2009年5月2日星期六

nepenthes configure

log-irc.conf:
use-tor "1"; //change 1 to 0, use no proxy to connect irc

nepenthes configure is really hard, for it is hard to get enough information!
I do not understand why nobody try to attack my nepenthes until now! It shoud be insteresing.

I get many .bin file in directory: /var/lib/nepenthes/hexdumps, but nothing in /var/lib/nepenthes/binaries.

-----------------------1
uncomment "logirc.so" in nepenthes.conf and edit log-irc.conf
-----------------------2
in irc I get:
(10时51分10秒) nep-noname: Handler http download handler will download http://213.92.8.7:31204/
(10时51分11秒) nep-noname: HTTP ERROR header found 12

-----------------------3
if I use metasploit to exploit honeypot, it should get shellcode , and i should see it on irc. try! 143 smtp !but I still get nothing in /var/lib/nepenthes/binaries.


----- I failed to find anthing valuable, so I decide to reinstall nepenthes.
#sudo su
#apt-get purge nepenthes //do not use remove
#cp /etc/nepenthes /etc/nepenthes.bak

change
/etc/nepenthes/nepenthes.conf:
uncomment the line "submitnorman.so", "submit-norman.conf"
uncomment the line "logirc.so","log-irc.conf",
/etc/nepenthes/submit-norman.conf
change email to "dongfangjack@gmail.com"
/etc/nepenthe/log-irc.conf
use-tor "0";
....configure irc server and channel

#cd /etc/nepenthes
#rm *~
#/etc/init.d/nepenthes start

irc display:
(19时57分28秒) nep-noname: Handler http download handler will download http://213.92.8.7:31204/
(19时57分32秒) nep-noname: HTTP ERROR header found 12

没有评论:

发表评论