What is a honeypot, How to install and what can we see from honeypots?

Поділитися
Вставка
  • Опубліковано 20 гру 2024

КОМЕНТАРІ •

  • @papajohnscookie
    @papajohnscookie 3 роки тому +3

    This is great, I don't know why I never of thought of running one in the cloud just for curiosities sake

  • @davidpecoraro194
    @davidpecoraro194 2 роки тому +3

    Great video. Can you explain how to set up PFsense to allow for a configuration in front of your firewall? I would like to set up tpot to receive pertinent internet traffic. Are there a list of ports to forward to tpot or a configuration setup in PFsense?

  • @willhikeforfood3272
    @willhikeforfood3272 5 років тому +17

    Very nice (from one I.T. person to another). Keep up the great work!

  • @R4YW4R
    @R4YW4R 2 роки тому

    Hi, I bought a coin but I can't sell it, they told me it could be a honeypot, I could get my money back or nothing

  • @BvG-ck2ry
    @BvG-ck2ry 4 роки тому +4

    I did exactly what the video says, but in the last step I get an error: E: packadge ‘netselect-apt’ has no installation candidate. Packadge manager quit with exit code. Aborting. Debia focal is not supported.

    • @shailendraverma1675
      @shailendraverma1675 3 роки тому +1

      Did your error resolved ??

    • @shailendraverma1675
      @shailendraverma1675 3 роки тому +1

      Please help

    • @udayanbhakar
      @udayanbhakar 2 роки тому

      Edit install.sh file under iso/installer/install.sh
      Change line 21 to
      myLSB_STABLE_SUPPORTED="stretch buster focal"
      It should work

  • @dablet
    @dablet 4 роки тому +1

    how to set up alerts if instruder is in my network??? u didnt mention anything about that

  • @hotsince84
    @hotsince84 4 роки тому +5

    But I'm also interested about what they doing and how they doing it. For example, when they bruteforce the ssh server, or doing SQL Injections, what commands they are using, what they're downloading (exploits, tools, etc). Is this capable of displaying these? Maybe a realtime view of their shell ?

    • @Okseje123
      @Okseje123 3 роки тому

      Hey Cthulhu, did you find out if it was capable of this and if not what did you do?

    • @g-nice_pimp
      @g-nice_pimp 2 роки тому +1

      I think for that you should be able to hookup the servers access logs, so you can see brute force attempts

    • @t58beare
      @t58beare 2 роки тому

      You could always use an OSSIM, this would show a lot of information.

  • @cosminwheelz2597
    @cosminwheelz2597 7 місяців тому

    page is not found. Do you have an updated link by any chance?

  • @sudeyuksek8379
    @sudeyuksek8379 2 роки тому +1

    Could you please make video about intalling tpot on virtual machine with tpot iso. I have been facing some problems for a week I couldn't make it. Especially I want to learn installation of the latest version tpot.

  • @brianturney2124
    @brianturney2124 2 роки тому +1

    Super cool. I set this up on AWS and it works great. I havent opened up all the ports yet in the documentation did you open up every port or just enough to make the web page load?

  • @radityawaliulu
    @radityawaliulu 4 роки тому

    Hi, about timing 7:28 to 7:40 is it auto binding port?
    then, is it secure about port opened even for honeypot or honeytrap

  • @davidreichert6376
    @davidreichert6376 2 роки тому

    your videos are very good and have a wide message thank you

  • @davidamigos.davidamigosnwa4522
    @davidamigos.davidamigosnwa4522 8 місяців тому

    excellent thanks. Keep up the great work.

  • @abidasamia2380
    @abidasamia2380 5 років тому +2

    Why does my ubuntu tell me the E: Package 'netselect-apt' has no installation candidate ? It aborts the download and it tells me the Debian xenial is not supported ? What do i do now?

    • @Xandro69
      @Xandro69 5 років тому +2

      I also experienced this. I found out that Ubuntu doesn't support tpot anymore. I don't know which platform supports it either. Tried debian 10 and kali linux 2018 & 19 and still got the same issue

  • @ashutoshguleria3921
    @ashutoshguleria3921 2 роки тому

    my kibana dashboard is not opening ...any explanations????

  • @vigneshsiva4471
    @vigneshsiva4471 4 роки тому +1

    The github link is giving an error 404 page not found .Can you send the github link again .

  • @潘凡雯SHAIKRESHMAPARVEENQ36
    @潘凡雯SHAIKRESHMAPARVEENQ36 4 роки тому +2

    hello, while installing I got this error E: Package 'netselect-apt' has no installation candidate
    Package manager quit with exit code.
    Aborting. Debian bionic is not supported.
    what am i suppose to do? The Ubuntu is in Vmware Workstation

    • @ITSecurityLabs
      @ITSecurityLabs  4 роки тому

      Maybe the packages do not work anymore. I have not updated mine but i will let you know if i find a solution.

    • @潘凡雯SHAIKRESHMAPARVEENQ36
      @潘凡雯SHAIKRESHMAPARVEENQ36 4 роки тому

      @@ITSecurityLabs Yeah please do suggest as i was learning to install honeypot.if any other alternatives do suggest

  • @dude244342
    @dude244342 5 років тому +1

    ubuntu should use APT though right not YUM 5:27

  • @jeffersonc.briones7223
    @jeffersonc.briones7223 5 років тому +3

    Working... this may take a while.
    E: Package 'netselect-apt' has no installation candidate
    Package manager quit with exit code.
    Aborting. Debian bionic is not supported.
    im having this error on my ubuntu 18.04

    • @moko2511
      @moko2511 5 років тому +1

      TPot now runs on Debian 10 Buster, maybe you have to update.

  • @hassenzayani2882
    @hassenzayani2882 3 роки тому

    please help , after installing i can't open the web interface ..

  • @danielfu3884
    @danielfu3884 4 роки тому +1

    Perfect Honeypot Video 👍

  • @user-uw1wq9rj8g
    @user-uw1wq9rj8g 4 роки тому +1

    Amazing explanation, thanks for sharing the knowledge

  • @shailendraverma1675
    @shailendraverma1675 3 роки тому

    When installing it says debain bionic is not supported please help

  • @slfonden4753
    @slfonden4753 6 років тому +2

    Thanks for another great video

  • @steven3469
    @steven3469 5 місяців тому

    sir your github link is dead.Could you share it again? Thanks in advance.

  • @pooriapirhayati6798
    @pooriapirhayati6798 4 роки тому

    i want to learn every thing about honeypot what should i read or see?can you introduce some thing?

  • @bernardasareasante4355
    @bernardasareasante4355 4 роки тому

    Please do you have any tutorials on installation of capture-HPC ?

  • @prestigedps7435
    @prestigedps7435 4 роки тому

    Can you advise what version of Ubuntu and the direct edition you are using. Currently i created my own ISO and installing a Debian stretch edition. it seems TPOT only supports older Debian stretch SID editions . if you cat /etc/Debian_version on the latest Ubuntu LTS it shows buster. Install fails

  • @yarekzethiopia9050
    @yarekzethiopia9050 5 років тому +3

    it's nice tutorial what is next after getting honeypot log data and related with cyber intelligence

  • @jeromewhite2946
    @jeromewhite2946 3 роки тому

    having some issues with my emails and devices, find these hackers are so annoying! have gone through multibed devices and emails at this stage, apart from protecting with 2fa, could you advise any major deterrents? im exhausted at this stage and would sincerely welcome any help!

  • @thenightstreamer4702
    @thenightstreamer4702 2 роки тому

    So are attackers getting into the actual network through a honeypot or is an isolated from the real network? Are attackers getting real information or falsified information that appears to be real?

  • @dbxyzoo
    @dbxyzoo 5 років тому +6

    No longer works with Ubuntu by the looks of things, debian only

    • @andrezao1991
      @andrezao1991 5 років тому +1

      Should put this comment on top....

  • @jiro_hartts
    @jiro_hartts 3 роки тому +1

    can I install that honeypot on a raspberry pi 3?

  • @axriogrey2415
    @axriogrey2415 5 років тому +2

    great video! very interesting! Which version of Ubuntu does tpotce run on? is there any other platform besides Ubuntu for it to run on?

    • @ITSecurityLabs
      @ITSecurityLabs  5 років тому +1

      Axrio Grey Ubuntu 16 or 18 should work.

    • @mitch2764
      @mitch2764 4 роки тому +3

      @@ITSecurityLabs 20.04 doesn't work, fyi.

  • @fortuneodesanya
    @fortuneodesanya 3 роки тому

    How do I implement this on Windows on-prem servers?

  • @orca2162
    @orca2162 4 роки тому +1

    Great stuff, thank you!

  • @mutarusheitijani7331
    @mutarusheitijani7331 4 роки тому

    I HAVE DONE THE UPDATE AND UPGRADE BUT STILL HAVE THE ISSUES

  • @carloskombo2967
    @carloskombo2967 5 років тому +4

    I am doing my final year work at the university where I will use the T-Pot. Is it possible for me to simulate attacks?
    And in case where do I see the logs generated from all attacks?

    • @carloskombo2967
      @carloskombo2967 5 років тому

      Sorry for the questions, maybe so obvious to you, is that I was going to use the honeyD tool but I ended up changing it and found this news here, and I want to use it to solve my final course problem

    • @ITSecurityLabs
      @ITSecurityLabs  5 років тому

      Yes, you can simulate attacks. Set up the lab like i show you here : ua-cam.com/video/57Da4uVdoiM/v-deo.html

    • @ITSecurityLabs
      @ITSecurityLabs  5 років тому

      Launch attacks from Kali towards your tport .

    • @carloskombo2967
      @carloskombo2967 5 років тому

      @@ITSecurityLabs Thanks for answering and for the tips. I will watch this other video from the link.
      But two questions to finish: The ip that T-POT uses to receive all these attacks is the local ip or the external / public ip?
      To simulate attacks towards him as you said, using kali linux, use the external / public ip too or the local ip?

    • @gitanjaliravichandran9329
      @gitanjaliravichandran9329 Рік тому

      @carloskombo2967 Hello, I am doing my project on cloud security using honeypots and I need to simulate attacks. Did you manage to simulate attacks in your case?

  • @dodonohoe30
    @dodonohoe30 3 роки тому +1

    Great video!! Can this be deplyed in Azure?
    Also does it work best on Ubuntu or Debian, does it make a difference?

    • @stan464
      @stan464 3 роки тому +2

      I had issues running on Ubuntu. it states the "Aborting. Debian focal is not supported."

  • @IBITZEE
    @IBITZEE 4 роки тому

    nice info...
    ?any honeypot for windows you recommend... foss if possible...

    • @LauweLeon
      @LauweLeon 4 роки тому +1

      install virtualbox and then install TPOT

    • @abdelkadertibeoui2344
      @abdelkadertibeoui2344 3 роки тому +1

      @@LauweLeon i have some difficulties for configuration tpot on virtualbox
      you can help me sir ?

  • @Bossa_Fenzi
    @Bossa_Fenzi Рік тому

    could barely hear you bro... cranked up volume to max then got blown away by a loud advert (lol)

  • @haythamalhsous6945
    @haythamalhsous6945 5 років тому +1

    How can i delete logs from tpot?

    • @carloskombo2967
      @carloskombo2967 5 років тому

      Sorry, I was wondering how to see the logs? I couldn't understand that part. I used honeyD. I discovered this tool now.

  • @haris5851
    @haris5851 3 роки тому

    How sell koin honey pot, i'm buyy koin but not sell, please help me 😭😭😭😭 ?

  • @supermike3852
    @supermike3852 5 років тому

    Can we still install in Ubuntu? I read the document that should install on Debian 9.X

    • @ste1747
      @ste1747 4 роки тому +1

      ubuntu is a fork of deb.

  • @ashapatel3204
    @ashapatel3204 4 роки тому

    how to install honeyd in unubtu

  • @stephanomarku9915
    @stephanomarku9915 4 роки тому

    while installing I got this error E: Package 'netselect-apt' has no installation candidate
    Is there any workaround for this and how did you implement it in the cloud? badly need your help for this one. Awesome content btw! defo subscribing.

    • @yogeshdasari
      @yogeshdasari 4 роки тому

      Hey Stephano, even i got the same issue E: Package 'netselect-apt' has no installation candidate
      . Aborting Debian eoan is not supported. If u get any resolution request me to help me out to get into.

    • @shailendraverma1675
      @shailendraverma1675 3 роки тому

      @@yogeshdasari same error mate did you resolved it

    • @t58beare
      @t58beare 2 роки тому

      @@shailendraverma1675 Install on a Debian distribution.

    • @kelechigodwin9724
      @kelechigodwin9724 2 роки тому

      @@t58beare i tried using the lastest version of ubuntu 2022 and it is saying Debian Jammy is not supported. can you help me out here

  • @sorensd
    @sorensd 6 років тому +2

    Wakanda Forever!

  • @fordsrmaster
    @fordsrmaster Рік тому

    the link is no longer valid

  • @oladimejimichaeloloyede7203
    @oladimejimichaeloloyede7203 4 роки тому +1

    Nice job!! how do I send you a private message?

  • @mikekyto
    @mikekyto 5 років тому +1

    Can I run it on my PI?

    • @ITSecurityLabs
      @ITSecurityLabs  5 років тому

      Kiromatsu I think so. Let me know if it works because I would like to try it as well

  • @pebrialkautsar8692
    @pebrialkautsar8692 4 роки тому +1

    Hello, I'm sorry for disturbing you ;((. I have some problems with my project..
    I never use honeypot before. But, I have a task from my lecture, that I should use honeypot for detecting hackers attacks..
    I searching for many journals, tutorials and articles. I tried using the honeydrive3 and used the honeypot Kippo. When I tried that, and I attack by myself, it works, the detailed of attack is served ... But, when I told that to my lecture, he said it was not what he want...
    The workflow he want is, we use the honeypot and then we try that to some websites.. But, when the attacker scanning or do something to that web ip address, it must deflect to the honeypot, it means that the attacker really attacks the real website.. and I really don't know what to do ;( It's the first time for me and I didn't know anything, I never see the tutorial or something that helps ... can you help me please???I really thankfull if you help mee.. I know I'm bad ;(((

  • @blackcipher8765
    @blackcipher8765 5 років тому

    Hi Thank you for this!
    Just want to ask is it only work on Debian linux?
    thanks more power!

    • @ITSecurityLabs
      @ITSecurityLabs  5 років тому +1

      I have not seen it deployed on other distributions. Looks like this is the easiest way.

  • @javibrooks8058
    @javibrooks8058 5 років тому

    how connect tpot sensor with tpot collector on distributed environment

  • @danielfu3884
    @danielfu3884 4 роки тому +1

    There is a NEW Version available of tpot

    • @ITSecurityLabs
      @ITSecurityLabs  4 роки тому +1

      Daniel Fu that’s awesome. I tried it a few weeks ago in azure

    • @danielfu3884
      @danielfu3884 4 роки тому +1

      @@ITSecurityLabs i check it with greenbone a open Source security scanner

    • @ITSecurityLabs
      @ITSecurityLabs  4 роки тому +1

      Daniel Fu I am a big fan of this project

  • @rinusgroenendael3020
    @rinusgroenendael3020 5 років тому +4

    Github gives me a 404 :( , can you re-upload?

  • @MoveForwardEveryday
    @MoveForwardEveryday 5 років тому +3

    🐝 looking for that

  • @stevecross9159
    @stevecross9159 4 роки тому

    Good video

  • @Yvtq8K3n
    @Yvtq8K3n 4 роки тому

    Very nice:)

  • @hidayatbachtar
    @hidayatbachtar 2 роки тому

    why i got this error?
    Aborting. Debian focal is not supported.

    • @ITSecurityLabs
      @ITSecurityLabs  2 роки тому

      I think they changed things a little bit. I will create another one soon

    • @hidayatbachtar
      @hidayatbachtar 2 роки тому

      @@ITSecurityLabs thats works well when i installed iso version

  • @animeannihilator4534
    @animeannihilator4534 3 роки тому

    cool fact, honeypot is also the name of a porta potty.

  • @davidg4512
    @davidg4512 6 років тому

    Typo in the title?

  • @familyinJeddah
    @familyinJeddah 5 років тому

    Cool!!!

  • @ChristopherCompagnon1AndOnly
    @ChristopherCompagnon1AndOnly 4 роки тому +1

    8 GB of RAM!!!!!
    You kidding !

  • @pickoworkerofficialchannel1065
    @pickoworkerofficialchannel1065 2 роки тому

    Well

  • @ABehrooz
    @ABehrooz 6 років тому

    That event histogram distribution is so hurtful to watch. Everything else is great.

    • @ITSecurityLabs
      @ITSecurityLabs  5 років тому

      I powered off the machine and started it 24 hours later, thats why the histogram looks weird.

  • @Vermino
    @Vermino 3 роки тому

    FBI sent me here.

  • @Andres-wq6cz
    @Andres-wq6cz 5 років тому

    g

  • @derob3rst440
    @derob3rst440 5 років тому

    lol script kiddy hour

  • @Red_Hot_Little_Pepper_Pupper

    not sure if you will see this one, but when trying to install both in ubuntu and kali, it says "aborting, debian jammy/kali is not supported" I have not been able to find a solution.

  • @davidpecoraro194
    @davidpecoraro194 2 роки тому

    Great video. Can you explain how to set up PFsense to allow for a configuration in front of your firewall? I would like to set up tpot to receive pertinent internet traffic. Are there a list of ports to forward to tpot or a configuration setup in PFsense?