4 ms·
Somewhat related: I run an http server on the local network for various services. Due to the large number of bogus requests I set up a honeypot vhost which res
by wooptoo 6y ago
Somewhat related: I run an http server on the local network for various services.
Due to the large number of bogus requests I set up a honeypot vhost which responds only to requests sent without a Host header, i.e. received directly on the IP address. It also logs these requests separately.
It's fun to check the logs once in a while and see all sorts of exploit attempts. Wordpress and PHP seem to attract a lot of attention.
- Guest42 6y agoCan you elaborate a bit on how you set things up and introduced some security?
- wooptoo 6y agoAuthorised parties have prior knowledge of the subdomains where the apps reside. Everyone else hitting the IPs directly (presumably coming from mass IP scans) will be met with a honeypot vhost returning nothing. An example can be found in the nginx manual with the catch-all approach: https://nginx.org/en/docs/http/server_names.html#miscellaneous_names https://nginx.org/en/docs/http/server_names.html#miscellaneo...
- Guest42 6y agoFantastic, didn’t know that was possible
- jffry 6y agoAs a fun exercise sometime, spin up any cheap EC2 instance in AWS, set up an HTTP server listening on port 80 and 443, and watch your SSH and HTTP logs. The last time I did this I had random SSH and HTTP requests rolling in within minutes.
- logshipper 6y agoI recently interned in cloud security for a mid-sized firm. In my first week, I spun up a free-tier EC2 for some testing (Only port 22 was open) and soon enough, the logs were full of port scans and unauthorized ssh attempts. It is only then I realized the scale at which malicious parties operate. Suffice it to say, I was very careful with my filters after that incident.
- Communitivity 6y agoIn 2004 a study was done that showed an unprotected PC connected to the internet was attacked within 20 minutes, half the time of a previous study just a few years prior. If we suppose that it continues to half, say ever five years, it went to within 10 minutes in 2010, within 5 minutes in 2015, and is now somewhere around within 3 minutes for an unprotected PC to be attacked once connected the the internet.
- banana_giraffe 6y agoHeck, not just EC2. Try doing this with a home connection. Add RDP into the mix. It doesn't take long before one scan finds the port, and then a bunch of people start trying different attacks.