
आभासी हनीपॉट्स
Honeyd एक छोटा डेमन है जो नेटवर्क पर वर्चुअल होस्ट बनाता है। होस्टों को मनमानी सेवाएँ चलाने के लिए कॉन्फ़िगर किया जा सकता है, और उनके TCP पर्सनैलिटी को इस प्रकार अनुकूलित किया जा सकता है कि वे ऑपरेटिंग सिस्टम के विशेष संस्करण चला रहे हों। Honeyd एक ही होस्ट को नेटवर्क सिमुलेशन के लिए LAN पर कई एड्रेस - मैंने 65536 तक परीक्षण किया है - अपनाने में सक्षम बनाता है।
वर्चुअल मशीनों को पिंग करना या उनका ट्रेसरूट करना संभव है। वर्चुअल मशीन पर किसी भी प्रकार की सेवा को एक साधारण कॉन्फ़िगरेशन फ़ाइल के अनुसार सिमुलेट किया जा सकता है। किसी सेवा को सिमुलेट करने के बजाय, उसे किसी अन्य मशीन पर प्रॉक्सी करना भी संभव है।
Honeyd कई लाइब्रेरीज़ पर निर्भर करता है:
सुनिश्चित करें कि आपने उन्हें इंस्टॉल किया है।
Ubuntu में निर्भरताएँ इंस्टॉल करने के लिए:
$ sudo apt-get install libevent-dev libdumbnet-dev libpcap-dev libpcre3-dev libedit-dev bison flex libtool automake
ArchLinux में निर्भरताएँ इंस्टॉल करने के लिए:
$ pacman -S libdnet libpcap libevent pcre libedit bison flex libtool automake
रिग्रेशन फ्रेमवर्क चलाने के लिए, आपको libdnet के लिए Python मॉड्यूल इंस्टॉल करना होगा। सर्वोत्तम परिणामों के लिए आपको Python 2.4 की आवश्यकता हो सकती है।
honeyd बनाने के लिए, निम्नलिखित कमांड चलाएँ:
$ ./autogen.sh $ ./configure $ make $ sudo make install
यदि आपका कंपाइलेशन Python संबंधित त्रुटियों के कारण रुक जाता है, तो आप configure को इस प्रकार चलाने का प्रयास कर सकते हैं
$ ./configure --without-python
यदि आपको Linux पर कंपाइलेशन वार्निंग मिलती हैं तो कंडीशनल हेडर फ़ाइल की मूर्खता के लिए ज़िम्मेदार लोगों से शिकायत करें।
आप इस रिलीज़ के भाग के रूप में दस्तावेज़ पा सकते हैं। मैनुअल पेज को निम्नलिखित कमांड के साथ एक्सेस किया जा सकता है:
$ man honeyd
या सोर्स निर्देशिका में
$ nroff -mdoc honeyd.8
अधिक जानकारी http://www.honeyd.org/ और https://github.com/DataSoft/Honeyd पर पाई जा सकती है।
Honeyd को निष्पादन के लिए रूट-विशेषाधिकारों की आवश्यकता होती है। सामान्यतः, आप इसे निम्नलिखित के समान तर्कों के साथ चलाते हैं:
$ sudo ./honeyd -d -f config.sample 10.0.0.0/8
यह दृढ़ता से अनुशंसित है कि आप Honeyd को systrace जैसे सैंडबॉक्स के अंतर्गत chroot वातावरण में चलाएँ। यदि संभव हो, तो Honeyd अपने raw sockets बनाने के बाद विशेषाधिकार छोड़ देता है। यह आपकी कॉन्फ़िगरेशन फ़ाइल पर निर्भर करता है। आप -u और -g फ़्लैग के माध्यम से Honeyd की uid और gid सेट करके विशेषाधिकार छोड़ने के लिए बाध्य कर सकते हैं।
OS स्कैन परिणामों की गुणवत्ता को अनुभवजन्य रूप से सत्यापित करने के लिए, ostest नामक एक bash स्क्रिप्ट शामिल है। हालाँकि, इसके साथ कुछ समस्याएँ हैं। सामान्यतः, honeyd रूटिंग लूप से बचने के लिए उसी मशीन से आने वाले पैकेटों को अनदेखा करता है जिस पर यह चल रहा है। (या कम से कम यह ऐसा दावा करता है) इसलिए स्वयं को स्कैन करना काम नहीं करता।
इसे काम करने के लिए एक भद्दा हैक एक अलग हार्डवेयर ईथरनेट इंटरफ़ेस का उपयोग करना है, जैसे कि सस्ता usb-ethernet एडाप्टर। फिर आपके पास दो eth एडाप्टर होंगे, उन्हें eth0 और eth1 कहें। एक रूट सेट करें ताकि ostest को दिया गया IP एड्रेस eth0 पर रूट हो रहा हो। फिर आप honeyd को eth1 पर सुनने के लिए सेट करें।
Honeyd eth0 से आने वाले पैकेटों को देखेगा और मान लेगा कि यह हमारी मशीन से भिन्न एक मशीन है, और उन्हें ड्रॉप नहीं करेगा।
This program is free software; you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation; either version 2 of the License, or (at your option) any later version.
This program is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details.
You should have received a copy of the GNU General Public License along with this program; if not, write to the Free Software Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA This program is free software; you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation; either version 2 of the License, or (at your option) any later version.
This program is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details.
You should have received a copy of the GNU General Public License along with this program; if not, write to the Free Software Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
निम्नलिखित लोगों ने सुझावों, विचारों या कोड के साथ मदद की है:
Dug Song [email protected] Jamie Van Randwyk [email protected] Eric Thomas [email protected] Christopher Kolina Derek Cotton Yuqing Mai Lance Spitzner [email protected] Christian Kreibich [email protected] Bill Cheswick [email protected] Lauren Oudot [email protected] Jon Oberheide [email protected] David Clark [email protected] Dan Petro [email protected] David Scott [email protected] Addison Waldow [email protected] Rami Rashid [email protected]