Reinstall Dionaea, Glastopf, Kippo

661 views
Skip to first unread message

Kenneth M. S. LAU

unread,
Dec 18, 2014, 3:20:54 AM12/18/14
to modern-hon...@googlegroups.com

Dear sir / madam,

 

My installation of some honeypots are not successful.  What is the procedure to remove and reinstall Dionaea, Glastopf and Kippo?

 

Kenneth Lau

ASTRI

Jason Trost

unread,
Dec 19, 2014, 8:46:34 AM12/19/14
to Kenneth M. S. LAU, modern-hon...@googlegroups.com
This should be the steps:

1. Go to the sensors page in MHN, find the sensor you want to re-install and delete it
2. On the sensor box, if the honeypot/sensor was installed to /opt/$SENSOR then remove this directory.  This is how every sensor except dionaea is installed.
3. On the sensor box, run the deployment script.

--
You received this message because you are subscribed to the Google Groups "Modern Honey Network" group.
To unsubscribe from this group and stop receiving emails from it, send an email to modern-honey-net...@googlegroups.com.
To post to this group, send email to modern-hon...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/modern-honey-network/02A6D29B6BFB1D4A92714211745FBBD90B48AD99%40asdag2.
For more options, visit https://groups.google.com/d/optout.


--
Jason Trost | Director of ThreatStream Labs | www.threatstream.com 
Phone:  386.235.0078 | Twitter:  @jason_trost 

Kenneth M. S. LAU

unread,
Dec 22, 2014, 1:32:22 AM12/22/14
to Jason Trost, modern-hon...@googlegroups.com

Dear Jason,

 

How about Dionaea?  How to remove and re-install it?

 

Kenneth Lau

ASTRI

Jason Trost

unread,
Dec 22, 2014, 8:44:13 AM12/22/14
to Kenneth M. S. LAU, modern-hon...@googlegroups.com
This should do it:

apt-get purge -y dionaea
apt-get purge -y dionaea-phibo
rm -rf /var/dionaea/ /etc/supervisor/conf.d/dionaea.conf /etc/dionaea/
supervisorctl update

Scott Keoseyan

unread,
Mar 7, 2015, 4:12:08 PM3/7/15
to Jason Trost, modern-hon...@googlegroups.com
I know this is an older thread - but I was doing this recently and noticed that, on Ubuntu 12.04 at least, if you do not remove the user kippo from /etc/passwd, the deploy.sh script fails with no error at “user already exists”… it never goes to the next step and does the git clone.

—Scott


Reply all
Reply to author
Forward
0 new messages