Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

any guideline? #1

Open
sayo-nara opened this issue May 22, 2022 · 3 comments
Open

any guideline? #1

sayo-nara opened this issue May 22, 2022 · 3 comments

Comments

@sayo-nara
Copy link

May I know how to enable it to gather dns amplification attack in real time?

@Kasperg2
Copy link

Hi Sayo-nara!
Where are you in the process? Have you installed it? Are you running it? Where have you placed the honeypot? Is it on a local network or in the cloud? Where is your problem exactly? Please supply more info. :)

@sayo-nara
Copy link
Author

Hi Sayo-nara! Where are you in the process? Have you installed it? Are you running it? Where have you placed the honeypot? Is it on a local network or in the cloud? Where is your problem exactly? Please supply more info. :)

Hi Kasperg2, I have installed it in my local network. I thought I could use it for having dns amplification attack in real time and running packet capturing tool for collecting real time dns traffic at the same time, but seems like it doesn't work. I think most probably I need to do some configuration on it, but I am not experienced enough on what to do.
Screenshot

@Kasperg2
Copy link

Kasperg2 commented May 27, 2022

Hmmm... it looks like you are logging your own dns-queries.

If you want to log ddos attacks you need to deply ddospot on the open internet - e.g. on a cloud platform or with a static IP address directly exposed to the internet. Remember that attackers have to scan and find your honeypot first, before any attacks are launched. If it's sitting in your local network, it's probably screened of from both scans and attacks. Does that make sense? :)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants