6 ms·
A honeypot programmed in Micropython for the ESP8266
- i_am_nomad 8y agoDo the authors ever reveal if they detected any would-be hackers?
- droopybuns 8y agoNo. This is an adorable project that assumes people who are familiar with nmap regularly scan whatever they can. It’s cute, but I’d expect it to be pretty dull to watch.
- duskwuff 8y agoEh, it depends on how it's exposed. I used to run a Kippo[1] honeypot on port 22. I'd regularly see automated intrusion attempts, often followed up by users manually interacting with the server (and slowly coming to realize that it was fake). Nowadays I expect the exploitation process is typically much more automatic, so it'd be less interesting to watch. [1]: https://github.com/desaster/kippo https://github.com/desaster/kippo
- jeffalyanak 8y agoThe only place that I've ever seen this kind of honeypot regularly pick anything up is on college campuses.
- tty7 8y agonever heard of the mirai botnet i take it https://en.wikipedia.org/wiki/Mirai_(malware) https://en.wikipedia.org/wiki/Mirai_(malware)
- tty7 8y agohttps://zmap.io/ https://zmap.io/ https://github.com/robertdavidgraham/masscan https://github.com/robertdavidgraham/masscan it will be attacked within minutes, you should start a honeypot and see for yourselves
- cptskippy 8y agoI was kind of surprised and a little disappointed when I got a router with IPS monitoring and 9 months on there hasn't been a blip in the logs.
- gkm25 8y agoI understand your misconceptions about this working. It really just depends on if it appears to be vulnerable enough to scanners, and whether people actually bother to take interest. I guess you could say that my "project" is more of and experiment in how hackers go about finding vulnerable devices. Who knows, maybe hackers don't take interest in vulnerable telnet services anymore (they probably don't), but thats okay, this was fun while it lasted. I'll leave the memes on the readme.
- droopybuns 8y agoHey- if you are the author, I want to say I support what you are doing. We need more projects like this. But when I read the source, looks pretty lean to me in terms of follow on functionality. Would love to help you expand on this.
- itronitron 8y agoif you can still edit the title would you please change it from ALL CAPS to mostly lower case?
- chb 8y ago"The honeypot is set up to act as a telnet server owned by a fake bank." Really?
- gkm25 8y agoits just a joke/fun thing I decided to do.
- martijn9612 8y agoA way more interesting and more complete honeypot is https://github.com/honeytrap/honeytrap https://github.com/honeytrap/honeytrap. It combines a great list of services exposed to the internet and is very extendable. Currently development has a somewhat lower priority, but in the near future, it'll be ramped up.
- jpdb 8y agoI think the difference is that the Honeypot in the OP runs in an ESP8266; a small, single core chip that can be had for under $5.
- drb91 8y agoWhile this is true, why not just get a raspberry pi zero or whatever?
- ktta 8y agoIt is cheaper
- drb91 8y agoIf we’re evaluating cost, surely micropython is at least $5 of lost functionality for a single chip. Only at scale would you see any savings.
- gkm25 8y agoDeveloping on an ESP8266 is completely different than a RasPi Zero. If you want a challenge, and want to write code that can run in 80KB of RAM and have the code and all of its dependencies fit in 4MB of flash, then that’s part of the reason why microcontrollers are popular (also because a lot of them are easy to get going with).
- drb91 8y agoGreat answer, thank you :)
- zachruss92 8y agoI've always been amazed by the power of these little ESP chips. I'm actually really curious to see what outside the box use cases the ESP 8266 and the ESP 32 will have in the future.
- CapacitorSet 8y agoThat's a very unprofessional readme.
- gkm25 8y agoI don't work on this full time, so it necessarily need to be professional. Although I think I might cut down on the emojis.