#!/bin/bash # SSH Honeypot Response Script # Deploy to: /opt/honeypot/response.sh # # Setup commands: # sudo mkdir -p /opt/honeypot # sudo cp config/honeypot/response.sh /opt/honeypot/ # sudo chmod +x /opt/honeypot/response.sh # sudo touch /var/log/honeypot.log # sudo chmod 644 /var/log/honeypot.log # Log connection with timestamp and client IP CLIENT_IP=${NCAT_REMOTE_ADDR:-unknown} echo "$(date): SSH honeypot connection from $CLIENT_IP" >> /var/log/honeypot.log # Send fake SSH banner to make it look like OpenSSH echo "SSH-2.0-OpenSSH_8.9" # Brief delay before closing connection sleep 2