vnclowpot Logo

vnclowpot

0
Free
Visit Website

Low-interaction VNC honeypot that listens on a port and logs responses to a static VNC Auth challenge. It was inspired by VNC-Pot, but does not have any dependencies outside the go standard library. Setup and Install: go get github.com/magisterquis/vnclowpot go install github.com/magisterquis/vnclowpot vnclowpot Options: There are only two options: The listen address can be changed with -l. John The Ripper-compatible lines can be generated with -j (and will need to be extracted from the log messages with something like cut -f 4 -d ' '). Pull requests are welcome. Cracker: In the cracker directory, there is a simple program to try to crack the handshakes logged in John The Ripper format. See its README for more details. Tester: In the tester directory, there is a simple program to generate VNC authentication attempts, for use in testing vnclowpot, as well as being production-grade for pentesting. See its README for more details. Windows: Should probably work.

FEATURES

ALTERNATIVES

A low-interaction honeypot that logs IP addresses, usernames, and passwords used by clients connecting via SSH, primarily used for gathering intelligence on brute force attacks.

Django App for the SSH Honeypot called 'kippo'

RDP based Honeypot that creates virtual machines for incoming connections and analyzes traffic with Suricata.

A simple Elasticsearch honeypot to catch attackers exploiting RCE vulnerabilities.

A low-interaction honeypot to detect and analyze attempts to exploit the CVE-2017-10271 vulnerability in Oracle WebLogic Server

Medium interaction SSH Honeypot with multiple virtual hosts and sandboxed filesystems.

Honeypot for Telnet service with configurable settings.

A simple honeypot that collects credentials across various protocols