76 lines
2.2 KiB
Markdown
76 lines
2.2 KiB
Markdown
# SSH-Tarpit
|
|
|
|
SSH honeypot capable of reading GeoIP databases and logging connection information to a SQLite or MySQL database. It can also be used as a [tarpit](https://nullprogram.com/blog/2019/03/22/) to hold hackers' connections open indefinitely.
|
|
|
|
## Configuration
|
|
|
|
All configuration is done via environment variables:
|
|
|
|
| Variable | Default | Description |
|
|
|---|---|---|
|
|
| `SSH_TARPIT_PORT` | `2222` | Port to listen on |
|
|
| `SSH_TARPIT_TARPIT` | `false` | Enable tarpit mode (`true`, `1`, `yes`, `on`) |
|
|
| `SSH_TARPIT_TARPIT_DELAY` | `1s` | Delay between tarpit bytes |
|
|
| `SSH_TARPIT_TARPIT_MAX_DURATION` | `0s` | Max tarpit duration (0 = unlimited) |
|
|
| `SSH_TARPIT_DB_PATH` | `./logs.db` | Path to SQLite database |
|
|
| `SSH_TARPIT_GEOIP_PATH` | | Path to GeoIP databases (GeoIP disabled if empty) |
|
|
| `SSH_TARPIT_MYSQL_USER` | | MySQL username (enables MySQL when set) |
|
|
| `SSH_TARPIT_MYSQL_PASS` | | MySQL password |
|
|
| `SSH_TARPIT_MYSQL_HOST` | `localhost` | MySQL host |
|
|
| `SSH_TARPIT_MYSQL_PORT` | `3306` | MySQL port |
|
|
| `SSH_TARPIT_MYSQL_DB` | `sshtarpit` | MySQL database name |
|
|
| `SSH_TARPIT_BANNER` | `SSH-2.0-OpenSSH_9.1p1 Debian-1` | Fake SSH banner |
|
|
| `SSH_TARPIT_MAX_CONNS` | `100` | Maximum concurrent connections |
|
|
| `SSH_TARPIT_SHUTDOWN_TIMEOUT` | `30s` | Max time to wait for active connections on shutdown |
|
|
|
|
## Deployment
|
|
|
|
### SQLite
|
|
|
|
Create the database file, then start the container:
|
|
|
|
```bash
|
|
git clone https://git.rznet.fr/razian/ssh-tarpit.git
|
|
cd ssh-tarpit
|
|
touch logs.db
|
|
docker compose up -d
|
|
```
|
|
|
|
### MySQL
|
|
|
|
Create a `.env` file with the required passwords:
|
|
|
|
```bash
|
|
cat > .env <<EOF
|
|
MYSQL_ROOT_PASSWORD=your_db_root_password
|
|
MYSQL_PASS=your_db_root_password
|
|
EOF
|
|
```
|
|
|
|
Then start with the MySQL compose file:
|
|
|
|
```bash
|
|
git clone https://git.rznet.fr/razian/ssh-tarpit.git
|
|
cd ssh-tarpit
|
|
vim .env # set passwords
|
|
docker compose -f docker-compose-mysql.yml up -d
|
|
```
|
|
|
|
### GeoIP
|
|
|
|
Use [geoipupdate](https://github.com/maxmind/geoipupdate) to download the GeoLite2 databases, then mount them and set `SSH_TARPIT_GEOIP_PATH`.
|
|
|
|
## Database Schema
|
|
|
|
```sql
|
|
CREATE TABLE connections (
|
|
ip TEXT,
|
|
country TEXT,
|
|
city TEXT,
|
|
latitude REAL,
|
|
longitude REAL,
|
|
isp TEXT,
|
|
timestamp TIMESTAMP DEFAULT CURRENT_TIMESTAMP
|
|
);
|
|
```
|