Live data from Hacker News

Learn from your attackers with a high interactivity SSH Honey Pot

robertputt.co.uk

1–10 of 21 posts

Re: Learn from your attackers with a high interactivity SSH Honey Pot

#9

My experience with kippo was that it basically didn’t work. They’d come in and run a few commands and then ghost. I figured they had some easy way to find out if they were inside a honeypot that’s was immediately obvious to me.

Yup, Kippo is extremely easy to detect.

Full interaction honeypots based on NAT like this are also detectable if you look at RTT and TTL on packets pre-auth and post-auth.

Re: Learn from your attackers with a high interactivity SSH Honey Pot

#10

My experience with kippo was that it basically didn’t work. They’d come in and run a few commands and then ghost. I figured they had some easy way to find out if they were inside a honeypot that’s was immediately obvious to me.

in this case: check if a directory /home/honssh exists to detect that it's a honeypot?
Post reply on HN