data/elasticpot -R
fi
end script end script
script script
/usr/bin/docker run --name elasticpot --rm=true -v /data/elasticpot:/data/elasticpot -v /data/ews:/data/ews -p 9200:9200 dtagdevsec/elasticpot:latest1603 /usr/bin/docker run --name elasticpot --rm=true -v /data/elasticpot:/data/elasticpot -v /data/ews:/data/ews -p 9200:9200 dtagdevsec/elasticpot:latest1603

View file

@ -2,7 +2,7 @@
# T-Pot # # T-Pot #
# ELK upstart script # # ELK upstart script #
# # # #
# v16.03.3 by mo, DTAG, 2016-02-08 # # v16.03.4 by mo, DTAG, 2016-03-04 #
######################################################## ########################################################
description "ELK" description "ELK"
@ -16,6 +16,7 @@ pre-start script
if [ "$myCID" != "" ]; if [ "$myCID" != "" ];
then docker rm -v $myCID; then docker rm -v $myCID;
fi fi
# ELK data will be kept for <= 90 days, check /etc/crontab for curator modification
end script end script
script script
/usr/bin/docker run --name=elk -v /data:/data -p 127.0.0.1:64296:8080 --rm=true dtagdevsec/elk:latest1603 /usr/bin/docker run --name=elk -v /data:/data -p 127.0.0.1:64296:8080 --rm=true dtagdevsec/elk:latest1603

View file

@ -1,8 +1,8 @@
######################################################## ########################################################
# T-Pot Community Edition # # T-Pot #
# Conpot upstart script # # eMobility upstart script #
# # # #
# v0.50 by msbeiti, DTAG, 2015-08-05 # # v16.03.1 by ms / mo, DTAG, 2016-03-03 #
######################################################## ########################################################
description "emobility" description "emobility"
@ -16,12 +16,15 @@ pre-start script
if [ "$myCID" != "" ]; if [ "$myCID" != "" ];
then docker rm $myCID; then docker rm $myCID;
fi fi
# Remove any data from previous container # Remove any data from previous container if persistence is not enabled
if ! [ -f /data/persistence.on ];
then
rm -rf /data/emobility/* || true rm -rf /data/emobility/* || true
rm /data/ews/emobility/ews.json || true rm /data/ews/emobility/ews.json || true
mkdir -p /data/emobility/log /data/ews/emobility mkdir -p /data/emobility/log /data/ews/emobility
chmod 760 /data/emobility -R chmod 760 /data/emobility -R
chown tpot:tpot /data/emobility -R chown tpot:tpot /data/emobility -R
fi
end script end script
script script
# Delayed start to avoid rapid respawning # Delayed start to avoid rapid respawning

View file

@ -2,7 +2,7 @@
# T-Pot # # T-Pot #
# Glastopf upstart script # # Glastopf upstart script #
# # # #
# v16.03.3 by mo, DTAG, 2016-02-08 # # v16.03.4 by mo, DTAG, 2016-03-04 #
######################################################## ########################################################
description "Glastopf" description "Glastopf"
@ -16,8 +16,14 @@ pre-start script
if [ "$myCID" != "" ]; if [ "$myCID" != "" ];
then docker rm -v $myCID; then docker rm -v $myCID;
fi fi
# Remove any data from previous container # Remove any data from previous container if persistence is not enabled
if ! [ -f /data/persistence.on ];
then
rm -rf /data/glastopf/* || true rm -rf /data/glastopf/* || true
mkdir -p /data/glastopf
chmod 760 /data/glastopf -R
chown tpot:tpot /data/glastopf -R
fi
end script end script
script script
/usr/bin/docker run --name glastopf --rm=true -v /data/glastopf:/data/glastopf -v /data/ews:/data/ews -p 80:80 dtagdevsec/glastopf:latest1603 /usr/bin/docker run --name glastopf --rm=true -v /data/glastopf:/data/glastopf -v /data/ews:/data/ews -p 80:80 dtagdevsec/glastopf:latest1603

View file

@ -2,7 +2,7 @@
# T-Pot # # T-Pot #
# Honeytrap upstart script # # Honeytrap upstart script #
# # # #
# v16.03.7 by mo, DTAG, 2016-02-08 # # v16.03.8 by mo, DTAG, 2016-03-04 #
######################################################## ########################################################
description "Honeytrap" description "Honeytrap"
@ -16,11 +16,15 @@ pre-start script
if [ "$myCID" != "" ]; if [ "$myCID" != "" ];
then docker rm -v $myCID; then docker rm -v $myCID;
fi fi
# Remove any data from previous container # Remove any data from previous container if persistence is not enabled
if ! [ -f /data/persistence.on ];
then
rm -rf /data/honeytrap/* || true rm -rf /data/honeytrap/* || true
mkdir -p /data/honeytrap/log/ /data/honeytrap/attacks/ /data/honeytrap/downloads/ mkdir -p /data/honeytrap/log/ /data/honeytrap/attacks/ /data/honeytrap/downloads/
chmod 760 /data/honeytrap/ -R chmod 760 /data/honeytrap/ -R
chown tpot:tpot /data/honeytrap/ -R chown tpot:tpot /data/honeytrap/ -R
fi
# Enable NFQ chain
/sbin/iptables -w -A INPUT -p tcp --syn -m state --state NEW -j NFQUEUE /sbin/iptables -w -A INPUT -p tcp --syn -m state --state NEW -j NFQUEUE
end script end script
script script
@ -31,5 +35,6 @@ post-start script
sleep 2 sleep 2
end script end script
post-stop script post-stop script
# Drop NFQ chain
/sbin/iptables -w -D INPUT -p tcp --syn -m state --state NEW -j NFQUEUE /sbin/iptables -w -D INPUT -p tcp --syn -m state --state NEW -j NFQUEUE
end script end script

View file

@ -2,7 +2,7 @@
# T-Pot # # T-Pot #
# Suricata upstart script # # Suricata upstart script #
# # # #
# v16.03.2 by mo, DTAG, 2016-02-08 # # v16.03.3 by mo, DTAG, 2016-03-04 #
######################################################## ########################################################
description "Suricata" description "Suricata"
@ -16,21 +16,24 @@ pre-start script
if [ "$myCID" != "" ]; if [ "$myCID" != "" ];
then docker rm -v $myCID; then docker rm -v $myCID;
fi fi
# Remove any data from previous container # Remove any data from previous container if persistence is not enabled
if ! [ -f /data/persistence.on ];
then
rm -rf /data/suricata/* || true rm -rf /data/suricata/* || true
mkdir -p /data/suricata/log mkdir -p /data/suricata/log
chmod 760 -R /data/suricata chmod 760 -R /data/suricata
chown tpot:tpot -R /data/suricata chown tpot:tpot -R /data/suricata
fi
# Get IF, disable offloading, enable promiscious mode
myIF=$(route | grep default | awk '{ print $8 }') myIF=$(route | grep default | awk '{ print $8 }')
/sbin/ethtool --offload $myIF rx off tx off /sbin/ethtool --offload $myIF rx off tx off
/sbin/ethtool -K $myIF gso off gro off /sbin/ethtool -K $myIF gso off gro off
/sbin/ip link set $myIF promisc on /sbin/ip link set $myIF promisc on
end script end script
script script
# Delayed start to avoid rapid respawning
sleep 2
/usr/bin/docker run --name suricata --cap-add=NET_ADMIN --net=host --rm=true -v /data/suricata:/data/suricata dtagdevsec/suricata:latest1603 /usr/bin/docker run --name suricata --cap-add=NET_ADMIN --net=host --rm=true -v /data/suricata:/data/suricata dtagdevsec/suricata:latest1603
end script end script
post-start script post-start script
sleep $(((RANDOM % 5)+5)) # Delay next start to avoid rapid respawning
sleep 2
end script end script