honey
Description
Honey is a multi-protocol honeypot for analyzing external bots that scan, probe and attack servers. It emulates several common network services with realistic banners and login scenarios, lures automated attack tools into interacting with it and silently records all credential brute-force attempts.
Honey runs as a single Go binary and simultaneously listens on five standard service ports: Telnet (23, emulating a BCM96318 broadband router), SSH (22, dropbear 0.53.1 of an embedded device), HTTP (80, a WordPress 6.8.2 site or a Basic Authentication service), HTTPS (443, a WordPress 6.8.2 site or a Basic Authentication service), FTP (21, a file server). All services share a single on-disk virtual file tree rooted at root/, each service locked into a subtree of that tree (configured via *_path parameters). By default the honeypot is fully passive: it never executes attacker commands and never grants access - every interaction is observed, recorded and rejected. Optionally, per service, emulation modes can be enabled that provide a jailed session (a restricted shell or file root the attacker cannot escape), luring interactive attackers into running commands, all of which are recorded. Both modes are safe to expose on a public IP address.
Modules used
- golang.org/x/crypto/ssh - base SSH protocol implementation (key exchange, cryptography, authentication)
- github.com/anmitsu/go-shlex - shell-style splitting of SSH command lines into words for parsing
- gliderlabs/ssh (vendor) - high-level SSH server framework: session handling, password auth callbacks, TCP/IP forwarding, keep-alive
- reiver/go-telnet (vendor) - Telnet server: protocol negotiation, connection handling, optional TLS
- reiver/go-telnet/telsh (vendor) - Telnet shell layer: login/password prompts, command registration and dispatch
- reiver/go-oi (vendor) - I/O primitives (long writes, rewindable readable streams) used by the Telnet stack
- goftp (vendor) - FTP server: command handling, authentication, passive/active data connections, plus a file driver
Technologies
- Go 1.21+ - the whole honeypot is written in Go and compiles into a single static binary
- golang.org/x/crypto/ssh - SSH protocol implementation (key exchange, cryptography, authentication) used by the SSH honeypot
- github.com/anmitsu/go-shlex - shell-style splitting of SSH command lines into words
- Vendored protocol stacks - the Telnet, FTP and SSH server frameworks are committed to the repository, so the project builds reproducibly using only the two external modules listed above
- License GNU AGPL v3 (Affero GPL)