- Home
- Security Operations
- Honeypots & Deception
- Telnetlogger

Telnetlogger
A simple Telnet honeypot program that logs login attempts and credentials from botnet attacks, specifically designed to track Mirai botnet activity.

Telnetlogger
A simple Telnet honeypot program that logs login attempts and credentials from botnet attacks, specifically designed to track Mirai botnet activity.
Telnetlogger Description
Telnetlogger is a lightweight program designed to log login attempts on Telnet port 23, specifically created to track activity from the Mirai botnet. The tool captures both IP addresses attempting connections and the passwords being used in brute force attacks. It was developed as an alternative to traditional telnetd installations, which the Mirai botnet reportedly does not interact with properly. Key features include: - Real-time logging of Telnet login attempts to stdout - Optional file output for passwords and IP addresses using -p and -i flags - Configurable port listening with -l option for testing purposes - Built-in parsing capabilities to extract usernames and passwords from connection attempts The program requires elevated privileges (sudo) on many systems when binding to ports below 1024. It provides a simple compilation process using make and is particularly useful for security researchers studying botnet behavior and attack patterns targeting IoT devices.
FEATURED
Password manager with end-to-end encryption and identity protection features
VPN service providing encrypted internet connections and privacy protection
Fractional CISO services for B2B companies to accelerate sales and compliance
Stay Updated with Mandos Brief
Get the latest cybersecurity updates in your inbox
TRENDING CATEGORIES
POPULAR
A cybersecurity platform that offers vulnerability scanning, Windows Defender and 3rd party AV management, and MFA compliance reporting, among other features.
Security platform that provides protection, monitoring and governance for enterprise generative AI applications and LLMs against various threats including prompt injection and data poisoning.
A threat intelligence aggregation service that consolidates and summarizes security updates from multiple sources to provide comprehensive cybersecurity situational awareness.
Fabric Platform is a cybersecurity reporting solution that automates and standardizes report generation, offering a private-cloud platform, open-source tools, and community-supported templates.
A weekly newsletter providing cybersecurity leadership insights, industry updates, and strategic guidance for security professionals advancing to management positions.