-
-
Notifications
You must be signed in to change notification settings - Fork 867
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Add shell support for parenthesis. #361
Comments
By brackets I think you mean parentheses? In any case, I have seen this on my cowrie as well. |
Yep, thanks. I've translated it incorrectly :( |
If I got it right, shlex doesn't support parentheses. That's sad. |
The quick fix would be to just ignore parenthesis. |
Yep, that's what I did. (fe7ch@ede2338, fe7ch@e2cd464). I wasn't sure if you are okey with such dirty hacks, so I didn't fill it in pull request. |
I keep seeing this on my honeypot. A fix that works would be appreciated! :) |
micheloosterhof, dwasserm, I've filled a pull request with a hotfix. It was tested on my honeypots for a week or so. |
Cool. Can the hotfix be merged into the current build? |
Closed, since a solution was merged. |
@fe7ch not sure if I'm doing something incorrect or not, however I've followed the same guidance for copying a working copy of the binary's into honeyfs/bin in order to get this sample captured, however it doesn't seem to work, was hoping maybe you could shed some light on the situation
|
@funtimes-ninja You don't neeed |
Hajime trojan started to use () brackets during infection stage. It prevents cowrie from capturing samples.
Part of the session how it was seen by the attacker:
The text was updated successfully, but these errors were encountered: