Fake filesystem with the ability to add/remove files. A full fake filesystem resembling a Debian 5.0 installation is includedposted by Foci for Analysis at 8:52 AM on March 11, 2011
Possibility of adding fake file contents so the attacker can 'cat' files such as /etc/passwd. Only minimal file contents are included
Session logs stored in an UML compatible format for easy replay with original timings
Just like Kojoney, Kippo saves files downloaded with wget for later inspection
Trickery; ssh pretends to connect somewhere, exit doesn't really exit, etc
Anybody who writes a honeypot that runs as rootNote that the launcher for kippo checks for this and bails if you try to run as root..
« Older La cucaracha, la cucaracha - ya no puede caminar -... | Guide Dog Loses Eyes, Gets His... Newer »
This thread has been archived and is closed to new comments
posted by demiurge at 8:45 AM on March 11, 2011