mirror of
https://github.com/telekom-security/tpotce.git
synced 2025-04-28 19:28:50 +00:00
honeytrap will log to host /data/honeytrap
This commit is contained in:
parent
c4903fef66
commit
3ba8567671
1 changed files with 8 additions and 4 deletions
|
@ -2,7 +2,7 @@
|
||||||
# T-Pot #
|
# T-Pot #
|
||||||
# Honeytrap upstart script #
|
# Honeytrap upstart script #
|
||||||
# #
|
# #
|
||||||
# v16.03.1 by mo, DTAG, 2015-12-11 #
|
# v16.03.2 by mo, DTAG, 2015-12-15 #
|
||||||
########################################################
|
########################################################
|
||||||
|
|
||||||
description "Honeytrap"
|
description "Honeytrap"
|
||||||
|
@ -16,14 +16,18 @@ pre-start script
|
||||||
if [ "$myCID" != "" ];
|
if [ "$myCID" != "" ];
|
||||||
then docker rm -v $myCID;
|
then docker rm -v $myCID;
|
||||||
fi
|
fi
|
||||||
|
# Remove any data from previous container
|
||||||
|
rm -rf /data/honeytrap/*
|
||||||
|
mkdir -p /data/honeytrap/log/ /data/honeytrap/attacks/ /data/honeytrap/downloads/
|
||||||
|
chmod 760 /data/honeytrap/ -R
|
||||||
|
chown tpot:tpot /data/honeytrap/ -R
|
||||||
/sbin/iptables -w -A INPUT -p tcp --syn -m state --state NEW -m multiport ! --dports 21,22,42,80,135,443,445,1433,3306,5060,5061,64295,64296 -j NFQUEUE
|
/sbin/iptables -w -A INPUT -p tcp --syn -m state --state NEW -m multiport ! --dports 21,22,42,80,135,443,445,1433,3306,5060,5061,64295,64296 -j NFQUEUE
|
||||||
end script
|
end script
|
||||||
script
|
script
|
||||||
# Delayed start to avoid rapid respawning
|
/usr/bin/docker run --name honeytrap --cap-add=NET_ADMIN --net=host --rm=true -v /data/honeytrap:/data/honeytrap -v /data/ews:/data/ews dtagdevsec/honeytrap:latest1603
|
||||||
sleep $(((RANDOM % 5)+5))
|
|
||||||
/usr/bin/docker run --name honeytrap --cap-add=NET_ADMIN --net=host --rm=true -v /data/ews:/data/ews dtagdevsec/honeytrap:latest1603
|
|
||||||
end script
|
end script
|
||||||
post-start script
|
post-start script
|
||||||
|
# Delay next start to avoid rapid respawning
|
||||||
sleep $(((RANDOM % 5)+5))
|
sleep $(((RANDOM % 5)+5))
|
||||||
end script
|
end script
|
||||||
post-stop script
|
post-stop script
|
||||||
|
|
Loading…
Reference in a new issue