Cowrie是一种中等交互式SSH和Telet蜜罐,用于记录暴力攻击和攻击者执行的shell交互。Cowrie还充当SSH和telet代理,以观察攻击者对另一个系统的行为。
使用方法:
dockerru-p2222:2222cowrie/cowriessh-p2222root@localhost文件列表:
etc/cowrie.cfg-Cowrie'scofiguratiofile.Defaultvaluescabefoudi etc/cowrie.cfg.dist.share/cowrie/fs.pickle-fakefilesystemetc/userdb.txt-credetialstoaccessthehoeypothoeyfs/ -filecotetsforthefakefilesystem-feelfreetocopyarealsystemhereorusebi/fsctlhoeyfs/etc/issue.et-pre-logibaerhoeyfs/etc/motd -post-logibaervar/log/cowrie/cowrie.jso-trasactiooutputiJSONformatvar/log/cowrie/cowrie.log-log/debugoutputvar/lib/cowrie/tty/-sessiologs,replayablewiththebi/playlogutility.var/lib/cowrie/dowloads/-filestrasferredfromtheattackertothehoeypotarestoredhereshare/cowrie/txtcmds/ -filecotetsforsimplefakecommadsbi/createfs -usedtocreatethefakefilesystembi/playlog -utilitytoreplaysessiologs









评论