ssh-auth-logger Logo

ssh-auth-logger

0
Free
Visit Website

A low/zero interaction ssh authentication logging honeypot. Structured logging ssh-auth-logger logs all authentication attempts as json making it easy to consume in other tools. No more ugly openssh log parsing vulnerabilities. This is normally logged on one line { "client_version": "SSH-2.0-libssh2_1.4.3", "destinationServicename": "sshd", "dpt": "22", "dst": "192.168.1.2", "duser": "root", "level": "info", "msg": "Request with password", "password": "P@ssword1", "product": "ssh-auth-logger", "server_version": "SSH-2.0-OpenSSH_5.3", "spt": "38624", "src": "192.168.1.4", "time": "2017-11-17T19:16:37-05:00" }

FEATURES

ALTERNATIVES

A Python-based honeypot service for SSH, FTP, and Telnet connections

A honeypot tool that simulates an open relay to capture and analyze spam

A honeypot for Intel's AMT Firmware Vulnerability CVE-2017-5689

SMTP Honeypot with custom modules for different modes of operation.

A tool for testing subdomain takeover possibilities at a mass scale.

A FTP honeypot tool for detecting and capturing malicious file upload attempts.

A project providing honeypots for embedded device vulnerabilities with support for AWS integration and JSON output.

A DNS server for executing DNS Rebinding attacks