Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Using with Cowrie #68

Open
rangerrkm opened this issue Feb 11, 2018 · 3 comments
Open

Using with Cowrie #68

rangerrkm opened this issue Feb 11, 2018 · 3 comments

Comments

@rangerrkm
Copy link

Hello,

I just got done setting up Kippo-Graph for use with Cowrie.

My setup is Ubuntu 14.04 64-bit, Kippo-Graph 1.5.1 and Cowrie (latest from git clone).

Installed location is: /home/cowrie/cowrie/

kippo is in the /var/www/html/kippo-graph/

I believe most of the charts and graphs are working, but Kippo-Playlog is not working.

On the Kippo-Input section, at the very bottom.

I see Interesting Commands, when I click play, under PlayLog, it takes me to Kippo-PlayLog.

All that I see is a blackbox with *** End of log! ***. Does this seem correct.

Also, when I click on the PlayLog Hyperlink, all that is it showing is Replay input by attackers captured by the honeypot system.

I checked my apache2 log files and it is free of errors.

I would like some help in trying to fix this issue, if this is not the correct function of PlayLog.

I did try using the playlog.py command and it works great from the command line.

Thanks for any help,

@micheloosterhof
Copy link

@ikoniaris hi! there are several tickets open for integration with Cowrie. Do you intend to continue to keep kippo-graph and cowrie interoperable or would it be better if there was a fork cowrie-graph fork?

@ikoniaris
Copy link
Owner

@micheloosterhof hi! Ideally... it would be nice if Kippo-Graph could support both. But, I think most people nowadays switch to Cowrie (I think there might need to be some better "marketing" for it since some people still use Kippo, but Cowrie is more modern and maintained). So, I'd be inclined to switch support to Cowrie. Problem is I don't have enough time to spend maintaining the project unfortunately. Have you taken a look at the code so far to determine if fixes for Cowrie as "easy" or not?

@micheloosterhof
Copy link

Actually it works fine once you install all the prereqs and set the right config variables.
Maybe you can change the defaults a little (BACKEND = cowrie) and the directory.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants