######################################################## # T-Pot # # Honeytrap upstart script # # # # v16.03.8 by mo, DTAG, 2016-03-04 # ######################################################## description "Honeytrap" author "mo" start on started docker and filesystem stop on runlevel [!2345] respawn pre-start script # Remove any existing honeytrap containers myCID=$(docker ps -a | grep honeytrap | awk '{ print $1 }') if [ "$myCID" != "" ]; then docker rm -v $myCID; fi # Remove any data from previous container if persistence is not enabled if ! [ -f /data/persistence.on ]; then rm -rf /data/honeytrap/* || true mkdir -p /data/honeytrap/log/ /data/honeytrap/attacks/ /data/honeytrap/downloads/ chmod 760 /data/honeytrap/ -R chown tpot:tpot /data/honeytrap/ -R fi # Enable NFQ chain /sbin/iptables -w -A INPUT -p tcp --syn -m state --state NEW -j NFQUEUE end script script /usr/bin/docker run --name honeytrap --cap-add=NET_ADMIN --net=host --rm=true -v /data/honeytrap:/data/honeytrap -v /data/ews:/data/ews dtagdevsec/honeytrap:latest1603 end script post-start script # Delay next start to avoid rapid respawning sleep 2 end script post-stop script # Drop NFQ chain /sbin/iptables -w -D INPUT -p tcp --syn -m state --state NEW -j NFQUEUE end script