Setting Up a Honeypot in AWS and Analyzing Cyber Attacks (Check pinned comment for 2022 update)

Поделиться
HTML-код
  • Опубликовано: 18 фев 2022
  • IMPORTANT UPDATE: Due to the honeypot github repo being updated you will need to use Debian 11 instead of Debian 10 now when you set up your AWS instance!
    This video will show you how to set up a honeypot in AWS and analyze REAL attacks using it. Throughout the course of this video you will learn more about AWS and cybersecurity. You might also learn a thing or two about the methods attackers use to breach into our system.
    Equipment:
    Microphone: amzn.to/45dfANz
    Audio Interface: amzn.to/3PrncG6
    Webcam: amzn.to/48kyBQz
    Keyboard: amzn.to/44S0Ljf
    Mouse: amzn.to/3PGEnoA

Комментарии • 42

  • @katrintchernev33
    @katrintchernev33 2 года назад +4

    Thank for the video Ryan!

  • @alicemary1234
    @alicemary1234 Год назад +2

    This is such a sick walkthrough. Thanks so much for sharing it! Would be good to get a guide on setting up VMs in VirtualBox. I did this myself in the end but it was moderately painful :D

  • @kwesihenry5583
    @kwesihenry5583 Год назад +1

    Yo! Thank you for this. I’m going to make a few tweaks and make a blog post on this.

    • @cybergoldenretriever
      @cybergoldenretriever  Год назад

      Awesome!! Link your blog post when you’re done, I’d love to see what you find!

  • @amarachiukor4016
    @amarachiukor4016 2 года назад +2

    Thank you for sharing this

  • @g1kster725
    @g1kster725 Год назад +2

    PowerShell7 supports ssh btw. Also WSL is a good option.

  • @roliramos1
    @roliramos1 5 месяцев назад +1

    Can you make a follow up as to why after shutting down the instance many of us are not able to get back into T-Pot. Appreciate it in advance.

  • @Jayohkay
    @Jayohkay Месяц назад

    No matter what I do I keep getting connection refused when trying to SSH into the machine for the first time. It is 2024 so I use Debian 12
    1. I checked inbound rules and they are set correctly
    2. I tried to connect with another AWS instance and it still would not work
    3. I rebooted the instance and it did not work
    4. I ensured I had the private key and it confirms I have the right one, still refuses connections
    I am at a complete loss. Any help?

  • @cybergoldenretriever
    @cybergoldenretriever  2 года назад +3

    IMPORTANT UPDATE: Due to the honeypot github repo being updated you will need to use Debian 11 instead of Debian 10 now when you set up your AWS instance! If you do not do this you might get an error saying Debian buster is not supported.

    • @ferozhussain582
      @ferozhussain582 Год назад

      Hey Ryan!
      I have a very concerning issue:
      I have successfully installed T-Pot whilst connecting to my AWS instance via SSH client (Linux Virtual Machine).
      I can access the T-Pot dashboard, however I'm experiencing issues with accessing Kibana.
      Can you possibly help me or guide me towards fixing this issue? I have my project assignment due shortly, so an immediate response would be very appreciated!
      A huge thank you in advance! :)

  • @milicajevremovic1891
    @milicajevremovic1891 Год назад +1

    Nice

  • @Scotts_909
    @Scotts_909 Год назад

    Which IDS is used in intrusion detection?

  • @Scotts_909
    @Scotts_909 Год назад

    Does everything that’s written in the terminal exactly the same as the terminal in linux virtual machine ?

  • @handle-2
    @handle-2 Год назад

    The step at 21:51 , seems like I forgot the credentials, I tried a bunch of attempts and now it keeps on saying “unable to connect” and doesn’t prompt me to put in the credentials.
    Is there a way to reset the credentials 😭?

  • @ferozhussain582
    @ferozhussain582 Год назад

    Hey everyone!
    I have successfully installed T-Pot whilst connecting to my AWS instance via SSH client (Linux Virtual Machine).
    I can access the T-Pot dashboard, however I'm experiencing issues with accessing Kibana.
    Can anyone help me or guide me towards fixing this issue? I have my project assignment due shortly, so immediate responses would be very appreciated!
    Thank you in advance! :)

  • @yaswanththavanti3879
    @yaswanththavanti3879 2 года назад

    You set up a honeypot in Tokyo right, but why do you get a usa attacks?

  • @ninagee4511
    @ninagee4511 Месяц назад

    I don't get hit with that warning window in order to sign in 21:44

  • @nandualal5999
    @nandualal5999 Месяц назад

    Hey it isn't working for me?

  • @falconspy1668
    @falconspy1668 2 года назад +2

    Hello! I literally followed all the steps but when I try to access the web(ip:64297) , I get an error: "unable to connect.
    Firefox can't establish....".
    How do I fix this?

    • @cybergoldenretriever
      @cybergoldenretriever  2 года назад +1

      Hi Cherno! It could be a couple reasons:
      1) Make sure you have "" in front of the IP (https:ip:64297)
      2) Double check and make sure your VPN is off
      3) Use google or your command line to ensure you IP is correct
      4) If using a Virtual Machine, is that Virtual Machine using a NAT for its network interface card?
      5) Give your firewall rules a look over to ensure

    • @jefffitzpatrick3006
      @jefffitzpatrick3006 2 года назад

      @@cybergoldenretriever I've tried all of these steps but I'm getting the same error as well. Any ideas?

    • @jefffitzpatrick3006
      @jefffitzpatrick3006 2 года назад

      @@cybergoldenretriever never mind I got it working. Thanks for the video!

    • @francomazilu4815
      @francomazilu4815 Год назад

      @@jefffitzpatrick3006 Do you remember how you fixed it? I am in the same situation and I don't really know what to do

    • @raqueseharris
      @raqueseharris 2 месяца назад

      I have done all the steps correctly and trouble shot as well still getting refused to connect (ERR_CONNECTION_REFUSED) I am almost there can you please help

  • @nandualal5999
    @nandualal5999 Месяц назад

    Can anyone help😔

  • @talishgarg8492
    @talishgarg8492 2 года назад

    Hi, I'm getting the error, Sorry Debian Buster is not supported please help. I followed all the same steps

    • @SteadyOak
      @SteadyOak 2 года назад +4

      I was getting that too and I believe what I did to fix that was before ./install I had to ./update.sh -y and then it would work after that if I ran everything with sudo

    • @401unauthuser
      @401unauthuser 2 года назад

      @@SteadyOak thank you so much.

    • @cybergoldenretriever
      @cybergoldenretriever  2 года назад +1

      @@SteadyOak Thank you for helping them out!

  • @Scotts_909
    @Scotts_909 Год назад

    When i wanted to clone from github, it asked for username and password and then fails to clone. Could someone please help.

    • @Scotts_909
      @Scotts_909 Год назад

      Can someone please answer as soon as possible? I tried doing everything whats the issue?. Got an assignment and its due soon. Please help

    • @cybergoldenretriever
      @cybergoldenretriever  Год назад

      In order for you to use the "git clone" command you need to either have SSH setup through github or if you use HTTPS to clone you need to insert your username and password for github in order to do it

  • @partha4891
    @partha4891 Год назад

    Not able to connnect to port ssh 64295

    • @luckky5421
      @luckky5421 Год назад

      same here, after rebooted, unable to SSH on port 64295

  • @sudaphedz433
    @sudaphedz433 Год назад +1

    I'd just like to interject for a moment. What you're refering to as Linux, is in fact, GNU/Linux, or as I've recently taken to calling it, GNU plus Linux. Linux is not an operating system unto itself, but rather another free component of a fully functioning GNU system made useful by the GNU corelibs, shell utilities and vital system components comprising a full OS as defined by POSIX.
    Many computer users run a modified version of the GNU system every day, without realizing it. Through a peculiar turn of events, the version of GNU which is widely used today is often called Linux, and many of its users are not aware that it is basically the GNU system, developed by the GNU Project.
    There really is a Linux, and these people are using it, but it is just a part of the system they use. Linux is the kernel: the program in the system that allocates the machine's resources to the other programs that you run. The kernel is an essential part of an operating system, but useless by itself; it can only function in the context of a complete operating system. Linux is normally used in combination with the GNU operating system: the whole system is basically GNU with Linux added, or GNU/Linux. All the so-called Linux distributions are really distributions of GNU/Linux!

    • @busyrand
      @busyrand 3 месяца назад

      Thank you for the background on how things are pieces together. Linux and it's troubleshooting is rooted in understanding how all the pieces fit together.

  • @adonyz666
    @adonyz666 2 года назад +1

    fullstack