
Simple TCP/UDP honeypot implemented in Perl
TCP/UDP Honeypot program implemented in Perl
README for malbait, 2/10/17
(btw my bitcoin address is 3A7yuqBcPAcVEM59bNAVQdTCmkxRb5JRgE )
(Here's an alternative, also for BTC, as I've been getting reports of some bitcoin wallets not supporting certain addresses: 1PEDKUiUTxGNJ3XTPfXCTAjpzVzX1VZAme )
Welcome to malbait, your one-stop, simple perl honeypot!
Malbait is a honeypot, or "malware bait" program. It is designed to waste the time of hackers and monitor hostile traffic on the internet (or your LAN).
Malbait creates a series of fake servers on selected or default TCP and, if selected, UDP ports. If anyone or anything connects to them, their input will be recorded in the logfiles.
These run as background processes, so you will have to either switch off your computer or use the shell's "kill" (or, better still, "skill") command to get rid of them. You can monitor them with netstat. I reccomend:
sudo netstat -anp|grep perl
to see what's listening, and
sudo skill -9 perl
to kill them off when you've had enough.
NB: If you use install.sh to install this program, you will have to run
sudo skill -9 malbait
instead. though you can still monitor it with: sudo netstat -anp|grep perl
Alternatively you can just shut down the machine. Obviously don't use malbait while using perl for anything else! I reccomend a dedicated "bait" machine, either something small like a Raspberry Pi running the default ports, or a big computer running as many ports as you can listen on (preferably all of them).
Malbait defaults to TCP, but can support UDP on its own and both running side-by-side.
It is VERY STRONGLY reccomended that you use this program in superuser mode, either by invoking gainroot (sudo gainroot) or by sudoing it (sudo malbait). You MUST have superuser permissions to open any of the first 1024 ports.
It's invoked like this
malbait -foo
if you run it without parameters it will spit out a lengthy text explaining usage further. If you want to get started "out of the box" run
malbait -defaults
This will open its' default ports and create servers wherever possible.
Malbait can create dummy servers for Telnet, FTP, SMTP, POP3, BGP, HTTP (not brilliantly), TR-69 (not brilliantly), imap, systat, echo, and the old ascii "time" server. By default these are opened on all of their default ports, but you can specify ports for them.
You can also open a range of ports, ie,
malbait -ports:1-1024
Will open ports 1-1024 (the "well-known" or "restricted" ports) and create fake servers where appropriate.
Use of malbait is only restricted by the amount of memory you have. The -trans_proto:tcpudp and -ports: options gives you the power to watch every single port if you have a hardcore enough machine; or crash your computer if you don't. I find that my little Lenovo x200 notepad can handle about 6000 ports or so before it starts to go bonkers, but your mileage may vary. Want to see how powerful your new box REALLY is? Malbait can provide a benchmark - personally I'd love to see what happens on a machine running
malbait -ports:1-65535 -trans_proto:tcpudp
on a very powerful computer - in my experience with just 10% of that, there's definitely more malicious UDP traffic out there (mainly dickheads trying to scam free phone calls it seems), and telnet is an absolute petri dish, but I'd love to see a survey of the uncharted territory beyond, if anyone has the horsepower (and the ability and balls / ovaries to completely disable their firewall!)
If you try to open, say, an FTP server in UDP mode, ( malbait -proto:ftp -trans_proto:udp ) it'll open the default ports - but you won't get a pretend FTP server! UDP will only create servers for UDP compatible services, which are asciitime, systat, echo and the special "hacktime" and "fuzz" meta-protocols.
Hacktime is a bit of a joke inspired by the film "Kung Fury". It creates NTP time servers, both old-school and new-fashioned, and transmits either all 1s or all FFs, the idea being to emulate the rollover date for the Unix Millenium ("hacktime-2036") or a freshly booted system ("hacktime-1900"). Obviously the NTP server is a lot more complicated than that and it probably won't work, but it will definitely confuse any hackers who attack you thinking you are an NTP server!
Fuzz is just that - an attempt to mess with automated attacks by throwing random garbage at them. Again, this is experimental and I don't necceserily take it massively seriously, but I thought someone might find it useful so it stays in.
The HTTP server looks for a file called "webpage.html". If it doesnt' find it, it generates a simple 404 page instead. Again, it's not brilliant- this programs more about helping you check out the exotic, random clients that try to connect to you rather than boring old web spiders.
Note that if you open it in a Web browser you will see a lot of "HTTP/1.1 200 OK" strings below the content; this is because it's not meant to be opened in a Web browser, it's meant to keep potentially malicious webcrawling bots on the line for as long as possible.
Feel free to replace the default webpage.html with your own, of course - while you are welcome to use it, it is designed for demonstration purposes.
The -transblank options allow you to override fake server creation. So if you invoke
malbait.pl -port:23 -proto:transblank
or
malbait.pl -proto:telnet -transblank
malbait will transmit the closest thing to a blank response (a single, solitary carraige return) to clients instead of creating a "Telnet server".
Various options have been provided for lovers of computer exotica.
-noloop: Doesn't loop, ie, kills each server after one connection. If it's a UDP server, kills it after the client has entered a "command".