-
Notifications
You must be signed in to change notification settings - Fork 46
/
Copy pathsshhipot.go
163 lines (152 loc) · 2.94 KB
/
sshhipot.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
package main
/*
* sshhipot.go
* Hi-interaction ssh honeypot
* By J. Stuart McMurray
* Created 20160514
* Last Modified 20160605
*/
import (
"flag"
"fmt"
"log"
"net"
"os"
"strings"
)
func main() {
/* Network addresses */
var laddr = flag.String(
"l",
":2222",
"Listen `address`",
)
var noAuthOk = flag.Bool(
"A",
false,
"Allow clients to connect without authentication",
)
var serverVersion = flag.String(
"v",
"SSH-2.0-OpenSSH_7.2",
"Server `version` to present to clients",
/* TODO: Get from real server */
)
var password = flag.String(
"p",
"hunter2",
"Allowed `password`",
)
var passList = flag.String(
"pf",
"",
"Password `file` with one password per line",
)
var passProb = flag.Float64(
"pp",
.05,
"Accept any password with this `probability`",
)
var kicHost = flag.String(
"H",
"localhost",
"Keyboard-Interactive challenge `hostname`",
)
var keyName = flag.String(
"k",
"shp_id_rsa",
"SSH RSA `key`, which will be created if it does not exist",
)
/* Logging */
var logDir = flag.String(
"d",
"conns",
"Per-connection log `directory`",
)
var hideBanners = flag.Bool(
"B",
false,
"Don't log connections with no authentication attempts (banners).",
)
/* Client */
var cUser = flag.String(
"cu",
"root",
"Upstream `username`",
)
var cKey = flag.String(
"ck",
"id_rsa",
"RSA `key` to use as a client, "+
"which will be created if it does not exist",
)
var saddr = flag.String(
"cs",
"192.168.0.2:22",
"Real server `address`",
)
var fingerprint = flag.String(
"sf",
"",
"Real server host key `fingerprint`",
)
/* Local server config */
flag.Usage = func() {
fmt.Fprintf(
os.Stderr,
`Usage: %v [options]
Options:
`,
os.Args[0],
)
flag.PrintDefaults()
}
flag.Parse()
/* Log better */
log.SetFlags(log.LstdFlags | log.Lmicroseconds)
log.SetOutput(os.Stdout)
/* TODO: Log target server */
/* Make a server config */
sc := makeServerConfig(
*noAuthOk,
*serverVersion,
*password,
*passList,
*passProb,
*kicHost,
*keyName,
)
/* Make a client config */
cc := makeClientConfig(*cUser, *cKey, *fingerprint)
/* Listen for clients */
l, err := net.Listen("tcp", addSSHPort(*laddr))
if nil != err {
log.Fatalf("Unable to listen on %v: %v", *laddr, err)
}
log.Printf("Listening on %v", l.Addr())
/* Accept clients, handle */
for {
c, err := l.Accept()
if nil != err {
log.Fatalf("Unable to accept client: %v", err)
}
go handle(c, sc, *saddr, cc, *logDir, *hideBanners)
}
}
/* addSSHPort adds the default SSH port to an address if it has no port. */
func addSSHPort(addr string) string {
/* Make sure we have a port */
_, _, err := net.SplitHostPort(addr)
if nil != err {
if !strings.HasPrefix(err.Error(), "missing port in address") {
log.Fatalf(
"Unable to check for port in %q: %v",
addr,
err,
)
}
addr = net.JoinHostPort(addr, "ssh")
}
return addr
}
/* TODO: Log to stdout or logfile */