12 ms·
Endlessh: An SSH Tarpit
- nickcw 6y agoGreat idea! I'm not sure we should be writing new network connected daemons in C though.
- klodolph 6y ago> I'm not sure we should be writing new network connected daemons in C though. In general, yes. However, in this case--no, that's not helpful advice--because this program doesn't actually receive input from clients! Kind of hard to trigger exploitable behavior on a program that only sends output.
- codeulike 6y agoKind of hard to trigger exploitable behavior on a program that only sends output. It wouldn't suprise me to find there were still possible exploits
- fb03 6y agoExplaining, since you were downvoted without a proper reason: While everything is possible, most exploits happen on buffer overflows on user-received custom data. and since this is not allocating any buffer to receive anything (besides internal connection structures that are filled by the OS), the attack/exploit surface on this one is really tiny, if existent at all.
- ravi-delia 6y agoCrucially, endlessh has a smaller codebase than some shell scripts I've written. If you have ever used any program written with even a single line of Python, you have more to worry about than a 843 line program that appends a string to a socket.
- kmbfjr 6y agoYour concern is well founded, but what are you going to use that doesn't end up touching libraries written in...C? We're a long way from "Smashing the Stack", people are aware of mitigation and the care that needs to be taken, precautions have been made inside operating systems and compilers.
- young_unixer 6y agoUntil there's a better alternative to C at its level of performance, people will keep using C.
- Lex-2008 6y agodiscussion of a blog post about this tool: https://news.ycombinator.com/item?id=19465967 https://news.ycombinator.com/item?id=19465967
- clon 6y agoThis is like a self-administered "slow lori attack" then - making it easier for an attacker to keep connections up until things start getting tight on port 443.
- heavenlyblue 6y agoI can imagine this is so easily overcome by the attacker. Why would they even need machines that take 10 seconds to return a single line over SSH?
- ivanbakel 6y agoTarpits trap dumb animals. An intelligent attacker won't fall for it, but they aren't meant to.
- xoa 6y agoAre tarpits still of use these days? I sort of figured that even modern script mass attackers have gotten professionalized and sophisticated enough that they can deal with trivial timeouts and the like. I could see actual honeypots still being of use for researchers or blue teams at organizations that are real targets, and ML might even open up some interesting new ways to make those more engaging for longer. But a tarpit doesn't seem like it'd cause bother for drive-by or APT, the former are all about volume so if something takes more than a few seconds just skip it (and maybe flag it as a tarpit for punishment) and an APT will instantly recognize it too. For individuals and smaller orgs I've sort of felt like keeping your head down, running a wg/ssh bastion with a non-standard port maybe along with single packet auth or even plain old port knocking to reduce log spam from random drive-by is more effective and attainable for places without any sort of dedicated security or even constant in-house IT staff. Running a tarpit on a VPS seems like it'd fail to bother most these days, and running it on an actual IP seems like at best it'd have no effect and at worst if it ever actually held up a scanner and the operator noticed they might decide to direct some actual attention to that IP, or at least throw a mild ddos at it for a bit. Am I wrong or out of date on that? I'm all for sticking it to bad actors and efforts to reduce the economic incentives, but in 2020 tarpits strike me as kind of obsolete with some risk to boot.
- jdc 6y agoDepends on your threat model and how playful you are.
- belorn 6y agoFor individuals and smaller orgs the easiest and by experience the best practice is to use a certificate (or generated and never to be reused password) for ssh authentication, install server monitoring, and then simply observe if the spam from random drive-by causes enough resource drain that would validate further work. Most likely it won't. Running a tar pit is a bit like installing a trap on a bike in order to teach bike thieves a lesson. It won't really reduce the problem, but for a lot of people the idea of vengeance gives a bit of a warm happy feeling.
- toyg 6y ago
- DarkWiiPlayer 6y agoReminds me of the dungeon I built for web crawlers to have fun collecting email addresses at https://darkwiiplayer.com/bot-dungeon https://darkwiiplayer.com/bot-dungeon xD
- codeulike 6y agohaha I gave up at level 13
- jk563 6y agoDoes it only go to level 100?
- nadavami 6y agoIt seems to go to as many characters as you can fit in the URL. Each new character after /bot-dungeon/ is a new level. Pretty clever!
- tyingq 6y agoNope. 5420 levels seems to be the limit: This one, right at the limit of 5420, works: https://darkwiiplayer.com/bot-dungeon/M1Kt80XBcvk4ofn2m2IqRVv5y4h5h3h3h3h3h3h3h3h3h3h3h3h3h3hh3h3h3h3h3hh3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3hh33h3h3h3h3h3h3h3hh3h3h3h3h3h3h3hh3h3h3h3h3h3h3h3h3hh3h3h3hM1Kt80XBcvk4ofn2m2IqRVv5y4h5h3h3h3h3h3h3h3h3h3h3h3h3h3hh3h3h3h3h3hh3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3hh33h3h3h3h3h3h3h3hh3h3h3h3h3h3h3hh3h3h3h3h3h3h3h3h3hh3h3h3hM1Kt80XBcvk4ofn2m2IqRVv5y4h5h3h3h3h3h3h3h3h3h3h3h3h3h3hh3h3h3h3h3hh3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3hh33h3h3h3h3h3h3h3hh3h3h3h3h3h3h3hh3h3h3h3h3h3h3h3h3hh3h3h3hM1Kt80XBcvk4ofn2m2IqRVv5y4h5h3h3h3h3h3h3h3h3h3h3h3h3h3hh3h3h3h3h3hh3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3hh33h3h3h3h3h3h3h3hh3h3h3h3h3h3h3hh3h3h3h3h3h3h3h3h3hh3h3h3hM1Kt80XBcvk4ofn2m2IqRVv5y4h5h3h3h3h3h3h3h3h3h3h3h3h3h3hh3h3h3h3h3hh3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3hh33h3h3h3h3h3h3h3hh3h3h3h3h3h3h3hh3h3h3h3h3h3h3h3h3hh3h3h3hM1Kt80XBcvk4ofn2m2IqRVv5y4h5h3h3h3h3h3h3h3h3h3h3h3h3h3hh3h3h3h3h3hh3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3hh33h3h3h3h3h3h3h3hh3h3h3h3h3h3h3hh3h3h3h3h3h3h3h3h3hh3h3h3hM1Kt80XBcvk4ofn2m2IqRVv5y4h5h3h3h3h3h3h3h3h3h3h3h3h3h3hh3h3h3h3h3hh3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3hh33h3h3h3h3h3h3h3hh3h3h3h3h3h3h3hh3h3h3h3h3h3h3h3h3hh3h3h3hM1Kt80XBcvk4ofn2m2IqRVv5y4h5h3h3h3h3h3h3h3h3h3h3h3h3h3hh3h3h3h3h3hh3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3hh33h3h3h3h3h3h3h3hh3h3h3h3h3h3h3hh3h3h3h3h3h3h3h3h3hh3h3h3hM1Kt80XBcvk4ofn2m2IqRVv5y4h5h3h3h3h3h3h3h3h3h3h3h3h3h3hh3h3h3h3h3hh3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3hh33h3h3h3h3h3h3h3hh3h3h3h3h3h3h3hh3h3h3h3h3h3h3h3h3hh3h3h3hM1Kt80XBcvk4ofn2m2IqRVv5y4h5h3h3h3h3h3h3h3h3h3h3h3h3h3hh3h3h3h3h3hh3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3hh33h3h3h3h3h3h3h3hh3h3h3h3h3h3h3hh3h3h3h3h3h3h3h3h3hh3h3h3hM1Kt80XBcvk4ofn2m2IqRVv5y4h5h3h3h3h3h3h3h3h3h3h3h3h3h3hh3h3h3h3h3hh3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3hh33h3h3h3h3h3h3h3hh3h3h3h3h3h3h3hh3h3h3h3h3h3h3h3h3hh3h3h3hM1Kt80XBcvk4ofn2m2IqRVv5y4h5h3h3h3h3h3h3h3h3h3h3h3h3h3hh3h3h3h3h3hh3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3hh33h3h3h3h3h3h3h3hh3h3h3h3h3h3h3hh3h3h3h3h3h3h3h3h3hh3h3h3hM1Kt80XBcvk4ofn2m2IqRVv5y4h5h3h3h3h3h3h3h3h3h3h3h3h3h3hh3h3h3h3h3hh3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3hh33h3h3h3h3h3h3h3hh3h3h3h3h3h3h3hh3h3h3h3h3h3h3h3h3hh3h3h3hM1Kt80XBcvk4ofn2m2IqRVv5y4h5h3h3h3h3h3h3h3h3h3h3h3h3h3hh3h3h3h3h3hh3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3hh33h3h3h3h3h3h3h3hh3h3h3h3h3h3h3hh3h3h3h3h3h3h3h3h3hh3h3h3hM1Kt80XBcvk4ofn2m2IqRVv5y4h5h3h3h3h3h3h3h3h3h3h3h3h3h3hh3h3h3h3h3hh3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3hh33h3h3h3h3h3h3h3hh3h3h3h3h3h3h3hh3h3h3h3h3h3h3h3h3hh3h3h3hM1Kt80XBcvk4ofn2m2IqRVv5y4h5h3h3h3h3h3h3h3h3h3h3h3h3h3hh3h3h3h3h3hh3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3hh33h3h3h3h3h3h3h3hh3h3h3h3h3h3h3hh3h3h3h3h3h3h3h3h3hh3h3h3hM1Kt80XBcvk4ofn2m2IqRVv5y4h5h3h3h3h3h3h3h3h3h3h3h3h3h3hh3h3h3h3h3hh3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3hh33h3h3h3h3h3h3h3hh3h3h3h3h3h3h3hh3h3h3h3h3h3h3h3h3hh3h3h3hM1Kt80XBcvk4ofn2m2IqRVv5y4h5h3h3h3h3h3h3h3h3h3h3h3h3h3hh3h3h3h3h3hh3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3hh33h3h3h3h3h3h3h3hh3h3h3h3h3h3h3hh3h3h3h3h3h3h3h3h3hh3h3h3hM1Kt80XBcvk4ofn2m2IqRVv5y4h5h3h3h3h3h3h3h3h3h3h3h3h3h3hh3h3h3h3h3hh3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3hh33h3h3h3h3h3h3h3hh3h3h3h3h3h3h3hh3h3h3h3h3h3h3h3h3hh3h3h3hM1Kt80XBcvk4ofn2m2IqRVv5y4h5h3h3h3h3h3h3h3h3h3h3h3h3h3hh3h3h3h3h3hh3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3hh33h3h3h3h3h3h3h3hh3h3h3h3h3h3h3hh3h3h3h3h3h3h3h3h3hh3h3h3hM1Kt80XBcvk4ofn2m2IqRVv5y4h5h3h3h3h3h3h3h3h3h3h3h3h3h3hh3h3h3h3h3hh3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3hh33h3h3h3h3h3h3h3hh3h3h3h3h3h3h3hh3h3h3h3h3h3h3h3h3hh3h3h3hM1Kt80XBcvk4ofn2m2IqRVv5y4h5h3h3h3h3h3h3h3h3h3h3h3h3h3hh3h3h3h3h3hh3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3hh33h3h3h3h3h3h3h3hh3h3h3h3h3h3h3hh3h3h3h3h3h3h3h3h3hh3h3h3hM1Kt80XBcvk4ofn2m2IqRVv5y4h5h3h3h3h3h3h3h3h3h3h3h3h3h3hh3h3h3h3h3hh3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3hh33h3h3h3h3h3h3h3hh3h3h3h3h3h3h3hh3h3h3h3h3h3h3h3h3hh3h3h3hM1Kt80XBcvk4ofn2m2IqRVv5y4h5h3h3h3h3h3h3h3h3h3h3h3h3h3hh3h3h3h3h3hh3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3hh33h3h3h3h3h3h3h3hh3h3h3h3h3h3h3hh3h3h3h3h3h3h3h3h3hh3h3h3hM1Kt80XBcvk4ofn2m2IqRVv5y4h5h3h3h3h3h3h3h3h3h3h3h3h3h3hh3h3h3h3h3hh3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3hh33h3h3h3h3h3h3h3hh3h3h3h3h3h3h3hh3h3h3h3h3h3h3h3h3hh3h3h3hM1Kt80XBcvk4ofn2m2IqRVv5y4h5h3h3h3h3h3h3h3h3h3h3h3h3h3hh3h3h3h3h3hh3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3hh33h3h3h3h3h3h3h3hh3h3h3h3h3h3h3hh3h3h3h3h3h3h3h3h3hh3h3h3hM1Kt80XBcvk4ofn2m2IqRVv5y4h5h3h3h3h3h3h3h3h3h3h3h3h3h3hh3h3h3h3h3hh3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3hh33h3h3h3h3h3h3h3hh3h3h3h3h3h3h3hh3h3h3h3h3h3h3h3h3hh3h3h3hM1Kt80XBcvk4ofn2m2IqRVv5y4h5h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3hh3h3h3h3h3hh3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3hh33h3h3h3h3h3h3h3hh3h3h3h3h3h3h3hh3h3h3h3h3h3h3h3h3hh3h3h3hM1Kt80XBcvk4ofn2m2IqRVv5y4h5h3h3h3h3h3h3h3h3h3h3h3h3h3hh3h3h3h3h3hh3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3hh33h3h3h3h3h3h3h3hh3h3h3h3h3h3h3hh3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3hh3h3h3h3h3hh3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3hh33h3h3h3h3h3h3h3hh3h3h3h3h3h3h3hh3h3h3h3h3h3h3h3h3hh3h3h3hM1Kt80XBcvk4ofn2m2IqRVv5y4h5h3h3h3h3h3h3h3h3h3h3h3h3h3hh3h3h3h3h3hh3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h https://darkwiiplayer.com/bot-dungeon/M1Kt80XBcvk4ofn2m2IqRV... (YMMV, some browsers might have their own url length limitations) This one, at 5421 levels, breaks: https://darkwiiplayer.com/bot-dungeon/M1Kt80XBcvk4ofn2m2IqRVv5y4h5h3h3h3h3h3h3h3h3h3h3h3h3h3hh3h3h3h3h3hh3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3hh33h3h3h3h3h3h3h3hh3h3h3h3h3h3h3hh3h3h3h3h3h3h3h3h3hh3h3h3hM1Kt80XBcvk4ofn2m2IqRVv5y4h5h3h3h3h3h3h3h3h3h3h3h3h3h3hh3h3h3h3h3hh3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3hh33h3h3h3h3h3h3h3hh3h3h3h3h3h3h3hh3h3h3h3h3h3h3h3h3hh3h3h3hM1Kt80XBcvk4ofn2m2IqRVv5y4h5h3h3h3h3h3h3h3h3h3h3h3h3h3hh3h3h3h3h3hh3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3hh33h3h3h3h3h3h3h3hh3h3h3h3h3h3h3hh3h3h3h3h3h3h3h3h3hh3h3h3hM1Kt80XBcvk4ofn2m2IqRVv5y4h5h3h3h3h3h3h3h3h3h3h3h3h3h3hh3h3h3h3h3hh3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3hh33h3h3h3h3h3h3h3hh3h3h3h3h3h3h3hh3h3h3h3h3h3h3h3h3hh3h3h3hM1Kt80XBcvk4ofn2m2IqRVv5y4h5h3h3h3h3h3h3h3h3h3h3h3h3h3hh3h3h3h3h3hh3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3hh33h3h3h3h3h3h3h3hh3h3h3h3h3h3h3hh3h3h3h3h3h3h3h3h3hh3h3h3hM1Kt80XBcvk4ofn2m2IqRVv5y4h5h3h3h3h3h3h3h3h3h3h3h3h3h3hh3h3h3h3h3hh3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3hh33h3h3h3h3h3h3h3hh3h3h3h3h3h3h3hh3h3h3h3h3h3h3h3h3hh3h3h3hM1Kt80XBcvk4ofn2m2IqRVv5y4h5h3h3h3h3h3h3h3h3h3h3h3h3h3hh3h3h3h3h3hh3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3hh33h3h3h3h3h3h3h3hh3h3h3h3h3h3h3hh3h3h3h3h3h3h3h3h3hh3h3h3hM1Kt80XBcvk4ofn2m2IqRVv5y4h5h3h3h3h3h3h3h3h3h3h3h3h3h3hh3h3h3h3h3hh3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3hh33h3h3h3h3h3h3h3hh3h3h3h3h3h3h3hh3h3h3h3h3h3h3h3h3hh3h3h3hM1Kt80XBcvk4ofn2m2IqRVv5y4h5h3h3h3h3h3h3h3h3h3h3h3h3h3hh3h3h3h3h3hh3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3hh33h3h3h3h3h3h3h3hh3h3h3h3h3h3h3hh3h3h3h3h3h3h3h3h3hh3h3h3hM1Kt80XBcvk4ofn2m2IqRVv5y4h5h3h3h3h3h3h3h3h3h3h3h3h3h3hh3h3h3h3h3hh3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3hh33h3h3h3h3h3h3h3hh3h3h3h3h3h3h3hh3h3h3h3h3h3h3h3h3hh3h3h3hM1Kt80XBcvk4ofn2m2IqRVv5y4h5h3h3h3h3h3h3h3h3h3h3h3h3h3hh3h3h3h3h3hh3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3hh33h3h3h3h3h3h3h3hh3h3h3h3h3h3h3hh3h3h3h3h3h3h3h3h3hh3h3h3hM1Kt80XBcvk4ofn2m2IqRVv5y4h5h3h3h3h3h3h3h3h3h3h3h3h3h3hh3h3h3h3h3hh3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3hh33h3h3h3h3h3h3h3hh3h3h3h3h3h3h3hh3h3h3h3h3h3h3h3h3hh3h3h3hM1Kt80XBcvk4ofn2m2IqRVv5y4h5h3h3h3h3h3h3h3h3h3h3h3h3h3hh3h3h3h3h3hh3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3hh33h3h3h3h3h3h3h3hh3h3h3h3h3h3h3hh3h3h3h3h3h3h3h3h3hh3h3h3hM1Kt80XBcvk4ofn2m2IqRVv5y4h5h3h3h3h3h3h3h3h3h3h3h3h3h3hh3h3h3h3h3hh3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3hh33h3h3h3h3h3h3h3hh3h3h3h3h3h3h3hh3h3h3h3h3h3h3h3h3hh3h3h3hM1Kt80XBcvk4ofn2m2IqRVv5y4h5h3h3h3h3h3h3h3h3h3h3h3h3h3hh3h3h3h3h3hh3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3hh33h3h3h3h3h3h3h3hh3h3h3h3h3h3h3hh3h3h3h3h3h3h3h3h3hh3h3h3hM1Kt80XBcvk4ofn2m2IqRVv5y4h5h3h3h3h3h3h3h3h3h3h3h3h3h3hh3h3h3h3h3hh3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3hh33h3h3h3h3h3h3h3hh3h3h3h3h3h3h3hh3h3h3h3h3h3h3h3h3hh3h3h3hM1Kt80XBcvk4ofn2m2IqRVv5y4h5h3h3h3h3h3h3h3h3h3h3h3h3h3hh3h3h3h3h3hh3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3hh33h3h3h3h3h3h3h3hh3h3h3h3h3h3h3hh3h3h3h3h3h3h3h3h3hh3h3h3hM1Kt80XBcvk4ofn2m2IqRVv5y4h5h3h3h3h3h3h3h3h3h3h3h3h3h3hh3h3h3h3h3hh3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3hh33h3h3h3h3h3h3h3hh3h3h3h3h3h3h3hh3h3h3h3h3h3h3h3h3hh3h3h3hM1Kt80XBcvk4ofn2m2IqRVv5y4h5h3h3h3h3h3h3h3h3h3h3h3h3h3hh3h3h3h3h3hh3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3hh33h3h3h3h3h3h3h3hh3h3h3h3h3h3h3hh3h3h3h3h3h3h3h3h3hh3h3h3hM1Kt80XBcvk4ofn2m2IqRVv5y4h5h3h3h3h3h3h3h3h3h3h3h3h3h3hh3h3h3h3h3hh3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3hh33h3h3h3h3h3h3h3hh3h3h3h3h3h3h3hh3h3h3h3h3h3h3h3h3hh3h3h3hM1Kt80XBcvk4ofn2m2IqRVv5y4h5h3h3h3h3h3h3h3h3h3h3h3h3h3hh3h3h3h3h3hh3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3hh33h3h3h3h3h3h3h3hh3h3h3h3h3h3h3hh3h3h3h3h3h3h3h3h3hh3h3h3hM1Kt80XBcvk4ofn2m2IqRVv5y4h5h3h3h3h3h3h3h3h3h3h3h3h3h3hh3h3h3h3h3hh3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3hh33h3h3h3h3h3h3h3hh3h3h3h3h3h3h3hh3h3h3h3h3h3h3h3h3hh3h3h3hM1Kt80XBcvk4ofn2m2IqRVv5y4h5h3h3h3h3h3h3h3h3h3h3h3h3h3hh3h3h3h3h3hh3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3hh33h3h3h3h3h3h3h3hh3h3h3h3h3h3h3hh3h3h3h3h3h3h3h3h3hh3h3h3hM1Kt80XBcvk4ofn2m2IqRVv5y4h5h3h3h3h3h3h3h3h3h3h3h3h3h3hh3h3h3h3h3hh3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3hh33h3h3h3h3h3h3h3hh3h3h3h3h3h3h3hh3h3h3h3h3h3h3h3h3hh3h3h3hM1Kt80XBcvk4ofn2m2IqRVv5y4h5h3h3h3h3h3h3h3h3h3h3h3h3h3hh3h3h3h3h3hh3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3hh33h3h3h3h3h3h3h3hh3h3h3h3h3h3h3hh3h3h3h3h3h3h3h3h3hh3h3h3hM1Kt80XBcvk4ofn2m2IqRVv5y4h5h3h3h3h3h3h3h3h3h3h3h3h3h3hh3h3h3h3h3hh3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3hh33h3h3h3h3h3h3h3hh3h3h3h3h3h3h3hh3h3h3h3h3h3h3h3h3hh3h3h3hM1Kt80XBcvk4ofn2m2IqRVv5y4h5h3h3h3h3h3h3h3h3h3h3h3h3h3hh3h3h3h3h3hh3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3hh33h3h3h3h3h3h3h3hh3h3h3h3h3h3h3hh3h3h3h3h3h3h3h3h3hh3h3h3hM1Kt80XBcvk4ofn2m2IqRVv5y4h5h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3hh3h3h3h3h3hh3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3hh33h3h3h3h3h3h3h3hh3h3h3h3h3h3h3hh3h3h3h3h3h3h3h3h3hh3h3h3hM1Kt80XBcvk4ofn2m2IqRVv5y4h5h3h3h3h3h3h3h3h3h3h3h3h3h3hh3h3h3h3h3hh3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3hh33h3h3h3h3h3h3h3hh3h3h3h3h3h3h3hh3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3hh3h3h3h3h3hh3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3hh33h3h3h3h3h3h3h3hh3h3h3h3h3h3h3hh3h3h3h3h3h3h3h3h3hh3h3h3hM1Kt80XBcvk4ofn2m2IqRVv5y4h5h3h3h3h3h3h3h3h3h3h3h3h3h3hh3h3h3h3h3hh3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h3h https://darkwiiplayer.com/bot-dungeon/M1Kt80XBcvk4ofn2m2IqRV...
- seqizz 6y agoI'd rather have a trusted common list of known abusers' IPs. But I think that's harder to maintain.
- mortehu 6y agoThat's called a DNSBL, and there are many of them, mostly for email spam though. https://www.dnsbl.info/ https://www.dnsbl.info/
- geocrasher 6y agoWhat I find infuriating is when an admin gets the bright idea to block all connections from IP's that are in mail dnsbl's. It's a great way to alienate people from using your services. I can't remember which company was doing it, but a customers API calls to a vendor failed because the vendor blocked the IP, which was blacklisted somewhere. Here's the kicker: The server wasn't even used to send mail and hadn't been for a long time. So we had to apply for a delisting from a mail blacklist for a server that didn't send mail so that a customer could use an API. The admin thought they were being clever, but instead they were just being difficult.
- beatrobot 6y agoThere's https://iplists.firehol.org/ https://iplists.firehol.org/
- verroq 6y agoThis would have been fun to put onto production machines. We had a botnet that was running ssh bruteforce with 10s requests per second with unique IPs. It stopped after we disabled password auth.
- creeble 6y agoWait, I think I'm an idiot - does disabling password auth entirely prevent openssh from generating a password prompt?
- VWWHFSfQ 6y agoyes
- creeble 6y agoWhoops, silly me / more coffee needed. All my servers have: PasswordAuthentication no ChallengeResponseAuthentication no so sshd never generates a password prompt. They all run on a non-standard port, and it's somewhat rare to see more than one unique IP address connection attempt, but every few days you see a few hundred in sequence from a script too dumb to notice.
- k33n 6y agoThe tarpit approach is a double-edged sword. Sure, you're keeping some script kiddie's machine locked up (maybe), but you're also keeping socket connections open and wasting resources on the machine they are targeting. A much more efficient approach is using fail2ban and a firewall to just drop traffic from offenders.
- mtlynch 6y agoTarpits aren't really a defense mechanism. They're meant to waste attackers' time and study their techniques, making attacks more expensive. It's sort of like those YouTube channels where they waste phone scammers' time in an entertaining way. [0] Obviously, the easiest thing for the callee to do is hang up the phone, but their goal is to make phone scams less profitable. [0] https://en.wikipedia.org/wiki/Jim_Browning_(YouTuber) https://en.wikipedia.org/wiki/Jim_Browning_(YouTuber)
- a1369209993 6y ago> where they waste phone scammers' time in an entertaining way. This can also be automated, so the defender doesn't even need to waste their own time on it. Eg: https://old.reddit.com/r/itslenny/ https://old.reddit.com/r/itslenny/ .
- prussian 6y agoYou could also do a combined approach with the tarpit + fail2ban parser that could just ban people stuck for longer than x amount of seconds.
- golem14 6y agoIn my experience, fail2ban does only help if there is a small number of IP addresses requests come from. I usually observed a trickle of requests from huge number of IP addresses, at most 1-2 request from each IP over the course of days. tarpit will likely hurt yourself as the system ties up sockets for a long time and you'll run out eventually. You'd have to combine the tarpit with something to limit the number of connections you accept. IMO, setting up ssh on another port has been useful, especially combined with port knocking. And of course turning off password auth.
- deleted 6y ago[deleted]
- tptacek 6y agoI'm sure this was fun to put together and it seems like it's fun for people to talk about, but you can put this along with fail2ban, port knocking, and nonstandard SSH ports in the back of the attic and just (1) turn off password authentication entirely and (2) put SSH behind WireGuard. Even if you don't do step (2), step (1) eliminates the rationale for all the silly stuff people do to obfuscate their SSH installs.
- Drdrdrq 6y agoCould you elaborate on WireGuard part? Do you mean that users must first VPN, and only then can SSH, or something else?
- tptacek 6y agoYes. This is how SSH access to prod works in most large companies: you have to be behind the VPN to get it.
- pvg 6y agoYou know this but I'm just throwing it in for people who don't and aren't working on large company things: You can give yourself a WireGuard-powered, Single Sign-on, secure overlay network between, say, your phone, your laptop, a DO droplet and an AWS instance near-instantly and for (currently) free with tailscale. By 'near-instantly' I mean it takes almost no effort to set up. It takes me longer to get my dotfiles right on a new host.
- tptacek 6y agoIt is disgusting how good Tailscale is. I mean that I am literally welling up with disgust thinking about it.
- teddyh 6y agoI you put it behind WireGuard, why use SSH? Why not simply use telnet instead? And use FTP for file transfers.
- geocrasher 6y agoI have to admit that I tried this and it was rather lackluster. Log output: https://pastebin.com/4FTHRF3f https://pastebin.com/4FTHRF3f Not a lot of activity over the time I ran it, and I know that the port gets hit more than that. I had a much better time when I ran a honeypot with Kippo: https://github.com/desaster/kippo https://github.com/desaster/kippo It was much more useful as it gave me a great list of IP's to block from all my systems ;)
- mdaniel 6y agoThe top of the readme for that repo advises to use the fork: https://github.com/cowrie/cowrie https://github.com/cowrie/cowrie
- Freaky 6y agoOne I made in async Rust: https://github.com/Freaky/tarssh https://github.com/Freaky/tarssh I currently have 22 clients stuck it in across three machines. When I started out it was more like a thousand, so seems they've largely adapted.
- dclaw 6y agoHah, I love endlessh.... been running it for a few years now on one of my digital ocean droplets. Better to fuck with these bots. My personal record was somewhere around 23 days having one stuck.
- earthboundkid 6y agohttps://github.com/carlmjohnson/heffalump https://github.com/carlmjohnson/heffalump
- ryankrage77 6y agoThis seems like it would use a lot of bandwidth?
- earthboundkid 6y agoOh, it’s a terrible idea. It’s basically a practical joke.
- nirui 6y agoWhat got my inspired here is, if a simple delay strategy can make attack harder, why not add this as a common feature in SSH? It can be called "Initial Connection Delay": Once a new TCP connection is established, wait for an uncertain number of n seconds before read and respond to the handshake request.
- password4321 6y agoOne of the simplest ways to block unwanted connections is to filter on client id. I haven't seen anyone willing to change it even though I've blocked libssh, sshgo, and paprika. Of course, this functionality is only available in non-standard SSH servers such as the one from Bitvise.