Monday, 28 October 2013

No bees to my honeypot

So unlike the girl on the left here it seems that my honeypot as yet isn't enticing enough to warrant a look. Since I set the honeypot up a few weeks ago all I have seen is port scans checking the SSH port is open.
This has also tied in with some work travel and responsibilities, but hopefully this week I will get some time to set up Kippo Graph and look at ways of making my server look more enticing and at least warrant a brute force attempt against it!

Tuesday, 8 October 2013

Enabling MySQL Logging for Kippo

At the moment my SSH honeypot isn't getting a large amount of hits, the only interactions thus far have been with what would seem to be port scanners where the connections are made and dropped within a few sections and no user interaction. I have changed the default root password from "123456" to "Password1!" and changed the hostname from "nas3" to "Dev-server" in an effort to disguise it a little bit more.

The flat log files produced by Kippo are a good start, but the later version of Kippo come with the ability to log directly into a MySQL database which will allow for more powerful integration with other data as well as give the ability to extract information more easily, so while I wait for further interactions on my Honeypot, now would be a good time to continue optimisation and automation of the process so I'm set up for the long haul. Luckily the later version of Kippo are ready to log straight to SQL with minimal configuration and instructions are provided on the Kippo project page.

Saturday, 5 October 2013

Automating the Kippo review process - Part 1


With time being a commodity I do not have a lot of, it has quickly become apparent that the enthusiasm that I now have for logging in and checking my Kippo honeypot everyday will eventually wane. While Googling around for some ideas on what to look for and running Kippo I came across this blog post "Reviewing Kippo Logs" and the author Andrew Waite has provided his script to provide a daily review of Kippo logs via email, and I will look at customising this script to run on my honeypot.

Friday, 4 October 2013

Honeypots for blondes, Part 1

This is the first time I am setting up a honeypot, and I'll be taking my time and going through two different set-ups. Firstly I'll set-up and play around with Kippo, and then once that is up and running I'm going to also install dionaea.

"Kippo is a medium interaction SSH honeypot designed to log brute force attacks and, most importantly, the entire shell interaction performed by the attacker". 

I'm not hiding from the Feds ... I promise!

... otherwise known as "Setting up PuTTY for use with Tor".

Sometimes, just sometimes, you do have something to hide, and in my case right now it's my IP address. There are times when you just don't want your home IP address being logged on a server somewhere, for someone not so very nice to find. This is the case for me as I am setting up a honeypot, and in case of the worst happening (my instance gets p0wned) I don't want my home IP address littered throughout the logs. So, to get around this I am connecting with PuTTY using a Tor proxy to anonymise my IP address. So before any of you start to think up your witty "Tor isn't really anonymous" comments for the sections below .. let me stop you .. I am not using Tor to completely anonymise my actions, but so that the IP address logged on my honeypot system is not my own .. for my own (paranoid) protection. For more information on Tor and internet privacy, you can see their website.

Monday, 4 June 2012

Amusing comic of the week

Just thought this was quite amusing ...

Thursday, 1 March 2012

Post #1

So how do you actually start your first post on a brand new blog? I'm not really sure, so I'll start with a little bit about myself!

I'm relatively new to the field of computer forensics, having worked in Information Security for about 10 years before moving into a forensicator role.  I am in the middle of a Masters degree with a focus on Digital Forensics, and have completed the SANS408 course and the GCFE certification.

So what does someone so new have to offer the world of the #DFIR blog? I have been following a number of blogs over the last 6 months, including my favourite by GirlUnallocated who keeps inspiring me to take up the blogging challenge, and by following these blogs and CONSTANTLY referencing them, i found myself agreeing that even the smallest contributions can mean big things.

I'm going to try as much as I can to put an Australian spin onto things I write about. We have done a small amount of work during my Masters on law and ethics, and I would like to expand on Australian Cybercrime Law as I study it more. I also need to keep a professional journal over the next 12 weeks as part of my subject, so I'll be using some of the material i collect to make some blog posts.

The next post I make will be something I have been meaning to do for weeks, and it involves the challenges faced when doing a remote acquisition (say for example your client is an Australian based company who use an American web hosting provider). I'm going to jump on the "case-study" bandwagon somewhat as well as I have a goal to write several case studies this year!

Thoughts are welcome, <joke>criticisms are as well I suppose</joke>, all along with the usual disclaimer that I'm not here to try and teach everyone everything, my journey is only just beginning, and as many others have before me, I would like to share this for my own learning and others who are just starting out!