this post was submitted on 14 May 2024
25 points (96.3% liked)

homelab

6374 readers
3 users here now

founded 4 years ago
MODERATORS
25
Homelab Honeypot (lemmy.world)
submitted 3 months ago* (last edited 3 months ago) by [email protected] to c/[email protected]
 

I recently installed an instance of TPot Honeypot, and it looks and feels pretty fantastic.

I haven't opened it up to the whole world, because my goal here was to just have the same ports I expose for my personal projects (game server, matrix chat, wireguard, etc) be exposed to it.

I know this project is a bit overkill for this use case, since it comes with a ton of honeypots that I'm not using, and that I'm essentially trying to make a fancy IDS, however I have a couple questions.

  1. Is it possible to add custom ports for honeypots that aren't included in the project? For example, if I have a game running on port 4567 and there is no honeypot for that, I won't see any activity.

  2. Is there another (perhaps lighter) Honeypot that you guys would recommend?

Edit: I guess disregard. I realize now that I can't have honeypots running on the same ports as the services in which I'm wanting to monitor. Port forwarding from WAN to multiple devices using the same port won't work

top 5 comments
sorted by: hot top controversial new old
[–] [email protected] 7 points 3 months ago* (last edited 3 months ago)

The T-Pot installation needs at least 8-16 GB RAM, 128 GB free disk space

Good lord.

And fuck curl-bash script installers.

[–] scottmeme 6 points 3 months ago (1 children)

HOLY SHIT! That's a long ass docker compose

[–] [email protected] 4 points 3 months ago

820 lines, you weren't kidding.

[–] [email protected] 1 points 3 months ago (1 children)

Glad you figured your edit out before you got too deep. Yeah, port forwarding is a tricky beast, because there’s no “good” way to do it. Either you have open ports exposed to the internet, or you have everything bouncing off of a third-party service. Neither option is great.

[–] [email protected] 1 points 3 months ago

Yeah, such a nightmare, lol. If I ever feel like hosting a honeypot I'll probably DMZ it or use a VPS or something, but I'm going to change gears on projects for now.