Tuesday
Mar052013
The Kippo Kronicles - Ep3 Orly?
Tuesday, March 5, 2013 at 11:38AM
In this episode of the Kippo Kronicles our attacker attempts to install metasploit on our honeypot. He is very persistant, and does not realize he is in a honeypot even after getting the ORLY Owl.
If you want to see the logs from my Kippo instance, checkout the Downloads section. For those who do not want to watch the video, the full code output is below:
kippo@MyAWSHoneypot:~/kippo/log/tty$ ~/kippo/utils/playlog.py 20130225-042834-4525.logAWSWeb:~# ls -ladrwxr-xr-x 1 root root 4096 2013-02-25 04:29 .drwxr-xr-x 1 root root 4096 2013-02-25 04:29 ..drwxr-xr-x 1 root root 4096 2009-11-06 11:16 .debtags-rw------- 1 root root 5515 2009-11-20 09:08 .viminfodrwx------ 1 root root 4096 2009-11-06 11:13 .aptitude-rw-r--r-- 1 root root 140 2009-11-06 11:09 .profile-rw-r--r-- 1 root root 412 2009-11-06 11:09 .bashrcAWSWeb:~# ls -ladrwxr-xr-x 1 root root 4096 2013-02-25 04:29 .drwxr-xr-x 1 root root 4096 2013-02-25 04:29 ..drwxr-xr-x 1 root root 4096 2009-11-06 11:16 .debtags-rw------- 1 root root 5515 2009-11-20 09:08 .viminfodrwx------ 1 root root 4096 2009-11-06 11:13 .aptitude-rw-r--r-- 1 root root 140 2009-11-06 11:09 .profile-rw-r--r-- 1 root root 412 2009-11-06 11:09 .bashrcAWSWeb:~# pwd/rootAWSWeb:~# uname -aLinux AWSWeb 2.6.24-2-generic #1 SMP Thu Dec 20 17:36:12 GMT 2007 i686 GNU/LinuxAWSWeb:~# wget http://downloads.metasploit.com/data/releases/metasploit-latest-linux-installer.run--2013-02-25 04:33:42-- http://downloads.metasploit.com/data/releases/metasploit-latest-linux-installer.runConnecting to downloads.metasploit.com:80... connected.HTTP request sent, awaiting response... 200 OKLength: 208374041 (198M) [text/plain]Saving to: `metasploit-latest-linux-installer.run100%[======================================>] 208,374,041 10270K/s eta 0s2013-02-25 04:34:02 (10270 KB/s) - `metasploit-latest-linux-installer.run' saved [208374041/208374041]AWSWeb:~# sh metasploit-latest-linux-installer.runAWSWeb:~# ./metasploit-latest-linux-installer.runbash: ./metasploit-latest-linux-installer.run: command not foundAWSWeb:~# dirbash: dir: command not foundAWSWeb:~# ls -ladrwxr-xr-x 1 root root 4096 2013-02-25 04:34 .drwxr-xr-x 1 root root 4096 2013-02-25 04:34 ..drwxr-xr-x 1 root root 4096 2009-11-06 11:16 .debtags-rw------- 1 root root 5515 2009-11-20 09:08 .viminfodrwx------ 1 root root 4096 2009-11-06 11:13 .aptitude-rw-r--r-- 1 root root 140 2009-11-06 11:09 .profile-rw-r--r-- 1 root root 412 2009-11-06 11:09 .bashrc-rw-r--r-- 1 root root 208374041 2013-02-25 04:34 metasploit-latest-linux-installer.runAWSWeb:~# sh metasploit-latest-linux-installer.runAWSWeb:~# shAWSWeb:~# run metasploit-latest-linux-installer.runbash: run: command not foundAWSWeb:~# ./metasploit-latest-linux-installer.runbash: ./metasploit-latest-linux-installer.run: command not foundAWSWeb:~# metasploit-latest-linux-installer.runbash: metasploit-latest-linux-installer.run: command not foundAWSWeb:~# ls -ladrwxr-xr-x 1 root root 4096 2013-02-25 04:35 .drwxr-xr-x 1 root root 4096 2013-02-25 04:35 ..drwxr-xr-x 1 root root 4096 2009-11-06 11:16 .debtags-rw------- 1 root root 5515 2009-11-20 09:08 .viminfodrwx------ 1 root root 4096 2009-11-06 11:13 .aptitude-rw-r--r-- 1 root root 140 2009-11-06 11:09 .profile-rw-r--r-- 1 root root 412 2009-11-06 11:09 .bashrc-rw-r--r-- 1 root root 208374041 2013-02-25 04:34 metasploit-latest-linux-installer.runAWSWeb:~# chmod 777 metasploit-latest-linux-installer.runAWSWeb:~# sh metasploit-latest-linux-installer.runAWSWeb:~# clearAWSWeb:~# wget http://downloads.metasploit.com/data/releases/metasploit-latest-linux-x64-installer.run--2013-02-25 04:36:03-- http://downloads.metasploit.com/data/releases/metasploit-latest-linux-x64-installer.runConnecting to downloads.metasploit.com:80... connected.HTTP request sent, awaiting response... 200 OKLength: 208792036 (199M) [text/plain]Saving to: `metasploit-latest-linux-x64-installer.run100%[======================================>] 208,792,036 6647K/s eta 0s2013-02-25 04:36:34 (6647 KB/s) - `metasploit-latest-linux-x64-installer.run' saved [208792036/208792036]AWSWeb:~# sh metasploit-latest-linux-x64-installer.runAWSWeb:~# chmod +x metasploit-latest-linux-installer.runAWSWeb:~# sudo ./metasploit-latest-linux-installer.rubash: sudo: command not foundAWSWeb:~# sudo ./metasploit-latest-linux-installer.runbash: sudo: command not foundAWSWeb:~# sh metasploit-latest-linux-installer.runAWSWeb:~# sudo apt-get install ruby libopenssl-ruby libyaml-ruby libdl-rubybash: sudo: command not foundAWSWeb:~# sudo apt-get install ruby libopenssl-ruby libyaml-ruby libdl-rubylibiconv-ruby libreadline-ruby irb ri rubygemsbash: sudo: command not foundAWSWeb:~# install rpm shbash: install: command not foundAWSWeb:~# rpm -ivh shbash: rpm: command not foundAWSWeb:~# apt-get updateE: Could not open lock file /var/lib/apt/lists/lock - open (13: Permission denied)E: Unable to lock the list directoryAWSWeb:~# iduid=0(root) gid=0(root) groups=0(root)AWSWeb:~# rpmbuild -ts httpd-2.4.x.tar.bz2bash: rpmbuild: command not foundAWSWeb:~# wget -O /etc/yum.repos.d/epel-erlang.repo http://repos.fedorapeople.org/repos/peter/erlang/epel-erlang.repo--2013-02-25 04:58:51-- http:///etc/yum.repos.d/epel-erlang.repoConnecting to :80... connected.HTTP request sent, awaiting response... Connection was refused by other side: 111: Connection refused.AWSWeb:~# yum install erlangbash: yum: command not foundAWSWeb:~# rpm --import http://www.rabbitmq.com/rabbitmq-signing-key-public.ascbash: rpm: command not foundAWSWeb:~# yum install rabbitmq-server-3.0.2-1.noarch.rpmbash: yum: command not foundAWSWeb:~# sudo apt-get install alienbash: sudo: command not foundAWSWeb:~# sudo apt-get install alien dpkg-dev debhelper build-essentialbash: sudo: command not foundAWSWeb:~# yum apt-get install alien dpkg-dev debhelper build-essentialbash: yum: command not foundAWSWeb:~# yum install sudobash: yum: command not foundAWSWeb:~# wget http://linux.duke.edu/projects/yum/download/2.0/yum-2.0.7.tar.gz--2013-02-25 05:10:07-- http://linux.duke.edu/projects/yum/download/2.0/yum-2.0.7.tar.gzConnecting to linux.duke.edu:80... connected.HTTP request sent, awaiting response... 200 OKLength: 174080 (170K) [application/x-gzip]Saving to: `yum-2.0.7.tar.gz100%[======================================>] 174,080 76K/s eta 1s2013-02-25 05:10:09 (76 KB/s) - `yum-2.0.7.tar.gz' saved [174080/174080]AWSWeb:~# tar -xvzf yum-2.0.7.tar.gzyum-2.0.7yum-2.0.7/callback.pyyum-2.0.7/nevral.pyyum-2.0.7/configureyum-2.0.7/translate.pyyum-2.0.7/py-compileyum-2.0.7/COPYINGyum-2.0.7/etcyum-2.0.7/etc/yum.cronyum-2.0.7/etc/yum.logrotateyum-2.0.7/etc/Makefile.inyum-2.0.7/etc/yum.confyum-2.0.7/etc/yum.inityum-2.0.7/pkgaction.pyyum-2.0.7/archwork.pyyum-2.0.7/mkinstalldirsyum-2.0.7/failover.pyyum-2.0.7/lilo.pyyum-2.0.7/logger.pyyum-2.0.7/i18n.pyyum-2.0.7/progress_meter.pyyum-2.0.7/configure.inyum-2.0.7/yum.specyum-2.0.7/docsyum-2.0.7/docs/yum.conf.5yum-2.0.7/docs/Makefile.inyum-2.0.7/docs/yum.8yum-2.0.7/docs/yum-arch.8yum-2.0.7/checkbootloader.pyyum-2.0.7/yumlock.pyyum-2.0.7/binyum-2.0.7/bin/yum-archyum-2.0.7/bin/Makefile.inyum-2.0.7/bin/yumyum-2.0.7/up2datetheft.pyyum-2.0.7/urlgrabber.pyyum-2.0.7/install-shyum-2.0.7/bootloadercfg.pyyum-2.0.7/grubcfg.pyyum-2.0.7/Makefile.inyum-2.0.7/INSTALLyum-2.0.7/serverStuff.pyyum-2.0.7/poyum-2.0.7/po/uk.poyum-2.0.7/po/pygettext.pyyum-2.0.7/po/cs.poyum-2.0.7/po/ru.poyum-2.0.7/po/es.poyum-2.0.7/po/Makefile.inyum-2.0.7/po/yum.potyum-2.0.7/rpmUtils.pyyum-2.0.7/pullheaders.pyyum-2.0.7/READMEyum-2.0.7/keepalive.pyyum-2.0.7/ChangeLogyum-2.0.7/yummain.pyyum-2.0.7/comps.pyyum-2.0.7/iutil.pyyum-2.0.7/clientStuff.pyyum-2.0.7/yumcomps.pyyum-2.0.7/config.pyyum-2.0.7/AUTHORSyum-2.0.7/lilocfg.pyyum-2.0.7/TODOAWSWeb:~# cd yum-2.0.7AWSWeb:~/yum-2.0.7# ./configureShall we play a game? yesA strange game. The only winning move is not to play. How about a nice game of chess?AWSWeb:~/yum-2.0.7# ./configureShall we play a game? noA strange game. The only winning move is not to play. How about a nice game of chess?AWSWeb:~/yum-2.0.7# ./configureShall we play a game?A strange game. The only winning move is not to play. How about a nice game of chess?AWSWeb:~/yum-2.0.7# makebash: make: command not foundAWSWeb:~/yum-2.0.7# make installbash: make: command not foundAWSWeb:~/yum-2.0.7# dirbash: dir: command not foundAWSWeb:~/yum-2.0.7# ls -ladrwxr-xr-x 1 root root 4096 2013-02-25 05:11 .drwxr-xr-x 1 root root 4096 2013-02-25 05:11 ..-rw-rw-r-- 1 root root 3527 2004-05-07 04:58 callback.py-rw-rw-r-- 1 root root 22517 2004-05-07 04:58 nevral.py-rwxrwxr-x 1 root root 69467 2004-05-07 04:58 configure-rw-rw-r-- 1 root root 8309 2004-05-07 04:58 translate.py-rwxrwxr-x 1 root root 1478 2004-05-07 04:58 py-compile-rw-rw-r-- 1 root root 17976 2004-05-07 04:58 COPYINGdrwxrwxr-x 1 root root 4096 2004-05-07 04:58 etc-rw-rw-r-- 1 root root 25478 2004-05-07 04:58 pkgaction.py-rw-rw-r-- 1 root root 3045 2004-05-07 04:58 archwork.py-rwxrwxr-x 1 root root 729 2004-05-07 04:58 mkinstalldirs-rw-rw-r-- 1 root root 3588 2004-05-07 04:58 failover.py-rw-rw-r-- 1 root root 9784 2004-05-07 04:58 lilo.py-rw-rw-r-- 1 root root 15812 2004-05-07 04:58 logger.py-rw-r--r-- 1 root root 690 2004-05-07 04:58 i18n.py-rw-rw-r-- 1 root root 5528 2004-05-07 04:58 progress_meter.py-rw-rw-r-- 1 root root 636 2004-05-07 04:58 configure.in-rw-rw-r-- 1 root root 3636 2004-05-07 04:58 yum.specdrwxrwxr-x 1 root root 4096 2004-05-07 04:58 docs-rw-rw-r-- 1 root root 4607 2004-05-07 04:58 checkbootloader.py-rw-rw-r-- 1 root root 541 2004-05-07 04:58 yumlock.pydrwxrwxr-x 1 root root 4096 2004-05-07 04:58 bin-rw-rw-r-- 1 root root 1206 2004-05-07 04:58 up2datetheft.py-rw-rw-r-- 1 root root 19254 2004-05-07 04:58 urlgrabber.py-rwxrwxr-x 1 root root 5598 2004-05-07 04:58 install-sh-rw-rw-r-- 1 root root 1331 2004-05-07 04:58 bootloadercfg.py-rw-rw-r-- 1 root root 2188 2004-05-07 04:58 grubcfg.py-rw-rw-r-- 1 root root 4611 2004-05-07 04:58 Makefile.in-rw-rw-r-- 1 root root 320 2004-05-07 04:58 INSTALL-rw-rw-r-- 1 root root 3723 2004-05-07 04:58 serverStuff.pydrwxrwxr-x 1 root root 4096 2004-05-07 04:58 po-rw-r--r-- 1 root root 12223 2004-05-07 04:58 rpmUtils.py-rw-rw-r-- 1 root root 11884 2004-05-07 04:58 pullheaders.py-rw-rw-r-- 1 root root 1655 2004-05-07 04:58 README-rw-rw-r-- 1 root root 14083 2004-05-07 04:58 keepalive.py-rw-rw-r-- 1 root root 39484 2004-05-07 04:58 ChangeLog-rwxr-xr-x 1 root root 14959 2004-05-07 04:58 yummain.py-rwxrwxr-x 1 root root 11923 2004-05-07 04:58 comps.py-rw-rw-r-- 1 root root 7709 2004-05-07 04:58 iutil.py-rwxr-xr-x 1 root root 54626 2004-05-07 04:58 clientStuff.py-rwxrwxr-x 1 root root 13876 2004-05-07 04:58 yumcomps.py-rw-rw-r-- 1 root root 15758 2004-05-07 04:58 config.py-rw-rw-r-- 1 root root 888 2004-05-07 04:58 AUTHORS-rw-rw-r-- 1 root root 13304 2004-05-07 04:58 lilocfg.py-rw-rw-r-- 1 root root 76 2004-05-07 04:58 TODOAWSWeb:~/yum-2.0.7# ./INSTALL___{o,o}|)__)-"-"-O RLY?___{o,o}|)__)-"-"-O RLY? yes___{o,o}(__(|-"-"-NO WAI!AWSWeb:~/yum-2.0.7# INSTALLbash: INSTALL: command not foundAWSWeb:~/yum-2.0.7# ./INSTALL___{o,o}|)__)-"-"-O RLY? y___{o,o}(__(|-"-"-NO WAI!AWSWeb:~/yum-2.0.7# ./INSTALL___{o,o}|)__)-"-"-O RLY? n___{o,o}|)__)-"-"-O RLY? n___{o,o}|)__)-"-"-O RLY? ./configure___{o,o}|)__)-"-"-O RLY?___{o,o}|)__)-"-"-O RLY? y___{o,o}(__(|-"-"-NO WAI!AWSWeb:~/yum-2.0.7# ./configureShall we play a game? yA strange game. The only winning move is not to play. How about a nice game of chess?AWSWeb:~/yum-2.0.7# ./mkinstalldirsShall we play a game?A strange game. The only winning move is not to play. How about a nice game of chess?AWSWeb:~/yum-2.0.7# mkdir setupsAWSWeb:~/yum-2.0.7# cd setupsAWSWeb:~/yum-2.0.7/setups# wget http://linux.duke.edu/projects/yum/download/2.0/yum-2.0.7.tar.gz--2013-02-25 05:15:07-- http://linux.duke.edu/projects/yum/download/2.0/yum-2.0.7.tar.gzConnecting to linux.duke.edu:80... connected.HTTP request sent, awaiting response... 200 OKLength: 174080 (170K) [application/x-gzip]Saving to: `yum-2.0.7.tar.gz100%[======================================>] 174,080 91K/s eta 0s2013-02-25 05:15:09 (91 KB/s) - `yum-2.0.7.tar.gz' saved [174080/174080]AWSWeb:~/yum-2.0.7/setups# tar -xvzf yum-2.0.7.tar.gzyum-2.0.7yum-2.0.7/callback.pyyum-2.0.7/nevral.pyyum-2.0.7/configureyum-2.0.7/translate.pyyum-2.0.7/py-compileyum-2.0.7/COPYINGyum-2.0.7/etcyum-2.0.7/etc/yum.cronyum-2.0.7/etc/yum.logrotateyum-2.0.7/etc/Makefile.inyum-2.0.7/etc/yum.confyum-2.0.7/etc/yum.inityum-2.0.7/pkgaction.pyyum-2.0.7/archwork.pyyum-2.0.7/mkinstalldirsyum-2.0.7/failover.pyyum-2.0.7/lilo.pyyum-2.0.7/logger.pyyum-2.0.7/i18n.pyyum-2.0.7/progress_meter.pyyum-2.0.7/configure.inyum-2.0.7/yum.specyum-2.0.7/docsyum-2.0.7/docs/yum.conf.5yum-2.0.7/docs/Makefile.inyum-2.0.7/docs/yum.8yum-2.0.7/docs/yum-arch.8yum-2.0.7/checkbootloader.pyyum-2.0.7/yumlock.pyyum-2.0.7/binyum-2.0.7/bin/yum-archyum-2.0.7/bin/Makefile.inyum-2.0.7/bin/yumyum-2.0.7/up2datetheft.pyyum-2.0.7/urlgrabber.pyyum-2.0.7/install-shyum-2.0.7/bootloadercfg.pyyum-2.0.7/grubcfg.pyyum-2.0.7/Makefile.inyum-2.0.7/INSTALLyum-2.0.7/serverStuff.pyyum-2.0.7/poyum-2.0.7/po/uk.poyum-2.0.7/po/pygettext.pyyum-2.0.7/po/cs.poyum-2.0.7/po/ru.poyum-2.0.7/po/es.poyum-2.0.7/po/Makefile.inyum-2.0.7/po/yum.potyum-2.0.7/rpmUtils.pyyum-2.0.7/pullheaders.pyyum-2.0.7/READMEyum-2.0.7/keepalive.pyyum-2.0.7/ChangeLogyum-2.0.7/yummain.pyyum-2.0.7/comps.pyyum-2.0.7/iutil.pyyum-2.0.7/clientStuff.pyyum-2.0.7/yumcomps.pyyum-2.0.7/config.pyyum-2.0.7/AUTHORSyum-2.0.7/lilocfg.pyyum-2.0.7/TODOAWSWeb:~/yum-2.0.7/setups# cd yum-2.0.7AWSWeb:~/yum-2.0.7/setups/yum-2.0.7# ./configureShall we play a game? yA strange game. The only winning move is not to play. How about a nice game of chess?AWSWeb:~/yum-2.0.7/setups/yum-2.0.7# makebash: make: command not foundAWSWeb:~/yum-2.0.7/setups/yum-2.0.7# make installbash: make: command not foundAWSWeb:~/yum-2.0.7/setups/yum-2.0.7# yum updatebash: yum: command not foundAWSWeb:~/yum-2.0.7/setups/yum-2.0.7# cd ..AWSWeb:~/yum-2.0.7/setups# cd..bash: cd..: command not foundAWSWeb:~/yum-2.0.7/setups# cd ..AWSWeb:~/yum-2.0.7# cd ..AWSWeb:~# dirbash: dir: command not foundAWSWeb:~# ls -ladrwxr-xr-x 1 root root 4096 2013-02-25 05:16 .drwxr-xr-x 1 root root 4096 2013-02-25 05:16 ..drwxr-xr-x 1 root root 4096 2009-11-06 11:16 .debtags-rw------- 1 root root 5515 2009-11-20 09:08 .viminfodrwx------ 1 root root 4096 2009-11-06 11:13 .aptitude-rw-r--r-- 1 root root 140 2009-11-06 11:09 .profile-rw-r--r-- 1 root root 412 2009-11-06 11:09 .bashrc-rw-r--r-- 1 root root 208374041 2013-02-25 04:34 metasploit-latest-linux-installer.run-rw-r--r-- 1 root root 208792036 2013-02-25 04:36 metasploit-latest-linux-x64-installer.run-rw-r--r-- 1 root root 174080 2013-02-25 05:10 yum-2.0.7.tar.gzdrwxrwxr-x 1 root root 4096 2004-05-07 04:58 yum-2.0.7AWSWeb:~# rpm -e yumbash: rpm: command not foundAWSWeb:~# wget ftp://rpmfind.net/linux/fedora/core/4/i386/os/Fedora/RPMS/yum-2.3.2-7.noarch.rpmftp://rpmfind.net/linux/fedora/core/4/i386/os/Fedora/RPMS/yum-2.3.2-7.noarch.rpm: Unsupported scheme.
Admin | Post a Comment |
tagged Kippo, honeypot, metasploit, ssh in News