Web Application HoneyPot
This app is WebApplication and logged Activity of USERs and what is Done on system to predict Hackers Attack Style and vectors
![]()
sudo apt install wget -y && sudo apt install curl -y && sudo apt install git -y && sudo apt install python39 -y && sudo apt install python3.9-pip -y && sudo pip3 install virtualenv
sudo apt install mariadb-server -y
sudo systemctl start mariadb.service
sudo mysql_secure_installation
This will take you through a series of prompts where you can make some changes to your MariaDB installation’s security options. The first prompt will ask you to enter the current database root password. Since you have not set one up yet, press ENTER to indicate “none”.
The next prompt asks you whether you’d like to set up a database root password. On Ubuntu, the root account for MariaDB is tied closely to automated system maintenance, so we should not change the configured authentication methods for that account. Doing so would make it possible for a package update to break the database system by removing access to the administrative account. Type N and then press ENTER.
Later, we will cover how to set up an additional administrative account for password access if socket authentication is not appropriate for your use case.
From there, you can press Y and then ENTER to accept the defaults for all the subsequent questions. This will remove some anonymous users and the test database, disable remote root logins, and load these new rules so that MariaDB immediately implements the changes you have made.
With that, you’ve finished MariaDB’s initial security configuration. The next step is an optional one, though you should follow it if you prefer to authenticate to your MariaDB server with a password.
sudo mariadb --execute="GRANT ALL ON *.* TO 'user'@'localhost' IDENTIFIED BY 'pass' WITH GRANT OPTION;"
sudo mariadb --execute="FLUSH PRIVILEGES;"
sudo apt-get update
sudo apt update && apt-get install clamav clamav-daemon
Note : Check clamscan versions by This command:
clamscan --version
sudo systemctl stop clamav-freshclam
sudo freshclam
You can download clamav database with name daily.cvd from here : https://database.clamav.net/daily.cvd
and copy manually Like This:
sudo mkdir /var/lib/clamav
sudo systemctl start clamav-freshclam
sudo apt install rkhunter -y
cd /opt
wget http://www.rfxn.com/downloads/maldetect-current.tar.gz
tar -xvf maldetect-current.tar.gz
cd maldetect-1.6.4/
./install.sh
cd
Add This configs :
sudo vi /usr/local/maldetect/conf.maldet
# To enable the email notification.
email_alert="1"
# Specify the email address on which you want to receive an email notification.
email_addr="[email protected]"
# Enable the LMD signature autoupdate.
autoupdate_signatures="1"
# Enable the automatic updates of the LMD installation.
autoupdate_version="1"
# Enable the daily automatic scanning.
cron_daily_scan="1"
# Allows non-root USERs to perform scans.
scan_USER_access="1"
# Move hits to quarantine & alert
quarantine_hits="1"
# Clean string based malware injections.
quarantine_clean="0"
# Suspend USER if malware found.
quarantine_suspend_USER="1"
# Minimum USERid value that be suspended
quarantine_suspend_USER_minuid="500"
# Enable Email Alerting
email_alert="1"
# Email Address in which you want to receive scan reports
email_addr="[email protected]"
# Use with ClamAV
scan_clamscan="1"
# Enable scanning for root-owned files. Set 1 to disable.
scan_ignore_root="0"
You have Several Choices when choosing a Firewall in Linux, but the most important ones are: iptables, Firewalld, and UFW. In this project, we try to use iptables or FirewallD.
sudo apt install iptables -y
sudo mkdir /etc/iptables
sudo touch /etc/iptables/rules.v4
sudo iptables -A INPUT -i enp0s1 -p tcp -m multiport ! --dport 22,80,443,8080 -j REJECT
sudo iptables -A INPUT -i enp1s0 -p tcp ! --syn -m state --state NEW -j DROP
sudo iptables -A INPUT -i enp1s0 -p tcp -m state --state ESTABLISHED,RELATED -j ACCEPT
sudo iptables -A OUTPUT -o enp1s0 -p tcp -m multiport --sport 22,80,443 -j ACCEPT
sudo iptables -A INPUT -i enp1s0 -p tcp --tcp-flags ALL NONE -j DROP
sudo iptables -A INPUT -i enp1s0 -p tcp --tcp-flags PSH,URG,FIN PSH,URG,FIN -j REJECT
sudo iptables -A INPUT -p tcp -m state --state INVALID -j DROP
sudo iptables -A INPUT -p tcp -m connlimit --connlimit-above 100 -j DROP
sudo iptables -A INPUT -f -j DROP
sudo iptables -A INPUT -p icmp --icmp-type 8 -j DROP
sudo iptables -A INPUT -p icmp --icmp-type 13 -j DROP
sudo iptables -A INPUT -p icmp --icmp-type 14 -j DROP
sudo iptables -A INPUT -i enp1s0 -p tcp --syn -m limit --limit 100/minute --limit-burst 80 -j DROP
sudo iptables -P INPUT DROP
sudo iptables -P OUTPUT DROP
sudo iptables-save > /etc/iptables/rules.v4
sudo apt install firewalld -y
sudo systemctl start firewalld
sudo apt install tcpdump -y
You can make Filter to tcpdump packets Like This:
sudo tcpdump --interface any -vv | grep -i "<Filter_value>"
write tcpdump packets:
sudo tcpdump --interface any -w captute.pcap
sudo apt install fail2ban -y
add this Lines to /etc/fail2ban/jail.conf
[webapp]
port=8080
logpath=/var/log/WebApp/WebApp.log
bantime = 10m
maxretry = 5
findtime = 1

sudo dnf install wget -y && sudo dnf install curl -y && sudo dnf install git -y && sudo dnf install python39 && sudo dnf install python3.9-pip -y && sudo pip install virtualenv
important Note : check python version.Best Reponse of app in python3.9 and Thats Better to Install python3.9
sudo dnf install mariadb-server -y
sudo systemctl enable mariadb
sudo dnf module enable mariadb:10.4
sudo dnf module install mariadb/server
sudo dnf module install mariadb:10.4/client
sudo mysql_secure_installation
This will take you through a series of prompts where you can make some changes to your MariaDB installation’s security options. The first prompt will ask you to enter the current database root password. Since you have not set one up yet, press ENTER to indicate “none”.
The next prompt asks you whether you’d like to set up a database root password. On Ubuntu, the root account for MariaDB is tied closely to automated system maintenance, so we should not change the configured authentication methods for that account. Doing so would make it possible for a package update to break the database system by removing access to the administrative account. Type N and then press ENTER.
Later, we will cover how to set up an additional administrative account for password access if socket authentication is not appropriate for your use case.
From there, you can press Y and then ENTER to accept the defaults for all the subsequent questions. This will remove some anonymous users and the test database, disable remote root logins, and load these new rules so that MariaDB immediately implements the changes you have made.
With that, you’ve finished MariaDB’s initial security configuration. The next step is an optional one, though you should follow it if you prefer to authenticate to your MariaDB server with a password.
sudo mariadb --execute="GRANT ALL ON *.* TO 'user'@'localhost' IDENTIFIED BY 'pass' WITH GRANT OPTION;"
sudo mariadb --execute="FLUSH PRIVILEGES;"
sudo yum install epel-release -y
sudo yum update && yum install clamd
You can download clamav database with name daily.cvd from here : https://database.clamav.net/daily.cvd
and copy manually Like This:
sudo mkdir /var/lib/clamav
sudo systemctl stop clamav-freshclam
sudo freshclam
sudo systemctl start clamav-freshclam
sudo dnf install rkhunter -y
cd /opt
wget http://www.rfxn.com/downloads/maldetect-current.tar.gz
tar -xvf maldetect-current.tar.gz
cd maldetect-1.6.4/
./install.sh
cd
Add This configs :
sudo vi /usr/local/maldetect/conf.maldet
# To enable the email notification.
email_alert="1"
# Specify the email address on which you want to receive an email notification.
email_addr="[email protected]"
# Enable the LMD signature autoupdate.
autoupdate_signatures="1"
# Enable the automatic updates of the LMD installation.
autoupdate_version="1"
# Enable the daily automatic scanning.
cron_daily_scan="1"
# Allows non-root USERs to perform scans.
scan_USER_access="1"
# Move hits to quarantine & alert
quarantine_hits="1"
# Clean string based malware injections.
quarantine_clean="0"
# Suspend USER if malware found.
quarantine_suspend_USER="1"
# Minimum USERid value that be suspended
quarantine_suspend_USER_minuid="500"
# Enable Email Alerting
email_alert="1"
# Email Address in which you want to receive scan reports
email_addr="[email protected]"
# Use with ClamAV
scan_clamscan="1"
# Enable scanning for root-owned files. Set 1 to disable.
scan_ignore_root="0"
sudo dnf install iptables-service -y
sudo iptables -A INPUT -i enp0s1 -p tcp -m multiport ! --dport 22,80,443,8080 -j REJECT
sudo iptables -A INPUT -i enp1s0 -p tcp ! --syn -m state --state NEW -j DROP
sudo iptables -A INPUT -i enp1s0 -p tcp -m state --state ESTABLISHED,RELATED -j ACCEPT
sudo iptables -A OUTPUT -o enp1s0 -p tcp -m multiport --sport 22,80,443 -j ACCEPT
sudo iptables -A INPUT -i enp1s0 -p tcp --tcp-flags ALL NONE -j DROP
sudo iptables -A INPUT -i enp1s0 -p tcp --tcp-flags PSH,URG,FIN PSH,URG,FIN -j REJECT
sudo iptables -A INPUT -p tcp -m state --state INVALID -j DROP
sudo iptables -A INPUT -p tcp -m connlimit --connlimit-above 100 -j DROP
sudo iptables -A INPUT -f -j DROP
sudo iptables -A INPUT -p icmp --icmp-type 8 -j DROP
sudo iptables -A INPUT -p icmp --icmp-type 13 -j DROP
sudo iptables -A INPUT -p icmp --icmp-type 14 -j DROP
sudo iptables -A INPUT -i enp1s0 -p tcp --syn -m limit --limit 100/minute --limit-burst 80 -j DROP
sudo iptables -P INPUT DROP
sudo iptables -P OUTPUT DROP
sudo iptables-save > /etc/iptables/rules.v4
sudo apt install firewalld -y
sudo systemctl start firewalld
You can sniif network packages and save Them in File with tcpdump
sudo dnf install tcpdump -y
You can make Filter to tcpdump packets Like This:
sudo tcpdump --interface any -vv | grep -i "<Filter_value>"
write tcpdump packets:
sudo tcpdump --interface any -w captute.pcap
sudo apt install fail2ban -y
add this Lines to /etc/fail2ban/jail.conf
[webapp]
port=8080
logpath=/var/log/WebApp/WebApp.log
bantime = 10m
maxretry = 5
findtime = 1
sudo zypper -n install wget && sudo zypper -n install curl && sudo zypper -m install git && sudo zypper -n install python39 && sudo zypper -m install python3.9-pip && sudo pip3.9 install virtualenv
important Note : check python version.Best Reponse of app in python3.9 and Thats Better to Install python3.9
sudo rpm --import https://yum.mariadb.org/RPM-GPG-KEY-MariaDB
sudo zypper --gpg-auto-import-keys refresh
sudo zypper addrepo --gpgcheck --refresh https://yum.mariadb.org/10.7/opensuse/15/x86_64 mariadb
sudo zypper refresh
sudo zypper -n install MariaDB-server MariaDB-client
sudo zypper -n install pcre-devel clamav clamav-database clamav-nodb clamz
You can download clamav database with name daily.cvd from here : https://database.clamav.net/daily.cvd
and copy manually Like This:
sudo mkdir /var/lib/clamav
sudo systemctl stop clamav-freshclam
sudo freshclam
sudo systemctl start clamav-freshclam
sudo zypper -n install rkhunter
cd /opt
wget http://www.rfxn.com/downloads/maldetect-current.tar.gz
tar -xvf maldetect-current.tar.gz
cd maldetect-1.6.4/
./install.sh
cd
Add This configs :
sudo vi /usr/local/maldetect/conf.maldet
# To enable the email notification.
email_alert="1"
# Specify the email address on which you want to receive an email notification.
email_addr="[email protected]"
# Enable the LMD signature autoupdate.
autoupdate_signatures="1"
# Enable the automatic updates of the LMD installation.
autoupdate_version="1"
# Enable the daily automatic scanning.
cron_daily_scan="1"
# Allows non-root USERs to perform scans.
scan_USER_access="1"
# Move hits to quarantine & alert
quarantine_hits="1"
# Clean string based malware injections.
quarantine_clean="0"
# Suspend USER if malware found.
quarantine_suspend_USER="1"
# Minimum USERid value that be suspended
quarantine_suspend_USER_minuid="500"
# Enable Email Alerting
email_alert="1"
# Email Address in which you want to receive scan reports
email_addr="[email protected]"
# Use with ClamAV
scan_clamscan="1"
# Enable scanning for root-owned files. Set 1 to disable.
scan_ignore_root="0"
sudo zypper -n install iptables
sudo iptables -A INPUT -i enp0s1 -p tcp -m multiport ! --dport 22,80,443,8080 -j REJECT
sudo iptables -A INPUT -i enp1s0 -p tcp ! --syn -m state --state NEW -j DROP
sudo iptables -A INPUT -i enp1s0 -p tcp -m state --state ESTABLISHED,RELATED -j ACCEPT
sudo iptables -A OUTPUT -o enp1s0 -p tcp -m multiport --sport 22,80,443 -j ACCEPT
sudo iptables -A INPUT -i enp1s0 -p tcp --tcp-flags ALL NONE -j DROP
sudo iptables -A INPUT -i enp1s0 -p tcp --tcp-flags PSH,URG,FIN PSH,URG,FIN -j REJECT
sudo iptables -A INPUT -p tcp -m state --state INVALID -j DROP
sudo iptables -A INPUT -p tcp -m connlimit --connlimit-above 100 -j DROP
sudo iptables -A INPUT -f -j DROP
sudo iptables -A INPUT -p icmp --icmp-type 8 -j DROP
sudo iptables -A INPUT -p icmp --icmp-type 13 -j DROP
sudo iptables -A INPUT -p icmp --icmp-type 14 -j DROP
sudo iptables -A INPUT -i enp1s0 -p tcp --syn -m limit --limit 100/minute --limit-burst 80 -j DROP
sudo iptables -P INPUT DROP
sudo iptables -P OUTPUT DROP
sudo iptables-save > /etc/iptables/rules.v4
sudo zypper -n install firewalld
sudo systemctl start firewalld
You can sniif network packages and save Them in File with tcpdump
sudo zypper -n install tcpdump
You can make Filter to tcpdump packets Like This:
sudo tcpdump --interface any -vv | grep -i "<Filter_value>"
write tcpdump packets:
sudo tcpdump --interface any -w captute.pcap
sudo zypper -n install fail2ban
add this Lines to /etc/fail2ban/jail.conf
[webapp]
port=8080
logpath=/var/log/WebApp/WebApp.log
bantime = 10m
maxretry = 5
findtime = 1
Download Zip File :
wget https://gitlab.com/kooshakooshadv/kygnus_webhoneypot/-/archive/main/kygnus_webhoneypot-main.zip
unzip KYGnus_Honeypot.zip
mv kygnus_webhoneypot-main/* /home/$USER/WebApp/App
cd /home/$USER/WebApp/App
mv Documents.tar.gz ../ && mv garardad.tar.gz ../ && mv personel_info.tar.gz ../ && cd .. && tar xfvz Documents.tar.gz && tar xfvz garardad.tar.gz && tar xfvz personel_info.tar.gz && cd
Create config File and Log File
sudo mkdir /etc/WebApp && cd /etc/WebApp && sudo ln -s webapp.conf /home/$USER/WebApp/App/config.py && cd && sudo mkdir /var/log/WebApp && cd /var/log/WebApp && sudo ln -s webapp.log /home/$USER/WebApp/log/WebApp.log && cd
echo -e '''#!/bin/bash\n\n\n\ncd /home/$USER/WebApp/App\nsource venv/bin/activate\npython3.9 app.py''' > /home/$USER/WebApp/App/wb.sh
sudo mv /home/$USER/WebApp/App/wb.sh /usr/bin
echo -e '''[Unit] \n Description=Tabriz Petrochemical\nDocumentation=Tabriz Petrochemical\nAfter=NetworkManager.service\n[Service]\nExecStart=/bin/bash /home/$USER/WebApp/App/wb.sh\nExecStop=/bin/bash /home/$USER/WebApp/App/wb.sh --Kill\nExecReload=/bin/bash /home/$USER/WebApp/App/wb.sh --HUP \n\n[Install]\nWantedBy=multi-USER.target''' > /home/$USER/WebApp/App/wb.service
sudo mv /home/$USER/WebApp/App/wb.service /etc/systemd/system
sudo systemctl enable /etc/systemd/system/wb.service && sudo systemctl start /etc/systemd/system/wb.service
virtualenv venv && source venv/bin/activate
pip3.9 install -r requirements.txt
Note 1 : in Debian Base systems You should Enter pip command with pip3 and python command with python3
Note 2 : if Get Error when Install packages (This might be From Versions of Packgaes and Python version) try to run pkg script to install lest version of python packgaes
./pkg
python3.9 app.py
OR Run Install Script
./Install
make nat rules for iptables
RouteServer IP = 127.16.2.11 mainSerevr IP = 127.16.2.10
iptables -t nat -I PREROUTING -p tcp --dport 22 -d 172.16.2.11 -j DNAT --to-destination 172.16.2.10:8080
iptables -t nat -I POSTROUTING -j MASQERADE
echo 1 > /proc/sys/net/ipv4/ip-forward
NOTE : The Policy of Forward chain should be ACCEPT
sudo zypper -n install nginx
sudo dnf install nginx -y
sudo apt install nginx -y
gunicorn -w 4 -b 127.0.0.1:8080 main:app
sudo rm -rf /home/$USER/WebApp && sudo rm -rf /etc/WebApp && sudo rm -rf /var/log/WebApp && sudo rm /etc/systemd/system/wb.service && sudo rm /usr/bin/wb.sh && sudo iptables -F
Note : Add nameha.zip and fishevarizi.zip to /home/$USER/WebApp/Documents
Gmail : [email protected]
ProtonMail : [email protected]
GitHub
Content type
Image
Digest
sha256:2fe366ca9…
Size
392.6 MB
Last updated
12 months ago
docker pull kygnus/myhp