53
submitted 3 years ago* (last edited 3 years ago) by KLISHDFSDF@lemmy.ml to c/selfhosted@lemmy.world

but before I do, I figured I'd ask if anyone's aware of any tools/software that covers my basic needs of setting something basic that may alert me if there are any intruders in the network?

Needs:

  1. Fake ssh login that can trigger a script so I can take care of the rest.
  2. Fake network share (cifs/samba) that can trigger a script if anything tries to access it.

Would be great if there are any docker images I can just pull, make some minor edits, and run.

Thanks!

top 18 comments
sorted by: hot top new old
[-] blarg_dunsen@sh.itjust.works 30 points 3 years ago

People were close, but what you actually want is OpenCanary. It fakes SSH and Samba services and can be configured to alert you when triggered.

[-] notexecutive@sh.itjust.works 22 points 3 years ago
[-] KLISHDFSDF@lemmy.ml 27 points 3 years ago

I plan on making it available inside my own network, not public. This way if someone makes it past my security, I at least have something that might "catch" them in the act and disable my network so I can intervene. Just another security layer.

[-] chandz05@lemmy.world 3 points 3 years ago

I have never thought about doing this... But this is actually such a good idea. I'm probably going to set this up myself

[-] lilShalom@lemmy.basedcount.com 19 points 3 years ago

If you place this on the inside of your network and it triggers, youre either compromised or a scanner/ person triggered it.

[-] finestnothing@lemmy.world 1 points 3 years ago

That's the idea I think

[-] recursive_recursion@programming.dev 14 points 3 years ago* (last edited 3 years ago)

one of the best ways to protect your friends is to leave juicy bait that only zero-sum people would try to steal

plus wasting malicious user's time also provides multiple benefits such as reducing the prevalence of spam and DDoS attacks

[-] FuntyMcCraiger@sh.itjust.works 9 points 3 years ago

Do you not feel the itch of curiosity?

[-] Smk@lemmy.ca 3 points 3 years ago

FOR SCIENCE!1!!

[-] waspentalive@lemmy.one 7 points 3 years ago

I am not affiliated with them, but you can get a trigger file (Canary Token) from the people at Thinkst. I quickly looked around their site, and did not see how, but their adds say you can get them for free, without having to buy their canary hardware device.

[-] Racle@sopuli.xyz 5 points 3 years ago* (last edited 3 years ago)

you can get them for free

https://canarytokens.org/generate should work just fine

[-] anzo@programming.dev 6 points 3 years ago
[-] lilShalom@lemmy.basedcount.com 5 points 3 years ago

You can also use something called canary tokens. You would put a file on a share that triggers an action to alert you.

[-] Bristlerock@kbin.social 4 points 3 years ago

The Honeynet Project, related to the SANS Institute when I last checked, has a lot of resources on honeypots that are worth a look, if you haven't already.

[-] electromage@lemm.ee 3 points 3 years ago

I'd like to create a funnypot

[-] matejc@matejc.com 1 points 3 years ago
[-] iMeddles@infosec.pub 1 points 3 years ago

Thinkst have also published opencanary which you can run yourself and contains a decent subset of what their hardware canaries run, including SSH and cifs.

[-] lilShalom@lemmy.basedcount.com -1 points 3 years ago
this post was submitted on 05 Sep 2023
53 points (92.1% liked)

Selfhosted

61853 readers
400 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

Detailed Rules Post

  1. Be civil.

  2. No spam.

  3. Posts are to be related to self-hosting.

  4. Don't duplicate the full text of your blog or readme if you're providing a link.

  5. Submission headline should match the article title.

  6. No trolling.

  7. Promotion posts require active participation, with an account that is at least 30 days old. F/LOSS without a paywall has exceptions, with requirements. See the rules link for details. Tags [CBH] or [AIP] are required, see the links in Rule 8 for details.

  8. AI-related discussions and AI-involved promotional posts have additional requirements for tagging, as noted in Rule 7 and the AI & Promotional Post Expanded Rules post, and find example disclosures here.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 3 years ago
MODERATORS