tpotce/installer/upstart/honeytrap.conf
2015-12-08 15:47:39 +01:00

31 lines
1.2 KiB
Text

########################################################
# T-Pot #
# Honeytrap upstart script #
# #
# v0.04 by mo, DTAG, 2015-12-08 #
########################################################
description "Honeytrap"
author "mo"
start on (started docker and filesystem)
stop on runlevel [!2345]
respawn
pre-start script
# Remove any existing honeytrap containers
myCID=$(docker ps -a | grep honeytrap | awk '{ print $1 }')
if [ "$myCID" != "" ];
then docker rm -v $myCID;
fi
/sbin/iptables -w -A INPUT -p tcp --syn -m state --state NEW -m multiport ! --dports 21,22,42,80,135,443,445,1433,3306,5060,5061,64295,64296 -j NFQUEUE
end script
script
# Delayed start to avoid rapid respawning
sleep $(((RANDOM % 5)+5))
/usr/bin/docker run --name honeytrap --cap-add=NET_ADMIN --net=host --rm=true -v /data:/data dtagdevsec/honeytrap:latest1603
end script
post-start script
sleep $(((RANDOM % 5)+5))
end script
post-stop script
/sbin/iptables -w -D INPUT -p tcp --syn -m state --state NEW -m multiport ! --dports 21,22,42,80,135,443,445,1433,3306,5060,5061,64295,64296 -j NFQUEUE
end script