{"id":725,"date":"2014-12-07T22:07:08","date_gmt":"2014-12-07T21:07:08","guid":{"rendered":"http:\/\/under12oot.noblogs.org\/?p=725"},"modified":"2014-12-07T22:07:08","modified_gmt":"2014-12-07T21:07:08","slug":"ultimo-aggiornamento-kippo","status":"publish","type":"post","link":"https:\/\/under12oot.noblogs.org\/?p=725","title":{"rendered":"Ultimo aggiornamento kippo"},"content":{"rendered":"<p>Proprio<em> ieri<\/em> dicevo che non c&#8217;era <em>soddisfazione<\/em> (e continua a <em>non<\/em> esserci, almeno finch\u00e8 non cambio sistema) ma <em>10 minuti fa<\/em> controllando i log mi sono accorto che<em> c&#8217;\u00e8 stato<\/em> un minimo di interazione<em> umana!<\/em> Era ora mi vien da dire&#8230; <em>Poca roba,<\/em> non pensate a chiss\u00e0 che! Qui c&#8217;\u00e8 il log <em>dell&#8217;attacco:<\/em><\/p>\n<p><em>honey@raspberrypi ~\/kippo-0.8\/log $ <\/em><strong>cat kippo.log.2 |grep 12:49:<\/strong><br \/>\n2014-12-07 12:49:02+0000 [kippo.core.honeypot.HoneyPotSSHFactory] New connection: 103.25.9.229:37269 (192.168.0.10:22) [session: 16900]<br \/>\n2014-12-07 12:49:03+0000 [HoneyPotTransport,16900,103.25.9.229] Remote SSH version: SSH-2.0-PUTTY<br \/>\n2014-12-07 12:49:03+0000 [HoneyPotTransport,16900,103.25.9.229] kex alg, key alg: diffie-hellman-group1-sha1 ssh-rsa<br \/>\n2014-12-07 12:49:03+0000 [HoneyPotTransport,16900,103.25.9.229] outgoing: aes128-ctr hmac-sha1 none<br \/>\n2014-12-07 12:49:03+0000 [HoneyPotTransport,16900,103.25.9.229] incoming: aes128-ctr hmac-sha1 none<br \/>\n2014-12-07 12:49:04+0000 [HoneyPotTransport,16900,103.25.9.229] NEW KEYS<br \/>\n2014-12-07 12:49:04+0000 [HoneyPotTransport,16900,103.25.9.229] starting service ssh-userauth<br \/>\n2014-12-07 12:49:04+0000 [SSHS..,16900,103.25.9.229] root trying auth none<br \/>\n2014-12-07 12:49:05+0000 [SSH..,16900,103.25.9.229] root trying auth password<br \/>\n2014-12-07 12:49:05+0000 [SSH..,16900,103.25.9.229] login attempt [root\/123456] succeeded<br \/>\n2014-12-07 12:49:05+0000 [SSH..,16900,103.25.9.229] root authenticated with password<br \/>\n2014-12-07 12:49:05+0000 [SSH..,16900,103.25.9.229] starting service ssh-connection<br \/>\n2014-12-07 12:49:05+0000 [SSH..,16900,103.25.9.229] got channel session request<br \/>\n2014-12-07 12:49:05+0000 [SSH..,16900,103.25.9.229] channel open<br \/>\n2014-12-07 12:49:06+0000 [SSH..,16900,103.25.9.229] executing command &#8220;#!\/bin\/sh<br \/>\n2014-12-07 12:49:06+0000 [SS..,16900,103.25.9.229] Unhandled Error<br \/>\n2014-12-07 12:49:06+0000 [SSH..16900,103.25.9.229] remote close<br \/>\n2014-12-07 12:49:06+0000 [SSH..,16900,103.25.9.229] sending close 0<br \/>\n2014-12-07 12:49:07+0000 [SSHService ssh-connection on HoneyPotTransport,16900,103.25.9.229] got channel session request<br \/>\n2014-12-07 12:49:07+0000 [SSH..,16900,103.25.9.229] channel open<br \/>\n2014-12-07 12:49:07+0000 [SSH..,16900,103.25.9.229] executing command &#8220;ls -la \/var\/run\/sftp.pid&#8221;<br \/>\n2014-12-07 12:49:08+0000 [SSH..,16900,103.25.9.229] Unhandled Error<br \/>\n2014-12-07 12:49:09+0000 [SSH..16900,103.25.9.229] remote close<br \/>\n2014-12-07 12:49:09+0000 [SSH..,16900,103.25.9.229] sending close 1<br \/>\n2014-12-07 12:49:09+0000 [HoneyPotTransport,16900,103.25.9.229] Got remote error, code 11<br \/>\n2014-12-07 12:49:09+0000 [HoneyPotTransport,16900,103.25.9.229] connection lost<\/p>\n<p>Indovinate un p\u00f2 da dove arriva il <em>103.25.9.229?<\/em> Ma dalla <span style=\"text-decoration: underline\">Cina<\/span> ovviamente!! Supponendo che siano<em> 7 ore avanti<\/em> erano quasi le<em> 20:00<\/em> quando <em>CaioLing<\/em> \u00e8 <span style=\"text-decoration: underline\">inkippato<\/span> nell<em>&#8216;honeypot!<\/em><\/p>\n<p><em>Vabb\u00e8<\/em>, almeno abbiamo avuto la conferma che qualcuno <em>legge i log<\/em> dello scanner di rete che ha fatto partire e si \u00e8 <em>incuriosito<\/em>!<\/p>\n<p><em>Questo \u00e8 quanto! Alla Prossima<\/em><\/p>\n<p>&nbsp;<\/p>\n<p>n0ys3<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Proprio ieri dicevo che non c&#8217;era soddisfazione (e continua a non esserci, almeno finch\u00e8 non cambio sistema) ma 10 minuti fa controllando i log mi sono accorto che c&#8217;\u00e8 stato un minimo di interazione umana! Era ora mi vien da dire&#8230; Poca roba, non pensate a chiss\u00e0 che! Qui c&#8217;\u00e8 il log dell&#8217;attacco: honey@raspberrypi ~\/kippo-0.8\/log [&hellip;]<\/p>\n","protected":false},"author":5820,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3,19],"tags":[179,65,66,104,105,44],"class_list":["post-725","post","type-post","status-publish","format-standard","hentry","category-howto","category-utility","tag-siti-di-e-per-acari","tag-honeypot","tag-kippo","tag-raspberry","tag-raspbian","tag-ssh"],"_links":{"self":[{"href":"https:\/\/under12oot.noblogs.org\/index.php?rest_route=\/wp\/v2\/posts\/725","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/under12oot.noblogs.org\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/under12oot.noblogs.org\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/under12oot.noblogs.org\/index.php?rest_route=\/wp\/v2\/users\/5820"}],"replies":[{"embeddable":true,"href":"https:\/\/under12oot.noblogs.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=725"}],"version-history":[{"count":1,"href":"https:\/\/under12oot.noblogs.org\/index.php?rest_route=\/wp\/v2\/posts\/725\/revisions"}],"predecessor-version":[{"id":726,"href":"https:\/\/under12oot.noblogs.org\/index.php?rest_route=\/wp\/v2\/posts\/725\/revisions\/726"}],"wp:attachment":[{"href":"https:\/\/under12oot.noblogs.org\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=725"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/under12oot.noblogs.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=725"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/under12oot.noblogs.org\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=725"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}