4 ms·
I once made a very similar visualization to see where people were trying to attack my servers from by adapting (e.g. use local geoip database file instead of ip
by mimimi31 5y ago
I once made a very similar visualization to see where people were trying to attack my servers from by adapting (e.g. use local geoip database file instead of ipinfo service) the Python script from [1], which uses folium to generate an interactive (standalone HTML file) heatmap of IP address locations.
[1] https://github.com/meesaltena/SSHHeatmap https://github.com/meesaltena/SSHHeatmap
- Topolomancer 5y agoThat looks gorgeous, thanks for sharing it!
- heap_perms 5y agoThat's a wonderful project. Amazing, this can be done with just over a hundred lines of code. (excluding packages)
- snek_case 5y agoI'm curious what would happen if someone set up a sandbox and let the attackers in. As in curious what commands they would run and what services they would try to install. I'm guessing crypto mining or spam mail?
- dspillett 5y agoThe problem with a honey trap like that is that the uninteresting events are uninteresting (as you suggest, installing a mail relay, miner, or both, and likely a copy of itself for further spreading), but the interesting ones are unlikely to be fooled unless the honeypot is very clever. To see anything really interesting you possibly need to let it get far enough that with a good zero-day intend in-hand it may be able to break out and affect the host. I don't know about you, but I don't trust myself to be that clever!