Hfish honeypot construction (docker&ubuntu)

Recently, HW is coming soon, Hfish honeypot is very popular, try to build it.


project address

https://github.com/hacklcx/HFish

https://hfish.io/

Supported honeypot types:

Official installation guide: (docker version operation is very simple)

https://hfish.io/docs/#/deploy/docker

docker installation


Docker installation:

Docker download image (the currently tested docker version is 0.6)


Single node deployment (this time mainly personal [cloud server] (https://cloud.tencent.com/product/cvm?from=10680) build)

The value of the environment variable API_IP is composed of the IP address of the API plus the port.

The default account password is admin, if you need to modify it, you can modify it by adding -e USERNAME= -e PASSWORD= to the environment variable. (You can also enter the container configuration config.ini to configure the account password after starting the container)

If you need to store data persistently, you can add the parameter -v $PWD:/opt to mount the data volume to Host to avoid data loss when the container is deleted.

Start docker


The port correspondence can also be modified by yourself (-p 22:22, the first 22 is the host port, and the second 22 is the port mapped by docker) can be changed according to your host situation

Access management port: ip+9001 (management port can be modified)

The port and password were changed when building

Enter the docker container after startup


You can modify the port and password after entering

vi Hfish/config.ini


Port relationship:


One more note:

report_key and query_key are recommended to be modified to prevent the data from being taken away


There are some other attributes that can be adjusted, see config.ini for details (default related information)

[ rpc]
status = 0 # Mode 0 closes 1 server 2 client
addr = 0.0.0.0:7879 # RPC server address or client address
name = Server # State 1 Server name State 2 Client name
[ admin] # admin can be deleted when RPC status is 2 cluster client
addr = 0.0.0.0:9001 # Management background start address
account = admin # Login account, no #
password = admin # Login password, no #
attack_city = Beijing# Data big screen attack area setting
db_type = sqlite # sqlite or mysql
db_max_open = 50 # Maximum connection pool, 0 means unlimited
db_max_idle = 50 # Maximum idle number, 0 means unlimited
db_str = ./db/hfish.db?cache=shared&mode=rwc # sqlite or mysql connection string
# sqlite : ./db/hfish.db?cache=shared&mode=rwc
# mysql: account: password@tcp(address: port)/database name?charset=utf8&parseTime=true&loc=Local
[ api]
status = 1 # Whether to start API 0 Disable 1 Start
web_url = /api/v1/post/report # WEB honeypot report API
deep_url = /api/v1/post/deep_report # Darknet honeypot report API
plug_url = /api/v1/post/plug_report # Plug-in honeypot report API
report_key = 9cbf8a4dcb8e30682b927f352d6559a0 # API report authentication key
query_key = X85e2ba265d965b1929148d0f0e33133 # API query authentication key
[ plug]
status = 1 # Whether to start the honeypot plugin 0 Close 1 Start, you need to start the API first
addr = 0.0.0.0:8989 # Honeypot plugin startup address
[ web]
status = 1 # Whether to start WEB 1 Start 0 Close, WEB can report the result after starting API
addr = 0.0.0.0:9000 # WEB startup address, 0.0.0.0 is open to the outside world, 127.0.0.1 is open to the inside and can use Nginx reverse proxy
template = wordPress/html # WEB template path
index = index.html # WEB home page file
static = wordPress/static # WEB static file path Note: There must be two directories, html file and static file cannot be leveled
url = / # WEB access directory, default / can be changed to index.html index.asp index.php
[ deep]
status = 1 # Whether to start the dark web 1 start 0 close, the result can be reported after the API is started
addr = 0.0.0.0:8080 # Darknet WEB start address
template = deep/html # Darknet WEB template path
index = index.html # Darknet WEB homepage file
static = deep/static # Darknet WEB static file path Note: There must be two directories, html files and static files cannot be leveled
url = / # Darknet WEB access directory, default / can be changed to index.html index.asp index.php
[ ssh]
status = 2 # Whether to start SSH 0 Close 1 Low interaction 2 High interaction
addr = 0.0.0.0:22 # SSH server address pay attention to the port conflict, please close the server openssh service first or modify the port
[ redis]
status = 1 # Whether to start Redis 0 Turn off 1 Start
addr = 0.0.0.0:6379 # Redis server address pay attention to port conflicts
[ mysql]
status = 1 # Whether to start Mysql 0 Close 1 Start
addr = 0.0.0.0:3306 # Mysql server address pay attention to port conflicts
files = /etc/passwd,/etc/group # Mysql server reads any file on the client side; write multiple commas to separate them, and they will be randomly selected
[ telnet]
status = 1 # Whether to start Telnet 0 Turn off 1 Start
addr = 0.0.0.0:23 # Telnet server address pay attention to port conflicts
[ ftp]
status = 1 # Whether to start Ftp 0 Turn off 1 Start
addr = 0.0.0.0:21 # Ftp server address pay attention to port conflicts
[ mem_cache]
status = 1 # Whether to start MemCache 0 Turn off 1 Start
addr = 0.0.0.0:11211 # Memcache server address pay attention to port conflicts
[ http]
status = 1 # Whether to start HTTP proxy 0 off 1 start
addr = 0.0.0.0:8081 # HTTP proxy address pay attention to port conflicts
[ tftp]
status = 1 # Whether to start tftp 0 close 1 start
addr = 0.0.0.0:69 # tftp server address pay attention to port conflicts
[ elasticsearch]
status = 1 # Whether to start ES honeypot 0 Close 1 Start
addr = 0.0.0.0:9200 # ES honeypot server address pay attention to port conflicts
[ vnc]
status = 1 # Whether to start the VNC honeypot 0 close 1 start
addr = 0.0.0.0:5900 # VNC honeypot server address pay attention to port conflicts

linux service installation (ubuntu)


Installation note (To use 0.6.3, please download 0.6.2 first, and then overwrite 0.6.3 into the 0.6.2 program.)

Otherwise the download will not work (./Hfish)

Download the version corresponding to your operating system:

Download and unzip


Overwrite the files in 0.6.3 to 0.6.2



Visit the ip+9001 management interface and it's OK

If you need to modify the port, password, service-related configuration, see the modification configuration method of the docker section (the configuration method is the same)

Final rendering


Dashboard effect

The effect is very good. Data display and process records are good.

Supplement: This article only builds a single node deployment. If you need cluster deployment, move to step (https://hfish.io/)

reference:

https://github.com/hacklcx/HFish

https://hfish.io/

https://hfish.io/docs/#/deploy/docker

Recommended Posts

Hfish honeypot construction (docker&ubuntu)