mushorg / snare

Super Next generation Advanced Reactive honEypot
http://mushmush.org
GNU General Public License v3.0
437 stars 136 forks source link

Tanner "Detection Type" shows only index, unknown and xss #331

Open djoker77 opened 1 month ago

djoker77 commented 1 month ago

Hello everyone, I recently reported an issue on the t-pot page about Tanner not identifying any other attack types than XSS. Maybe you know why this is the case. Snare and Tanner are running normally, but I tried a couple attacks like SQLi, RFI/LFI or XXE, but neither of those were detected. Instead, they were classified as index or unknown. Can you help me with this issue, or do you know the reason for this behavior? (Speculation would also help)

Issue at t-pot: https://github.com/telekom-security/tpotce/issues/1560

afeena commented 3 weeks ago

Hi,

please make sure you have other emulators "enabled" on the Tanner side

djoker77 commented 3 weeks ago

Hi, thanks for the reply, I see that the emulators are enabled, I just enabled another emulator in the Tanner emulator configuration of the Tpot installation. The rest were left on enabled.

djoker77 commented 2 weeks ago

Hi, sorry for the annoyance, but have you got any other explanation for this problem?