telekom-security / tpotce

🍯 T-Pot - The All In One Multi Honeypot Platform 🐝
GNU General Public License v3.0
6.77k stars 1.07k forks source link

[ASK] Dionaea not saving binaries? #84

Closed decker78 closed 7 years ago

decker78 commented 7 years ago

Hello All,

I have the latest T-Pot installed but seem to be unable to ctach any binaries using dionaea. Or it is just me being impatient? (running for 48 hours).

Also the question which tools are available on the distro to read out the dionaea.sqllite file?

Description=dionaeaRequires=docker.serviceAfter=docker.service[Service]Restart=alwaysExecStartPre=-/usr/bin/docker stop dionaeaExecStartPre=-/usr/bin/docker rm -v dionaeaExecStartPre=/bin/bash -c '/usr/bin/ dionaea off'ExecStart=/usr/bin/docker run --name dionaea --cap-add=NET_BIND_SERVICE --rm=true -p 21:21 -p 42:42 -p 69:69/udp -p 8081:80 -p 135:135 -p 443:443 -p 445:445 -p 1433:1433 -p 1723:1723 -p 1883:1883 -p 1900:1900 -p 3306:3306 -p 5060:5060 -p 5061:5061 -p 5060:5060/udp -p 11211:11211 -v /data/dionaea:/data/dionaea -v /data/ews:/data/ews dtagdevsec/dionaea:latest1610ExecStop=/usr/bin/docker stop dionaea[Install]

t3chn0m4g3 commented 7 years ago

Dionaea is mostly about detecting shellcodes which are stored in the bistreams folder. However you can test uploading via FTP. Kibana contains all information which is stored in the dionaea.json, which should be the same as the dionaea.sqlite. For the latter use sqlite3