What is a honeypot, How to install and what can we see from honeypots?

Поделиться
HTML-код
  • Опубликовано: 4 авг 2024
  • In this lab i will show you a honeypot implimentation, describe what a honey pot is and show you the step by step instructions to install tpot honeypots
    github.com/dtag-dev-sec/tpotc... of Contents:
    01:35 - Honeypot Deployment Considerations
    Join the community on Discord on this link : / discord . You can post live questions and get help from others there.
    Follow us on:
    Twitter: @lahilabs / lahilabs
    Facebook : / 2660291254110431
    And Support This Channel on
    Patreon: / itsecuritylabs Connect and Direct Message me on Linkedin: / howard-mukanda-24503144
  • ХоббиХобби

Комментарии • 115

  • @papajohnscookie
    @papajohnscookie 2 года назад +3

    This is great, I don't know why I never of thought of running one in the cloud just for curiosities sake

  • @user-uw1wq9rj8g
    @user-uw1wq9rj8g 3 года назад +1

    Amazing explanation, thanks for sharing the knowledge

  • @davidreichert6376
    @davidreichert6376 Год назад

    your videos are very good and have a wide message thank you

  • @slfonden4753
    @slfonden4753 5 лет назад +2

    Thanks for another great video

  • @danielfu3884
    @danielfu3884 3 года назад +1

    Perfect Honeypot Video 👍

  • @davidamigos.davidamigosnwa4522
    @davidamigos.davidamigosnwa4522 4 месяца назад

    excellent thanks. Keep up the great work.

  • @orca2162
    @orca2162 3 года назад +1

    Great stuff, thank you!

  • @willhikeforfood3272
    @willhikeforfood3272 5 лет назад +17

    Very nice (from one I.T. person to another). Keep up the great work!

  • @davidpecoraro194
    @davidpecoraro194 2 года назад +3

    Great video. Can you explain how to set up PFsense to allow for a configuration in front of your firewall? I would like to set up tpot to receive pertinent internet traffic. Are there a list of ports to forward to tpot or a configuration setup in PFsense?

  • @brianturney2124
    @brianturney2124 2 года назад +1

    Super cool. I set this up on AWS and it works great. I havent opened up all the ports yet in the documentation did you open up every port or just enough to make the web page load?

  • @prestigedps7435
    @prestigedps7435 4 года назад

    Can you advise what version of Ubuntu and the direct edition you are using. Currently i created my own ISO and installing a Debian stretch edition. it seems TPOT only supports older Debian stretch SID editions . if you cat /etc/Debian_version on the latest Ubuntu LTS it shows buster. Install fails

  • @radityawaliulu
    @radityawaliulu 4 года назад

    Hi, about timing 7:28 to 7:40 is it auto binding port?
    then, is it secure about port opened even for honeypot or honeytrap

  • @bernardasareasante4355
    @bernardasareasante4355 3 года назад

    Please do you have any tutorials on installation of capture-HPC ?

  • @Yvtq8K3n
    @Yvtq8K3n 4 года назад

    Very nice:)

  • @yarekzethiopia9050
    @yarekzethiopia9050 5 лет назад +3

    it's nice tutorial what is next after getting honeypot log data and related with cyber intelligence

  • @stevecross9159
    @stevecross9159 3 года назад

    Good video

  • @dablet
    @dablet 3 года назад +1

    how to set up alerts if instruder is in my network??? u didnt mention anything about that

  • @pooriapirhayati6798
    @pooriapirhayati6798 3 года назад

    i want to learn every thing about honeypot what should i read or see?can you introduce some thing?

  • @familyinJeddah
    @familyinJeddah 5 лет назад

    Cool!!!

  • @jeromewhite2946
    @jeromewhite2946 3 года назад

    having some issues with my emails and devices, find these hackers are so annoying! have gone through multibed devices and emails at this stage, apart from protecting with 2fa, could you advise any major deterrents? im exhausted at this stage and would sincerely welcome any help!

  • @sudeyuksek8379
    @sudeyuksek8379 2 года назад +1

    Could you please make video about intalling tpot on virtual machine with tpot iso. I have been facing some problems for a week I couldn't make it. Especially I want to learn installation of the latest version tpot.

  • @hassenzayani2882
    @hassenzayani2882 3 года назад

    please help , after installing i can't open the web interface ..

  • @vigneshsiva4471
    @vigneshsiva4471 3 года назад +1

    The github link is giving an error 404 page not found .Can you send the github link again .

  • @fortuneodesanya
    @fortuneodesanya 3 года назад

    How do I implement this on Windows on-prem servers?

  • @shailendraverma1675
    @shailendraverma1675 3 года назад

    When installing it says debain bionic is not supported please help

  • @cosminwheelz2597
    @cosminwheelz2597 2 месяца назад

    page is not found. Do you have an updated link by any chance?

  • @dodonohoe30
    @dodonohoe30 3 года назад +1

    Great video!! Can this be deplyed in Azure?
    Also does it work best on Ubuntu or Debian, does it make a difference?

    • @stan464
      @stan464 3 года назад +2

      I had issues running on Ubuntu. it states the "Aborting. Debian focal is not supported."

  • @ashutoshguleria3921
    @ashutoshguleria3921 2 года назад

    my kibana dashboard is not opening ...any explanations????

  • @mutarusheitijani7331
    @mutarusheitijani7331 4 года назад

    I HAVE DONE THE UPDATE AND UPGRADE BUT STILL HAVE THE ISSUES

  • @abidasamia2380
    @abidasamia2380 5 лет назад +2

    Why does my ubuntu tell me the E: Package 'netselect-apt' has no installation candidate ? It aborts the download and it tells me the Debian xenial is not supported ? What do i do now?

    • @Xandro69
      @Xandro69 4 года назад +2

      I also experienced this. I found out that Ubuntu doesn't support tpot anymore. I don't know which platform supports it either. Tried debian 10 and kali linux 2018 & 19 and still got the same issue

  • @MoveForwardEveryday
    @MoveForwardEveryday 5 лет назад +3

    🐝 looking for that

  • @supermike3852
    @supermike3852 5 лет назад

    Can we still install in Ubuntu? I read the document that should install on Debian 9.X

    • @ste1747
      @ste1747 3 года назад +1

      ubuntu is a fork of deb.

  • @thenightstreamer4702
    @thenightstreamer4702 Год назад

    So are attackers getting into the actual network through a honeypot or is an isolated from the real network? Are attackers getting real information or falsified information that appears to be real?

  • @Red_Hot_Little_Pepper_Pupper
    @Red_Hot_Little_Pepper_Pupper Год назад

    not sure if you will see this one, but when trying to install both in ubuntu and kali, it says "aborting, debian jammy/kali is not supported" I have not been able to find a solution.

  • @axriogrey2415
    @axriogrey2415 4 года назад +2

    great video! very interesting! Which version of Ubuntu does tpotce run on? is there any other platform besides Ubuntu for it to run on?

    • @ITSecurityLabs
      @ITSecurityLabs  4 года назад +1

      Axrio Grey Ubuntu 16 or 18 should work.

    • @mitch2764
      @mitch2764 3 года назад +3

      @@ITSecurityLabs 20.04 doesn't work, fyi.

  • @ashapatel3204
    @ashapatel3204 4 года назад

    how to install honeyd in unubtu

  • @hotsince84
    @hotsince84 4 года назад +5

    But I'm also interested about what they doing and how they doing it. For example, when they bruteforce the ssh server, or doing SQL Injections, what commands they are using, what they're downloading (exploits, tools, etc). Is this capable of displaying these? Maybe a realtime view of their shell ?

    • @Okseje123
      @Okseje123 2 года назад

      Hey Cthulhu, did you find out if it was capable of this and if not what did you do?

    • @g-nice_pimp
      @g-nice_pimp 2 года назад +1

      I think for that you should be able to hookup the servers access logs, so you can see brute force attempts

    • @t58beare
      @t58beare 2 года назад

      You could always use an OSSIM, this would show a lot of information.

  • @user-wl7kh2bj5x
    @user-wl7kh2bj5x 4 года назад +2

    hello, while installing I got this error E: Package 'netselect-apt' has no installation candidate
    Package manager quit with exit code.
    Aborting. Debian bionic is not supported.
    what am i suppose to do? The Ubuntu is in Vmware Workstation

    • @ITSecurityLabs
      @ITSecurityLabs  4 года назад

      Maybe the packages do not work anymore. I have not updated mine but i will let you know if i find a solution.

    • @user-wl7kh2bj5x
      @user-wl7kh2bj5x 4 года назад

      @@ITSecurityLabs Yeah please do suggest as i was learning to install honeypot.if any other alternatives do suggest

  • @dude244342
    @dude244342 4 года назад +1

    ubuntu should use APT though right not YUM 5:27

  • @jeffersonc.briones7223
    @jeffersonc.briones7223 4 года назад +3

    Working... this may take a while.
    E: Package 'netselect-apt' has no installation candidate
    Package manager quit with exit code.
    Aborting. Debian bionic is not supported.
    im having this error on my ubuntu 18.04

    • @moko2511
      @moko2511 4 года назад +1

      TPot now runs on Debian 10 Buster, maybe you have to update.

  • @R4YW4R
    @R4YW4R 2 года назад

    Hi, I bought a coin but I can't sell it, they told me it could be a honeypot, I could get my money back or nothing

  • @BvG-ck2ry
    @BvG-ck2ry 3 года назад +4

    I did exactly what the video says, but in the last step I get an error: E: packadge ‘netselect-apt’ has no installation candidate. Packadge manager quit with exit code. Aborting. Debia focal is not supported.

    • @shailendraverma1675
      @shailendraverma1675 3 года назад +1

      Did your error resolved ??

    • @shailendraverma1675
      @shailendraverma1675 3 года назад +1

      Please help

    • @udayanbhakar
      @udayanbhakar 2 года назад

      Edit install.sh file under iso/installer/install.sh
      Change line 21 to
      myLSB_STABLE_SUPPORTED="stretch buster focal"
      It should work

  • @javibrooks8058
    @javibrooks8058 5 лет назад

    how connect tpot sensor with tpot collector on distributed environment

  • @IBITZEE
    @IBITZEE 4 года назад

    nice info...
    ?any honeypot for windows you recommend... foss if possible...

    • @LauweLeon
      @LauweLeon 3 года назад +1

      install virtualbox and then install TPOT

    • @abdelkadertibeoui2344
      @abdelkadertibeoui2344 3 года назад +1

      @@LauweLeon i have some difficulties for configuration tpot on virtualbox
      you can help me sir ?

  • @haythamalhsous6945
    @haythamalhsous6945 5 лет назад +1

    How can i delete logs from tpot?

    • @carloskombo2967
      @carloskombo2967 4 года назад

      Sorry, I was wondering how to see the logs? I couldn't understand that part. I used honeyD. I discovered this tool now.

  • @stephanomarku9915
    @stephanomarku9915 4 года назад

    while installing I got this error E: Package 'netselect-apt' has no installation candidate
    Is there any workaround for this and how did you implement it in the cloud? badly need your help for this one. Awesome content btw! defo subscribing.

    • @yogeshdasari
      @yogeshdasari 4 года назад

      Hey Stephano, even i got the same issue E: Package 'netselect-apt' has no installation candidate
      . Aborting Debian eoan is not supported. If u get any resolution request me to help me out to get into.

    • @shailendraverma1675
      @shailendraverma1675 3 года назад

      @@yogeshdasari same error mate did you resolved it

    • @t58beare
      @t58beare 2 года назад

      @@shailendraverma1675 Install on a Debian distribution.

    • @kelechigodwin9724
      @kelechigodwin9724 2 года назад

      @@t58beare i tried using the lastest version of ubuntu 2022 and it is saying Debian Jammy is not supported. can you help me out here

  • @steven3469
    @steven3469 21 день назад

    sir your github link is dead.Could you share it again? Thanks in advance.

  • @haris5851
    @haris5851 2 года назад

    How sell koin honey pot, i'm buyy koin but not sell, please help me 😭😭😭😭 ?

  • @carloskombo2967
    @carloskombo2967 4 года назад +4

    I am doing my final year work at the university where I will use the T-Pot. Is it possible for me to simulate attacks?
    And in case where do I see the logs generated from all attacks?

    • @carloskombo2967
      @carloskombo2967 4 года назад

      Sorry for the questions, maybe so obvious to you, is that I was going to use the honeyD tool but I ended up changing it and found this news here, and I want to use it to solve my final course problem

    • @ITSecurityLabs
      @ITSecurityLabs  4 года назад

      Yes, you can simulate attacks. Set up the lab like i show you here : ruclips.net/video/57Da4uVdoiM/видео.html

    • @ITSecurityLabs
      @ITSecurityLabs  4 года назад

      Launch attacks from Kali towards your tport .

    • @carloskombo2967
      @carloskombo2967 4 года назад

      @@ITSecurityLabs Thanks for answering and for the tips. I will watch this other video from the link.
      But two questions to finish: The ip that T-POT uses to receive all these attacks is the local ip or the external / public ip?
      To simulate attacks towards him as you said, using kali linux, use the external / public ip too or the local ip?

    • @gitanjaliravichandran9329
      @gitanjaliravichandran9329 Год назад

      @carloskombo2967 Hello, I am doing my project on cloud security using honeypots and I need to simulate attacks. Did you manage to simulate attacks in your case?

  • @blackcipher8765
    @blackcipher8765 5 лет назад

    Hi Thank you for this!
    Just want to ask is it only work on Debian linux?
    thanks more power!

    • @ITSecurityLabs
      @ITSecurityLabs  5 лет назад +1

      I have not seen it deployed on other distributions. Looks like this is the easiest way.

  • @jiro_hartts
    @jiro_hartts 2 года назад +1

    can I install that honeypot on a raspberry pi 3?

  • @sorensd
    @sorensd 5 лет назад +2

    Wakanda Forever!

  • @dbxyzoo
    @dbxyzoo 5 лет назад +6

    No longer works with Ubuntu by the looks of things, debian only

    • @andrezao1991
      @andrezao1991 4 года назад +1

      Should put this comment on top....

  • @pickoworkerofficialchannel1065
    @pickoworkerofficialchannel1065 2 года назад

    Well

  • @pebrialkautsar8692
    @pebrialkautsar8692 4 года назад +1

    Hello, I'm sorry for disturbing you ;((. I have some problems with my project..
    I never use honeypot before. But, I have a task from my lecture, that I should use honeypot for detecting hackers attacks..
    I searching for many journals, tutorials and articles. I tried using the honeydrive3 and used the honeypot Kippo. When I tried that, and I attack by myself, it works, the detailed of attack is served ... But, when I told that to my lecture, he said it was not what he want...
    The workflow he want is, we use the honeypot and then we try that to some websites.. But, when the attacker scanning or do something to that web ip address, it must deflect to the honeypot, it means that the attacker really attacks the real website.. and I really don't know what to do ;( It's the first time for me and I didn't know anything, I never see the tutorial or something that helps ... can you help me please???I really thankfull if you help mee.. I know I'm bad ;(((

  • @Ace_Galton
    @Ace_Galton 11 месяцев назад +1

    could barely hear you bro... cranked up volume to max then got blown away by a loud advert (lol)

  • @fordsrmaster
    @fordsrmaster 9 месяцев назад

    the link is no longer valid

  • @mikekyto
    @mikekyto 4 года назад +1

    Can I run it on my PI?

    • @ITSecurityLabs
      @ITSecurityLabs  4 года назад

      Kiromatsu I think so. Let me know if it works because I would like to try it as well

  • @oladimejimichaeloloyede7203
    @oladimejimichaeloloyede7203 4 года назад +1

    Nice job!! how do I send you a private message?

    • @ITSecurityLabs
      @ITSecurityLabs  4 года назад +1

      Send me an email to lmakonem@gmail.com

  • @rinusgroenendael3020
    @rinusgroenendael3020 4 года назад +4

    Github gives me a 404 :( , can you re-upload?

  • @animeannihilator4534
    @animeannihilator4534 2 года назад

    cool fact, honeypot is also the name of a porta potty.

  • @davidg4512
    @davidg4512 5 лет назад

    Typo in the title?

  • @ChristopherCompagnon1AndOnly
    @ChristopherCompagnon1AndOnly 3 года назад +1

    8 GB of RAM!!!!!
    You kidding !

  • @danielfu3884
    @danielfu3884 3 года назад +1

    There is a NEW Version available of tpot

    • @ITSecurityLabs
      @ITSecurityLabs  3 года назад +1

      Daniel Fu that’s awesome. I tried it a few weeks ago in azure

    • @danielfu3884
      @danielfu3884 3 года назад +1

      @@ITSecurityLabs i check it with greenbone a open Source security scanner

    • @ITSecurityLabs
      @ITSecurityLabs  3 года назад +1

      Daniel Fu I am a big fan of this project

  • @Vermino
    @Vermino 3 года назад

    FBI sent me here.

  • @hidayatbachtar
    @hidayatbachtar 2 года назад

    why i got this error?
    Aborting. Debian focal is not supported.

    • @ITSecurityLabs
      @ITSecurityLabs  2 года назад

      I think they changed things a little bit. I will create another one soon

    • @hidayatbachtar
      @hidayatbachtar 2 года назад

      @@ITSecurityLabs thats works well when i installed iso version

  • @ABehrooz
    @ABehrooz 5 лет назад

    That event histogram distribution is so hurtful to watch. Everything else is great.

    • @ITSecurityLabs
      @ITSecurityLabs  5 лет назад

      I powered off the machine and started it 24 hours later, thats why the histogram looks weird.

  • @Andres-wq6cz
    @Andres-wq6cz 4 года назад

    g

  • @derob3rst440
    @derob3rst440 4 года назад

    lol script kiddy hour

  • @davidpecoraro194
    @davidpecoraro194 2 года назад

    Great video. Can you explain how to set up PFsense to allow for a configuration in front of your firewall? I would like to set up tpot to receive pertinent internet traffic. Are there a list of ports to forward to tpot or a configuration setup in PFsense?