SSH Honeypot in 4 Minutes - Trap Hackers in Your Server

Поділитися
Вставка
  • Опубліковано 12 жов 2020
  • In this video I'll show you a funny way to protect your SSH server from hackers, script kiddies and Chinese botnets, using Endlessh by Chris Wellons
    Endlessh (GitHub): github.com/skeeto/endlessh
    Support the channel:
    Patreon / wolfgangschannel
    PayPal (one time donation) www.paypal.com/donate/?hosted...
    Follow me:
    Twitter / notthebeeee
    GitHub github.com/notthebee
    Music:
    A.M. Beef - Takama no Hara
    Ian Post - Electricity

КОМЕНТАРІ • 1,1 тис.

  • @WolfgangsChannel
    @WolfgangsChannel  3 роки тому +598

    Please note that Endlessh is NOT meant to replace conventional SSH security methods. You should still set up public-key only authentication and 2FA, as well as tools like iptables, fail2ban and CrowdSec

  • @epic_baller123
    @epic_baller123 3 роки тому +7

    silly question. Couldn't you just do an nmap scan and figure out the actual port is 69?

  • @NithinJune
    @NithinJune 3 роки тому +851

    You should just have the banner be the bee movie script

  • @matthewmarkose
    @matthewmarkose 3 роки тому +1

    You're video is straight to the point and doesn't waste my time to increase your channel view time. Thank you.

  • @ss-xy2im
    @ss-xy2im 3 роки тому +285

    Don't run it on a production server or u might end up with 20k simultaneous ssh connections

  • @AVINIDE
    @AVINIDE 3 роки тому +152

    2/10 no actual bonk meme included

  • @youp1tralala
    @youp1tralala 3 роки тому +377

    Amusing, but I would rather setup fail2ban, as your real ssh server can still be hammered. Or do both

  • @0ldenn
    @0ldenn 3 роки тому +183

    This is the least efficient way of "protecting" an SSH server I have ever seen, but also the funniest without a doubt

  • @agentbarron3945
    @agentbarron3945 3 роки тому +35

    Wow a 5 minute video with 5 minutes of solid information. Not a 11 minute video with 2 minutes of eh information. You just earned yourself a sub and a spot on my whitelist, something very very few UA-camrs get from me.

  • @GreenLinuxPenguin
    @GreenLinuxPenguin 3 роки тому +141

    I think in addition to changing your real SSH port, I would also say setting up the SSH server to only accept keys for login would be the next step

  • @mulllhausen
    @mulllhausen 3 роки тому +33

    scripts will just adapt to close the connection after 10 second timeout and try another port

  • @colfaxschuyler3675
    @colfaxschuyler3675 3 роки тому +420

    I need to know: how often do we have to open the server up to let the trapped hackers out?

  • @DanielStinebaugh
    @DanielStinebaugh 3 роки тому +31

    Love this! There's a simple docker package as well in the docker hub, so quick to deploy! Thanks for bringing this project to me! Such a simple and powerful tarpit!!!

  • @Fregmazors
    @Fregmazors 2 роки тому +10

    I've been setting up a game server, and I am TOTALLY DOING THIS. Thank you so much for making this video! It never occurred to me to have a 'false front' ssh login, and making it a time sink is a brilliant approach.

  • @gnuPirate
    @gnuPirate 2 роки тому +1

    This is such a fantastic channel. Very well produced. Thanks Wolfgang.

  • @HarryBallsOnYa345
    @HarryBallsOnYa345 3 роки тому +73

    I honestly love mitigation techniques like this one; they are simple, effective, and feel a bit trolly ;)

  • @naoltitude9516
    @naoltitude9516 3 роки тому +38

    Damn I actually love Wolfgang's desk setup so much

  • @ericmasson7462
    @ericmasson7462 3 роки тому +13

    moving your SSHD to another port is a good practice, however a simple nmap on your IP will reveal it. Real hacker's script usually does a kind of nmap to list possible vulnerabilities. Good video

  • @Belgarathe
    @Belgarathe 3 роки тому +1

    Thanks for sharing this is pretty cool. True someone can script a timeout but the thought of slowing down even for 15 seconds seem to be worth it.

  • @eduardocarmona9660
    @eduardocarmona9660 3 роки тому +1

    Dude your content is great, so glad i'm subscribed, keep it up ! :)