~5m32:28Let's Catch Some Hackers - Deploying a Honeypot! #1
Mar 11, 2021
Read: ~5m · You save: 27 min
Let's Catch Some Hackers - Deploying a Honeypot!
Learn how to deploy a powerful honeypot to catch hackers! See how Teapot uses Docker to mimic vulnerable systems and gather crucial threat intelligence.
A honeypot server is a decoy system deployed on a network to attract and detect unauthorized access attempts. These servers mimic vulnerable services, such as outdated SSH, vulnerable MySQL, or exploitable web applications, to lure attackers. By observing interactions with a honeypot, security professionals can gather intelligence on current attack vectors, identify new exploitation methods, and assess the threat landscape. This information can then be used to strengthen the security of critical internal and external-facing systems.
Honeypots can be deployed in two primary strategies:
- External Deployment: Placed on the internet to attract and analyze attacks originating from the wider web. This allows for broad threat research.
- Internal Deployment: Situated within a private network to detect malicious insiders, identify malware that has bypassed perimeter defenses, or catch attackers in the early stages of reconnaissance before they reach critical assets.
Teapot: An All-in-One Honeypot Solution
Teapot is an open-source project available on GitHub that simplifies honeypot deployment. It leverages Docker to host a variety of pre-configured honeypot services, including emulations of vulnerable Cisco ASA, SSH, web applications, and RDP services. Teapot also integrates with network intrusion detection systems like Suricata to capture and analyze network traffic.
Installation and Configuration
The recommended hardware for Teapot includes at least 8GB of RAM and a 128GB SSD. The system can be configured with a DHCP or static IP address. A non-proxied internet connection is required for downloading Docker images during installation.
Installation can be performed using several methods:
- Pre-built ISO: For virtualized environments like VMware vSphere.
- Install Script: Cloning the Teapot repository and running the provided installation script on an Ubuntu system.
- Custom ISO Creation: Building a personalized ISO image.
The installation script automates the setup process, including the configuration of Dockerized honeypots and the necessary logging infrastructure.
Key Installation Steps and Considerations:
- Cloning the Repository:
git clone <repository_url> cd teapot/installer/ ./install.sh - SSH Port Change: The installation process may reconfigure the default SSH port (22) to a non-standard port (e.g., 64295) to accommodate honeypot services like Cowrie, which mimics a vulnerable SSH server on port 22.
- Honeypot Selection: Teapot offers various deployment profiles, including a "standard" setup and specialized profiles like "industrial" for emulating PLCs or medical devices, depending on the network environment.
- Logging Infrastructure: Teapot can deploy its own Elasticsearch and Kibana cluster for log aggregation and visualization. Alternatively, it can be configured to forward logs to an existing Elasticsearch cluster.
- Docker Image Downloads: The installer downloads Docker images for various honeypot sensors such as Honeytrap, Cowrie, and RDpy. Suricata is also utilized for network packet capture and analysis.
Post-Installation Access and Verification
After installation and a system reboot, users can access the honeypot server via SSH on the configured port (e.g., 64295). Network status can be verified using netstat to confirm that honeypot services are listening on their respective ports.
The Teapot web UI is accessible via a web browser at the server's IP address and a specific port (e.g., 64297). This UI provides access to Kibana dashboards for analyzing captured attack data.
Configuration File (teapot.yaml)
The teapot.yaml file, located in /etc/teapot/, allows for customization of the honeypot deployment. Users can:
- Enable/Disable Services: Comment out specific honeypot services (e.g., Cisco ASA) if they are not relevant to the deployment environment.
- Modify Ports and Protocols: Adjust the listening ports and protocols for individual honeypot services.
- Configure Log Forwarding: Set up log forwarding to external systems like Elasticsearch.
Changes to teapot.yaml require restarting the Teapot service using systemctl restart teapot.
Monitoring and Analysis with Kibana
Teapot integrates with Kibana, providing pre-built dashboards for visualizing attack data. These dashboards offer insights into:
- Attacked Services: Identifying which honeypot services are being targeted.
- Attacker IP Addresses: Displaying the source IP addresses of attackers.
- Exploited Vulnerabilities: Highlighting attempts to exploit known CVEs.
- Geographic Location: Visualizing the origin of attacks on a map.
- HTTP Methods and Payloads: Analyzing the types of HTTP requests and commands used by attackers.
- Credentials: Capturing attempted usernames and passwords for services like SSH.
The "Discover" tab in Kibana allows for viewing raw log alerts, including Suricata alerts detailing specific attack payloads and attempted exploits.
Mimicking Legitimate Systems
To enhance effectiveness, honeypots should appear as legitimate systems. This can involve:
- Customizing Hostnames: Changing the default random hostname generated by Teapot to match an organization's naming convention (e.g.,
prod-5625). This requires modifying the system's hostname configuration and rebooting. - Presenting Realistic Services: Configuring honeypot services, such as web applications, to appear as authentic as possible to avoid deterring attackers. This may involve creating custom HTML pages for web applications.
Network Scanning and Attacker Perspective
Tools like Nmap can be used to scan the honeypot from an attacker's perspective, revealing the open ports and services that would be visible to malicious actors. A legitimate server typically would not expose as many open ports as a default honeypot configuration. For internal deployments, disabling unnecessary services in teapot.yaml can make the honeypot appear less conspicuous.
Benefits of Honeypot Deployment
- Threat Intelligence: Gathers data on active attack methods and trends.
- Early Detection: Identifies potential breaches or malware activity within the network.
- Attacker Diversion: Wastes attackers' time and resources on decoy systems.
- IP Blacklisting: Enables the identification and blacklisting of malicious IP addresses before they target legitimate servers.
- Insider Threat Detection: Helps uncover malicious activities by internal users.
Future steps in honeypot deployment may include installing agents like WAZUH for log forwarding to an existing Elasticsearch cluster and configuring real-time alerting to notify security teams of interactions with the honeypot.
What is a Honeypot Server?
The video introduces the concept of a honeypot server, which is a decoy system designed to attract and trap attackers. It doesn't host critical business applications but mimics vulnerable services like outdated SSH or vulnerable web applications to gather intelligence on ongoing attacks.
- A honeypot server is a decoy system on a network.
- It does not run business-critical applications or services.
- It mimics vulnerable services (e.g., outdated SSH, vulnerable MySQL, vulnerable web apps, RDP).
- The purpose is to gather intelligence on attacker methods and ongoing attacks.
- This intelligence helps protect internal and external servers from similar exploits.
Honeypot Deployment Strategies
Honeypots can be deployed externally to attract internet-wide scans or internally to detect malicious insiders or malware that has entered the network. Internal honeypots are crucial for identifying unauthorized activity before significant damage occurs.
- Honeypots can be deployed externally (internet-facing) or internally.
- External deployment gathers intelligence on widespread attacks.
- Internal deployment detects malicious insiders or internal malware.
- They provide an early indicator of network breaches and reconnaissance activities.
- Catching activity early can prevent significant damage.
Introducing the Teapot Honeypot Project
The 'Teapot' project on GitHub is presented as an all-in-one honeypot solution utilizing Docker. It supports mimicking various vulnerable services and includes components for logging and analysis, such as Elasticsearch and Kibana.
- Teapot is an open-source, all-in-one honeypot project on GitHub.
- It uses Docker to host multiple honeypot services.
- Supported honeypots include vulnerable Cisco ASA, SSH, web applications, and more.
- It aims to capture malicious insider traffic and external attacks.
- It integrates with Elasticsearch and Kibana for log analysis.
Teapot Installation Process
Installation of Teapot can be done via a pre-built ISO or by cloning the repository and running an install script on an Ubuntu system. Hardware recommendations include at least 8GB RAM and a 128GB SSD. The installation process involves cloning the repo, running the install script, and configuring services like SSH port redirection.
- Installation options: pre-built ISO or cloning repo and running install script on Ubuntu.
- Recommended hardware: 8GB RAM, 128GB SSD.
- Network configuration: DHCP or static IP.
- Requires a non-proxy internet connection for downloading Docker images.
- The install script may change the default SSH port (e.g., to 64295) to run a honeypot on port 22.
Post-Installation Configuration and Access
The Teapot installation configures various honeypot services, including a vulnerable SSH (Cowrie) on port 22, and sets up an Elasticsearch and Kibana cluster for data visualization. Post-installation, users can access the Kibana dashboard to view attack data and alerts.
- Teapot deploys Docker containers for various honeypots (e.g., Cowrie for SSH, Tanner for web apps).
- It uses Circada to capture network packets and generate intrusion alerts.
- After reboot, SSH access is via the new port (e.g., 64295).
- Netstat shows honeypots running on their respective ports (e.g., Cowrie on port 22).
- A web UI provides access to Kibana dashboards for viewing attack data.
Customizing Honeypot Services
The `teapot.yaml` configuration file allows customization of honeypot services, enabling or disabling specific honeypots, and changing their listening ports and protocols. This flexibility is crucial for tailoring the honeypot to specific network environments.
- The
teapot.yamlfile in/etc/is the main configuration file. - Users can comment out services to disable specific honeypots.
- Ports and protocols for honeypot services can be modified.
- Example: Disabling Cisco ASA mimicry or changing SSH ports.
- Changes require restarting the Teapot service (
systemctl restart teapot).
Observing Attacks and Analyzing Data
The video demonstrates how attackers might perceive the honeypot using Nmap scans, revealing multiple open ports. It also shows how the honeypot captures attack attempts, including SQL injection on web applications and brute-force SSH logins, with data visible in Kibana.
- Nmap scans reveal multiple open ports, mimicking a vulnerable system.
- The honeypot captures web application attacks (e.g., SQL injection) via Tanner.
- It captures SSH login attempts, including usernames and passwords (via Cowrie).
- Circada alerts detect exploitation attempts against known CVEs.
- Kibana dashboards visualize attack data, including source IPs, HTTP methods, and rule triggers.
Making Honeypots Appear Legitimate
The importance of making honeypots appear legitimate is emphasized. This includes configuring hostnames to match internal naming conventions and avoiding overly obvious configurations. The goal is to trick attackers into wasting time and resources on the decoy.
- Honeypots should appear as legitimate systems to avoid deterring attackers.
- Random hostnames generated by Teapot can be changed to match internal conventions.
- Disabling unnecessary services can make the honeypot less obviously a decoy.
- The objective is to make attackers believe they are interacting with a real, vulnerable system.
- This wastes attacker time and provides valuable threat intelligence.
Conclusion and Future Steps
The video concludes by highlighting the value of honeypots in identifying malicious insiders, detecting malware, and diverting attackers from legitimate systems. Future videos will cover installing WAZUH agents for log forwarding and setting up real-time alerting.
- Honeypots help identify malicious insiders and network malware.
- They can divert attackers from critical infrastructure.
- They allow blacklisting attacker IPs before they target real servers.
- Honeypots save time and resources by slowing down attackers.
- Future topics: WAZUH agent installation, log forwarding to Elasticsearch, real-time alerting.