honeytrap

HoneydNepententhとは違う低対話型のハニーポットですね。
とりあえずDL。いじる暇があると良いんだけど;;

DESCRIPTION

honeytrap is a network security tool written to observe attacks against TCP services. As a low-interactive honeypot, it collects information regarding known or unknown network-based attacks. It starts server processes dynamically at the time of incoming connection requests. This generic behavior makes it possible to respond to most network-based attacks. Observed data can be processed with plugins for automatic analysis.

All data submitted to honeytrap can be dumped to the filesystem for further investigation. Attacks can be parsed automatically for download commands. Plugins enable honeytrap to recognize FTP and TFTP commands and do an automated download of online ressources.

honeytrap must be run by root or installed setuid to root, in order to bind to privileged ports. Always use the -u and -g flags to drop privileges early and switch to an unprivileged user and group as soon as possible.