{"id":13796035,"url":"https://github.com/justinazoff/ssh-auth-logger","last_synced_at":"2026-02-09T16:33:57.550Z","repository":{"id":54781565,"uuid":"88217100","full_name":"JustinAzoff/ssh-auth-logger","owner":"JustinAzoff","description":"A low/zero interaction ssh authentication logging honeypot","archived":false,"fork":false,"pushed_at":"2024-08-06T18:25:58.000Z","size":20,"stargazers_count":18,"open_issues_count":0,"forks_count":8,"subscribers_count":5,"default_branch":"master","last_synced_at":"2024-08-06T22:09:01.576Z","etag":null,"topics":["honeynet","ssh-server"],"latest_commit_sha":null,"homepage":"","language":"Go","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/JustinAzoff.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null}},"created_at":"2017-04-14T00:22:50.000Z","updated_at":"2024-08-06T18:26:01.000Z","dependencies_parsed_at":"2023-01-21T12:30:25.197Z","dependency_job_id":null,"html_url":"https://github.com/JustinAzoff/ssh-auth-logger","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/JustinAzoff%2Fssh-auth-logger","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/JustinAzoff%2Fssh-auth-logger/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/JustinAzoff%2Fssh-auth-logger/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/JustinAzoff%2Fssh-auth-logger/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/JustinAzoff","download_url":"https://codeload.github.com/JustinAzoff/ssh-auth-logger/tar.gz/refs/heads/master","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":225159845,"owners_count":17430191,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["honeynet","ssh-server"],"created_at":"2024-08-03T23:01:05.397Z","updated_at":"2026-02-09T16:33:57.517Z","avatar_url":"https://github.com/JustinAzoff.png","language":"Go","funding_links":[],"categories":["\u003ca id=\"c8f749888134d57b5fb32382c78ef2d1\"\u003e\u003c/a\u003eSSH\u0026\u0026Telnet"],"sub_categories":[],"readme":"A low/zero interaction ssh authentication logging honeypot\n\n## Interesting features\n\n### Structured logging\n\nssh-auth-logger logs all authentication attempts as json making it easy to\nconsume in other tools.  No more ugly [openssh log parsing\nvulnerabilities](http://dcid.me/texts/attacking-log-analysis-tools.html).\n\n### \"Random\" host keys\nssh-auth-logger uses HMAC to hash the destination IP address and a key in order to\ngenerate a consistently \"random\" key for every responding IP address.  This\nmeans you can run ssh-auth-logger on a /16 and every ip address will appear\nwith a different host key.  TODO: add random sshd version reporting as well.\n\n## Example log entry\n\nThis is normally logged on one line\n\n```\n{\n  \"client_version\": \"SSH-2.0-libssh2_1.4.3\",\n  \"destinationServicename\": \"sshd\",\n  \"dpt\": \"22\",\n  \"dst\": \"192.168.1.2\",\n  \"duser\": \"root\",\n  \"level\": \"info\",\n  \"msg\": \"Request with password\",\n  \"password\": \"P@ssword1\",\n  \"product\": \"ssh-auth-logger\",\n  \"server_version\": \"SSH-2.0-OpenSSH_5.3\",\n  \"spt\": \"38624\",\n  \"src\": \"192.168.1.4\",\n  \"time\": \"2017-11-17T19:16:37-05:00\"\n}\n```\n\n\n## How to use it\n\n    go install github.com/JustinAzoff/ssh-auth-logger@latest\n    export SSHD_BIND=:2222\n    ~/go/bin/ssh-auth-logger\n\n## Note\n\nTo bind to port 22 directly:\n\n    sudo setcap cap_net_bind_service=+ep ~/go/bin/ssh-auth-logger\n\n## Run with docker\n\n    docker run -t -i --rm  -p 2222:22 justinazoff/ssh-auth-logger\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fjustinazoff%2Fssh-auth-logger","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fjustinazoff%2Fssh-auth-logger","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fjustinazoff%2Fssh-auth-logger/lists"}