7 ms·
The Honeypot Diaries: Thousands of Daily Attacks on My Home Network
- m_a_g 3y agoI’d love to know more about the honeypot and the whole process.
- jrflowers 3y agoIt is important that we all know that if we intentionally configure our networks to draw attention from automated scans that we will draw attention from automated scans.
- nonrandomstring 3y agoIndeed, but remember that can also be a sacrificial defensive strategy rather than a "scientific" data collection exercise (which as you say would be biased by a Heisenberg/observability effect). Some honeynets are put up there to simply sink the resources of, and discombobulate attackers. Meanwhile, buried deep in there behind a couple of layers of port knocking, is the real asset.
- BMc2020 3y agoInteresting link at the bottom, the 1MB club: 1MB Club is a growing collection of performance-focused web pages weighing less than 1 megabyte.
- Brajeshwar 3y agoHey, I'm in the 1MB club too. I'm less than 50kb. :-)
- SushiHippie 3y agoThen you can be in the 512kb club. https://512kb.club/ https://512kb.club/ EDIT: even in the green team! https://512kb.club/faq https://512kb.club/faq
- Brajeshwar 3y agoAh! Now I realize my website has gotten a tad fatter. It is there in Yellow.
- blackoil 3y agoI think the author misunderstood the purpose of the 1MB club and removed all content.
- charcircuit 3y agoThe author's IP was likely added to a databases like shodan that includ information showing vulnerable services were running. The attempts are not because the author is a bank, but rather because the percieved difficulty is deemed to be trivial.
- est 3y agoscanners check full IPv4 all the time with known attack vectors.
- enthus1ast 3y agoI've build a simple telnet honeypot that emulated some embedded device. I also got thousand of samples. I think it was mostly different strains of Mirai. I learned some things about how bots fingerprint the honeypots, and patched it accordingly that they do not identify my service as a honeypot. The funny thing about this was, that my ISP send me a letter (by post o.0), that i run a vulnerable service on my network. The honeypot had a "MOD" from an old nuclear power plant, and did some random tarpit and randomly let random user/password combinations to log in. It was a fun experiment
- Roark66 3y agoHave I missed 99% of the content or is this purely to raise awarness? There is no description of the honeypot. Did the person running it manage to intercept any root kits, if yes what were they? I remember years ago there was this vnc vulnerability that allowed one to login without a password. At the time I was doing "it support" for various small businesses in West Yorkshire, UK. All of my regulars had firewalls with (site to site) vpn for remote access, but often I'd get new clients I never saw before asking to fix something. When that vulnerability came out I was getting calls from such new customers daily about "their system is slow", "our email is not going out" (in these days even small businesses used to run their own email servers). Every single "new customer" I had during next few weeks was "hacked" by the vnc bug. It seems whoever used to do IT for them left vnc accessible from the Internet (not even limiting the source IPs on the firewall). Every single time the root kits I found had outputs in Chinese (it required changing windows cmds settings to even see it). Most were very basic, but they did manage to successfully kill the AV software and they all had their own storage drivers that hid certain folders unless I booted the system in the safe mode(tgese were mostly windows 2000/2003 sbs servers BTW). Frequently I'd find lists of other victims IPs on these systems and their scanning software. What was the goal of this campaign? Sending spam of course. As mentioned most clients only realised they were "hacked" when their system became horribly slow, or their outgoing email was cut off by their ISP blocking outgoing smtp traffic from their IPs following complaints. What was the spam? Viagra of course.... I saw lots of these. Many of these systems had personal data of people, I never noticed attempts to exfiltrate such data. The only time I dealt with proper attempt to steal money from a business account using the IT system was after a disgruntled it admin was fired. This was almost 20 years ago. I'd love to find out how small network attackers try to "monetize" their victims today. Are they just searching for crypto, attempting "encrypting data" scams, or is there something more interesting? Curious minds want to know?
- fmajid 3y agoThey’re actually set up as cloud providers for hire now, as part of the professionalization of the criminal underworld and its stratification into specialized operators.
- 3y ago
- globalnode 3y agoplease excuse my ignorance but it looks like most incidents are from romania and germany, am i wrong? why is he highlighting china?
- deleted 3y ago[deleted]
- pizzapill 3y agoYou are wrong. Over 2k from China and 55 from Germany for example. I see the same distribution on my Servers. That being said: attributing those attacks to Chinese actors based on IP falls a little short. Proxychains exist and are used.
- blackoil 3y agoHe is not wrong, in 1st image CN is 2k, RO 56k and DE 26k. Across the graph red and purple lines are much higher
- fmajid 3y agoGiven the Great Firewall of China, it would be a pain to go through them if you have any alternatives.
- Dzidas 3y agoIf you take the population into account, it is only 2x more.
- RetroTechie 3y agoAttacks will originate from some cross-section of [country with many broadband connections] and [many outdated / unpatched OSes in use]. But no humans in the loop other than command & control, or people wondering why their device is slow / acting up. <Insert usual suspect here> high up can be read just as "many internet users there, whose PC or other device is infected with malware that tries to spread itself". As the article states: originating device can be silly IoT device like a router, TV, printer, Ring-style doorbell, etc etc etc. In fact, chance of random IoT device being vulnerable and/or been 'recruited' in a botnet, may be bigger than the same with random PC / tablet etc. Many IoT devices are junk that rarely see firmware updates (if any).
- HenryBemis 3y agoRegarding the list of things that people buy, I have to admit that I couldn't resist to buy a Plumbus. And for those who don't want to spend money buying it and prefer to DIY it, here are the instructions: https://www.youtube.com/watch?v=eMJk4y9NGvE https://www.youtube.com/watch?v=eMJk4y9NGvE
- BLKNSLVR 3y agoWubbalubbadubdub!
- Jamie9912 3y agoI wouldn't consider these attacks. Anything on the internet is going to receive background bot/spam traffic by default
- hsbauauvhabzb 3y agoThere’s a large volume of active attempts to access remote system, they are by definition attacks, regardless of their sophistication or likelihood of success. Honeypot a popular, recent, public vulnerability and you’ll see a tonne of attacks.
- schleck8 3y agoI'm still convinced that the majority of IoT devices are unnecessary nonsense. And I don't think manufacturers care about their great contribution to botnets either.
- brobinson 3y agoThis information is somewhat interesting, but what action does it allow you to take? https://en.wikipedia.org/wiki/Information-action_ratio https://en.wikipedia.org/wiki/Information-action_ratio
- mmasu 3y agoI find it somewhat amusing that it is someone named Postman who “frames the information-action ratio in the context of the telegraph's invention”. Post vs Telegraph :-)
- _trampeltier 3y agoSo may IPs from China. Would they not be stopped from Chinas firewall? I think you can't make an outging VPN or SSH connection. Is it possible somebody does a BGP hack and then reuse china IPs?
- denton-scratch 3y agoChina has a very large population of educated and under-employed nerds.
- LinuxBender 3y agoThey do not care about outbound attacks. They care about anything that goes against the approved narrative. The only way I've managed to get them to care was to have a coworker translate my email into Chinese characters and give CIDR blocks to their government and say they are spreading democracy and those networks go silent. The ISP's will just ignore complaints otherwise.
- fullspectrumdev 3y agoFuck that’s a deeply funny way to deal with attacks. You hardly have that letter somewhere?
- LinuxBender 3y agoYou hardly have that letter somewhere? This was ages ago. I try not to hold onto old corporate emails. And agree not to. I've honestly had mixed feelings about it given that some people probably got their door kicked in. In fairness to me they were DDoS'ing my customers. The CIDR blocks were part of a DDoS for hire farm.
- tamimio 3y ago> CIDR blocks to their government and say they are spreading democracy “The best weapon against an enemy is another enemy”
- em-bee 3y ago
- oger 3y agoWhat are good and battle proven tools to A) monitor traffic on my home network - especially in a MikroTik environment B) identify malicious activity Thx
- lormayna 3y agoI have a Mikrotik at my home too. Beside securing the device, I suggest to filter and logs all the DNS queries and to export netflows and firewall logs somewhere (ELK or clickhouse).
- tamimio 3y agoJust drop all inbound and access your home network behind a vpn remotely for the ultimate protection, not perfect, but far more secure. And monitor at the DNS level, or have a service running to monitor network activity on the terminals.
- bdavbdav 3y agoThis seems a bit confusing. It highlights all the external hits, with no internal hits shown, then worries about IoT devices internally. Most people aren’t going to have any external ingress at all.
- tamimio 3y agoI have several honeypots on different services (some of them mimics industrial automation systems like SCADA), and the majority of these attacks are coming from China, followed by the US and then the Netherlands.