######################################################## # T-Pot # # Honeytrap upstart script # # # # v0.04 by mo, DTAG, 2015-12-08 # ######################################################## description "Honeytrap" author "mo" start on (started docker and filesystem) stop on runlevel [!2345] respawn pre-start script # Remove any existing honeytrap containers myCID=$(docker ps -a | grep honeytrap | awk '{ print $1 }') if [ "$myCID" != "" ]; then docker rm -v $myCID; fi /sbin/iptables -w -A INPUT -p tcp --syn -m state --state NEW -m multiport ! --dports 21,22,42,80,135,443,445,1433,3306,5060,5061,64295,64296 -j NFQUEUE end script script # Delayed start to avoid rapid respawning sleep $(((RANDOM % 5)+5)) /usr/bin/docker run --name honeytrap --cap-add=NET_ADMIN --net=host --rm=true -v /data:/data dtagdevsec/honeytrap:latest1603 end script post-start script sleep $(((RANDOM % 5)+5)) end script post-stop script /sbin/iptables -w -D INPUT -p tcp --syn -m state --state NEW -m multiport ! --dports 21,22,42,80,135,443,445,1433,3306,5060,5061,64295,64296 -j NFQUEUE end script