Sign inSign up

kygnus/myhp

By kygnus

•Updated 12 months ago

Image
0

116

kygnus/myhp repository overview

⁠KYGnus_WebHoneypot

Web Application HoneyPot

⁠INFO

This app is WebApplication and logged Activity of USERs and what is Done on system to predict Hackers Attack Style and vectors

⁠Install

⁠System
⁠Ubuntu

Ubuntu

⁠Basic Tools
sudo apt install wget -y && sudo apt install curl -y && sudo apt install git -y && sudo apt install python39 -y  && sudo apt install python3.9-pip -y && sudo pip3 install virtualenv
⁠Mariadb
sudo apt install mariadb-server -y
sudo systemctl start mariadb.service
sudo mysql_secure_installation

This will take you through a series of prompts where you can make some changes to your MariaDB installation’s security options. The first prompt will ask you to enter the current database root password. Since you have not set one up yet, press ENTER to indicate “none”.

The next prompt asks you whether you’d like to set up a database root password. On Ubuntu, the root account for MariaDB is tied closely to automated system maintenance, so we should not change the configured authentication methods for that account. Doing so would make it possible for a package update to break the database system by removing access to the administrative account. Type N and then press ENTER.

Later, we will cover how to set up an additional administrative account for password access if socket authentication is not appropriate for your use case.

From there, you can press Y and then ENTER to accept the defaults for all the subsequent questions. This will remove some anonymous users and the test database, disable remote root logins, and load these new rules so that MariaDB immediately implements the changes you have made.

With that, you’ve finished MariaDB’s initial security configuration. The next step is an optional one, though you should follow it if you prefer to authenticate to your MariaDB server with a password.

sudo mariadb --execute="GRANT ALL ON *.* TO 'user'@'localhost' IDENTIFIED BY 'pass' WITH GRANT OPTION;"
sudo mariadb --execute="FLUSH PRIVILEGES;"
⁠Antivirus
⁠ClamAV
sudo apt-get update
sudo apt update && apt-get install clamav clamav-daemon

Note : Check clamscan versions by This command:

clamscan --version
sudo systemctl stop clamav-freshclam
sudo freshclam

You can download clamav database with name daily.cvd from here : https://database.clamav.net/daily.cvd⁠
and copy manually Like This:

sudo mkdir /var/lib/clamav
sudo systemctl start clamav-freshclam
⁠RkHunter ( RootKit Hunter )
sudo apt install rkhunter -y
⁠Maldet ( Linux Malware Detect )
cd /opt
wget http://www.rfxn.com/downloads/maldetect-current.tar.gz
tar -xvf maldetect-current.tar.gz
cd maldetect-1.6.4/
./install.sh
cd

Add This configs :

sudo vi /usr/local/maldetect/conf.maldet
# To enable the email notification.
email_alert="1"

# Specify the email address on which you want to receive an email notification.
email_addr="[email protected]"

# Enable the LMD signature autoupdate.
autoupdate_signatures="1"

# Enable the automatic updates of the LMD installation.
autoupdate_version="1"

# Enable the daily automatic scanning.
cron_daily_scan="1"

# Allows non-root USERs to perform scans.
scan_USER_access="1"
    
# Move hits to quarantine & alert
quarantine_hits="1"

# Clean string based malware injections.
quarantine_clean="0"

# Suspend USER if malware found. 
quarantine_suspend_USER="1"

# Minimum USERid value that be suspended
quarantine_suspend_USER_minuid="500"

# Enable Email Alerting
email_alert="1"

# Email Address in which you want to receive scan reports
email_addr="[email protected]"

# Use with ClamAV
scan_clamscan="1"

# Enable scanning for root-owned files. Set 1 to disable.
scan_ignore_root="0"

⁠Firewall

You have Several Choices when choosing a Firewall in Linux, but the most important ones are: iptables, Firewalld, and UFW. In this project, we try to use iptables or FirewallD.

⁠iptables
sudo apt install iptables -y
sudo mkdir /etc/iptables
sudo touch /etc/iptables/rules.v4
sudo iptables -A INPUT -i enp0s1 -p tcp -m multiport ! --dport 22,80,443,8080 -j REJECT
sudo iptables -A INPUT -i enp1s0 -p tcp ! --syn -m state --state NEW -j DROP
sudo iptables -A INPUT -i enp1s0 -p tcp -m state --state ESTABLISHED,RELATED -j ACCEPT
sudo iptables -A OUTPUT -o enp1s0 -p tcp -m multiport --sport 22,80,443 -j ACCEPT
sudo iptables -A INPUT -i enp1s0 -p tcp --tcp-flags ALL NONE -j DROP
sudo iptables -A INPUT -i enp1s0 -p tcp --tcp-flags PSH,URG,FIN PSH,URG,FIN -j REJECT
sudo iptables -A INPUT -p tcp -m state --state INVALID -j DROP
sudo iptables -A INPUT -p tcp -m connlimit --connlimit-above 100 -j DROP
sudo iptables -A INPUT -f -j DROP
sudo iptables -A INPUT -p icmp --icmp-type 8 -j DROP
sudo iptables -A INPUT -p icmp --icmp-type 13 -j DROP
sudo iptables -A INPUT -p icmp --icmp-type 14 -j DROP
sudo iptables -A INPUT -i enp1s0 -p tcp --syn -m limit --limit 100/minute --limit-burst 80 -j DROP
sudo iptables -P INPUT DROP
sudo iptables -P OUTPUT DROP
sudo iptables-save > /etc/iptables/rules.v4
⁠FirewallD
sudo apt install firewalld -y
sudo systemctl start firewalld
⁠Network Tools
⁠Tcpdump
sudo apt install tcpdump -y

You can make Filter to tcpdump packets Like This:

sudo tcpdump --interface any -vv | grep -i "<Filter_value>"

write tcpdump packets:

sudo tcpdump --interface any -w captute.pcap
⁠Fail2ban
sudo apt install fail2ban -y

add this Lines to /etc/fail2ban/jail.conf

[webapp]

port=8080
logpath=/var/log/WebApp/WebApp.log
bantime      = 10m
maxretry     = 5
findtime     = 1

⁠Fedora

Fedora

⁠Basic tools
sudo dnf install wget -y && sudo dnf install curl -y && sudo dnf install git -y && sudo dnf install python39 && sudo dnf install python3.9-pip -y && sudo pip install virtualenv

important Note : check python version.Best Reponse of app in python3.9 and Thats Better to Install python3.9

⁠MariaDB
sudo dnf install mariadb-server -y
sudo systemctl enable mariadb
sudo dnf module enable mariadb:10.4
sudo dnf module install mariadb/server
sudo dnf module install mariadb:10.4/client
sudo mysql_secure_installation

This will take you through a series of prompts where you can make some changes to your MariaDB installation’s security options. The first prompt will ask you to enter the current database root password. Since you have not set one up yet, press ENTER to indicate “none”.

The next prompt asks you whether you’d like to set up a database root password. On Ubuntu, the root account for MariaDB is tied closely to automated system maintenance, so we should not change the configured authentication methods for that account. Doing so would make it possible for a package update to break the database system by removing access to the administrative account. Type N and then press ENTER.

Later, we will cover how to set up an additional administrative account for password access if socket authentication is not appropriate for your use case.

From there, you can press Y and then ENTER to accept the defaults for all the subsequent questions. This will remove some anonymous users and the test database, disable remote root logins, and load these new rules so that MariaDB immediately implements the changes you have made.

With that, you’ve finished MariaDB’s initial security configuration. The next step is an optional one, though you should follow it if you prefer to authenticate to your MariaDB server with a password.

sudo mariadb --execute="GRANT ALL ON *.* TO 'user'@'localhost' IDENTIFIED BY 'pass' WITH GRANT OPTION;"
sudo mariadb --execute="FLUSH PRIVILEGES;"
⁠Antivirus
⁠clamAV
sudo yum install epel-release -y
sudo yum update && yum install clamd

You can download clamav database with name daily.cvd from here : https://database.clamav.net/daily.cvd⁠
and copy manually Like This:

sudo mkdir /var/lib/clamav
sudo systemctl stop clamav-freshclam
sudo freshclam
sudo systemctl start clamav-freshclam
⁠Rkhunter ( RootKit Hunter)
sudo dnf install rkhunter -y
⁠Maldet ( Linux Malware Detect )
cd /opt
wget http://www.rfxn.com/downloads/maldetect-current.tar.gz
tar -xvf maldetect-current.tar.gz
cd maldetect-1.6.4/
./install.sh
cd

Add This configs :

sudo vi /usr/local/maldetect/conf.maldet
# To enable the email notification.
email_alert="1"

# Specify the email address on which you want to receive an email notification.
email_addr="[email protected]"

# Enable the LMD signature autoupdate.
autoupdate_signatures="1"

# Enable the automatic updates of the LMD installation.
autoupdate_version="1"

# Enable the daily automatic scanning.
cron_daily_scan="1"

# Allows non-root USERs to perform scans.
scan_USER_access="1"
    
# Move hits to quarantine & alert
quarantine_hits="1"

# Clean string based malware injections.
quarantine_clean="0"

# Suspend USER if malware found. 
quarantine_suspend_USER="1"

# Minimum USERid value that be suspended
quarantine_suspend_USER_minuid="500"

# Enable Email Alerting
email_alert="1"

# Email Address in which you want to receive scan reports
email_addr="[email protected]"

# Use with ClamAV
scan_clamscan="1"

# Enable scanning for root-owned files. Set 1 to disable.
scan_ignore_root="0"

⁠Firewall
⁠iptables
sudo dnf install iptables-service -y
sudo iptables -A INPUT -i enp0s1 -p tcp -m multiport ! --dport 22,80,443,8080 -j REJECT
sudo iptables -A INPUT -i enp1s0 -p tcp ! --syn -m state --state NEW -j DROP
sudo iptables -A INPUT -i enp1s0 -p tcp -m state --state ESTABLISHED,RELATED -j ACCEPT
sudo iptables -A OUTPUT -o enp1s0 -p tcp -m multiport --sport 22,80,443 -j ACCEPT
sudo iptables -A INPUT -i enp1s0 -p tcp --tcp-flags ALL NONE -j DROP
sudo iptables -A INPUT -i enp1s0 -p tcp --tcp-flags PSH,URG,FIN PSH,URG,FIN -j REJECT
sudo iptables -A INPUT -p tcp -m state --state INVALID -j DROP
sudo iptables -A INPUT -p tcp -m connlimit --connlimit-above 100 -j DROP
sudo iptables -A INPUT -f -j DROP
sudo iptables -A INPUT -p icmp --icmp-type 8 -j DROP
sudo iptables -A INPUT -p icmp --icmp-type 13 -j DROP
sudo iptables -A INPUT -p icmp --icmp-type 14 -j DROP
sudo iptables -A INPUT -i enp1s0 -p tcp --syn -m limit --limit 100/minute --limit-burst 80 -j DROP
sudo iptables -P INPUT DROP
sudo iptables -P OUTPUT DROP
sudo iptables-save > /etc/iptables/rules.v4
⁠FirewallD
sudo apt install firewalld -y
sudo systemctl start firewalld
⁠Network Tools
⁠Tcpdump RedHat ( Optional )

You can sniif network packages and save Them in File with tcpdump

sudo dnf install tcpdump -y

You can make Filter to tcpdump packets Like This:

sudo tcpdump --interface any -vv | grep -i "<Filter_value>"

write tcpdump packets:

sudo tcpdump --interface any -w captute.pcap
⁠Fail2ban
sudo apt install fail2ban -y

add this Lines to /etc/fail2ban/jail.conf

[webapp]

port=8080
logpath=/var/log/WebApp/WebApp.log
bantime      = 10m
maxretry     = 5
findtime     = 1

⁠openSUSE
⁠Basic Tools

openSUSE

sudo zypper -n install wget  && sudo zypper -n install curl  && sudo zypper -m install git  && sudo zypper -n install python39 && sudo zypper -m install python3.9-pip && sudo pip3.9 install virtualenv

important Note : check python version.Best Reponse of app in python3.9 and Thats Better to Install python3.9

⁠MariaDB
sudo rpm --import https://yum.mariadb.org/RPM-GPG-KEY-MariaDB
sudo zypper --gpg-auto-import-keys refresh
sudo zypper addrepo --gpgcheck --refresh https://yum.mariadb.org/10.7/opensuse/15/x86_64 mariadb
sudo zypper refresh
sudo zypper -n install MariaDB-server MariaDB-client
⁠Antivirus
⁠clamAV
sudo zypper -n install pcre-devel clamav clamav-database clamav-nodb clamz

You can download clamav database with name daily.cvd from here : https://database.clamav.net/daily.cvd⁠
and copy manually Like This:

sudo mkdir /var/lib/clamav
sudo systemctl stop clamav-freshclam
sudo freshclam
sudo systemctl start clamav-freshclam
⁠Rkhunter ( RootKit Hunter)
sudo zypper -n install rkhunter
⁠Maldet ( Linux Malware Detect )
cd /opt
wget http://www.rfxn.com/downloads/maldetect-current.tar.gz
tar -xvf maldetect-current.tar.gz
cd maldetect-1.6.4/
./install.sh
cd

Add This configs :

sudo vi /usr/local/maldetect/conf.maldet
# To enable the email notification.
email_alert="1"

# Specify the email address on which you want to receive an email notification.
email_addr="[email protected]"

# Enable the LMD signature autoupdate.
autoupdate_signatures="1"

# Enable the automatic updates of the LMD installation.
autoupdate_version="1"

# Enable the daily automatic scanning.
cron_daily_scan="1"

# Allows non-root USERs to perform scans.
scan_USER_access="1"
    
# Move hits to quarantine & alert
quarantine_hits="1"

# Clean string based malware injections.
quarantine_clean="0"

# Suspend USER if malware found. 
quarantine_suspend_USER="1"

# Minimum USERid value that be suspended
quarantine_suspend_USER_minuid="500"

# Enable Email Alerting
email_alert="1"

# Email Address in which you want to receive scan reports
email_addr="[email protected]"

# Use with ClamAV
scan_clamscan="1"

# Enable scanning for root-owned files. Set 1 to disable.
scan_ignore_root="0"

⁠Firewall
⁠iptables
sudo zypper -n install iptables
sudo iptables -A INPUT -i enp0s1 -p tcp -m multiport ! --dport 22,80,443,8080 -j REJECT
sudo iptables -A INPUT -i enp1s0 -p tcp ! --syn -m state --state NEW -j DROP
sudo iptables -A INPUT -i enp1s0 -p tcp -m state --state ESTABLISHED,RELATED -j ACCEPT
sudo iptables -A OUTPUT -o enp1s0 -p tcp -m multiport --sport 22,80,443 -j ACCEPT
sudo iptables -A INPUT -i enp1s0 -p tcp --tcp-flags ALL NONE -j DROP
sudo iptables -A INPUT -i enp1s0 -p tcp --tcp-flags PSH,URG,FIN PSH,URG,FIN -j REJECT
sudo iptables -A INPUT -p tcp -m state --state INVALID -j DROP
sudo iptables -A INPUT -p tcp -m connlimit --connlimit-above 100 -j DROP
sudo iptables -A INPUT -f -j DROP
sudo iptables -A INPUT -p icmp --icmp-type 8 -j DROP
sudo iptables -A INPUT -p icmp --icmp-type 13 -j DROP
sudo iptables -A INPUT -p icmp --icmp-type 14 -j DROP
sudo iptables -A INPUT -i enp1s0 -p tcp --syn -m limit --limit 100/minute --limit-burst 80 -j DROP
sudo iptables -P INPUT DROP
sudo iptables -P OUTPUT DROP
sudo iptables-save > /etc/iptables/rules.v4
⁠FirewallD
sudo zypper -n install firewalld 
sudo systemctl start firewalld
⁠Network Tools
⁠Tcpdump RedHat ( Optional )

You can sniif network packages and save Them in File with tcpdump

sudo zypper -n install tcpdump 

You can make Filter to tcpdump packets Like This:

sudo tcpdump --interface any -vv | grep -i "<Filter_value>"

write tcpdump packets:

sudo tcpdump --interface any -w captute.pcap
⁠Fail2ban
sudo zypper -n install fail2ban 

add this Lines to /etc/fail2ban/jail.conf

[webapp]

port=8080
logpath=/var/log/WebApp/WebApp.log
bantime      = 10m
maxretry     = 5
findtime     = 1

⁠WebApp

Download Zip File :

wget https://gitlab.com/kooshakooshadv/kygnus_webhoneypot/-/archive/main/kygnus_webhoneypot-main.zip
unzip KYGnus_Honeypot.zip
mv kygnus_webhoneypot-main/* /home/$USER/WebApp/App
cd /home/$USER/WebApp/App
mv Documents.tar.gz ../ && mv garardad.tar.gz ../ && mv personel_info.tar.gz ../ && cd .. && tar xfvz Documents.tar.gz && tar xfvz garardad.tar.gz && tar xfvz personel_info.tar.gz && cd

Create config File and Log File

sudo mkdir /etc/WebApp && cd /etc/WebApp && sudo ln -s webapp.conf /home/$USER/WebApp/App/config.py && cd && sudo mkdir /var/log/WebApp && cd /var/log/WebApp && sudo ln -s webapp.log /home/$USER/WebApp/log/WebApp.log && cd 
echo -e '''#!/bin/bash\n\n\n\ncd /home/$USER/WebApp/App\nsource venv/bin/activate\npython3.9 app.py''' > /home/$USER/WebApp/App/wb.sh
sudo mv /home/$USER/WebApp/App/wb.sh /usr/bin
echo -e '''[Unit] \n Description=Tabriz Petrochemical\nDocumentation=Tabriz Petrochemical\nAfter=NetworkManager.service\n[Service]\nExecStart=/bin/bash /home/$USER/WebApp/App/wb.sh\nExecStop=/bin/bash /home/$USER/WebApp/App/wb.sh --Kill\nExecReload=/bin/bash /home/$USER/WebApp/App/wb.sh --HUP \n\n[Install]\nWantedBy=multi-USER.target''' > /home/$USER/WebApp/App/wb.service
sudo mv /home/$USER/WebApp/App/wb.service /etc/systemd/system
sudo systemctl enable /etc/systemd/system/wb.service && sudo systemctl start /etc/systemd/system/wb.service
virtualenv venv && source venv/bin/activate
pip3.9 install -r requirements.txt

Note 1 : in Debian Base systems You should Enter pip command with pip3 and python command with python3

Note 2 : if Get Error when Install packages (This might be From Versions of Packgaes and Python version) try to run pkg script to install lest version of python packgaes

./pkg
python3.9 app.py

OR Run Install Script

./Install
⁠Nat Server

make nat rules for iptables

RouteServer IP = 127.16.2.11 mainSerevr IP = 127.16.2.10

iptables -t nat -I PREROUTING -p tcp --dport 22 -d 172.16.2.11 -j DNAT --to-destination 172.16.2.10:8080
iptables -t nat -I POSTROUTING -j MASQERADE
echo 1 > /proc/sys/net/ipv4/ip-forward

NOTE : The Policy of Forward chain should be ACCEPT

⁠Deploy with Nginx
sudo zypper -n install nginx
sudo dnf install nginx -y
sudo apt install nginx -y
gunicorn -w 4 -b 127.0.0.1:8080 main:app

⁠Remove

sudo rm -rf /home/$USER/WebApp && sudo rm -rf /etc/WebApp && sudo rm -rf /var/log/WebApp && sudo rm /etc/systemd/system/wb.service && sudo rm /usr/bin/wb.sh && sudo iptables -F

Note : Add nameha.zip and fishevarizi.zip to /home/$USER/WebApp/Documents

⁠Contact

Gmail : [email protected]⁠
ProtonMail : [email protected]⁠
GitHub⁠

Tag summary

Content type

Image

Digest

sha256:2fe366ca9…

Size

392.6 MB

Last updated

12 months ago

docker pull kygnus/myhp