12 ms·
I run an open source honeypot that collects these botnet scans and produces blocklists. Blocklist download and configuration: https://knock-knock.net/blocklist
by djkurlander 2mo ago
I run an open source honeypot that collects these botnet scans and produces blocklists.
Blocklist download and configuration: https://knock-knock.net/blocklist https://knock-knock.net/blocklist
Honeypot dashboard, where you can see attempted attacks in realtime: http://knock-knock.net http://knock-knock.net
API: http://knock-knock.net/api http://knock-knock.net/api
- skinfaxi 2mo agoThis looks cool, where can I find the source?
- djkurlander 2mo agoIt's on github with an MIT license: https://github.com/djkurlander/knock-knock https://github.com/djkurlander/knock-knock. Have fun!
- skinfaxi 2mo agoThank you!!
- deleted 2mo ago[deleted]
- codegeek 2mo agoThank you for sharing. I will take a look.
- Bender 2mo agoCool site. I was curious and dropped your 100k list into a reverse DNS lookup site [1]. They may still have some of the records cached. I recognized quite a few of the scanner nodes and some other usual suspects. [1] - https://adver.tools/reverse-dns-lookup/ https://adver.tools/reverse-dns-lookup/
- djkurlander 2mo agoYeah, that’s pretty interesting! You can also see a live view of the ASN/ISP leaderboard by going to https://knock-knock.net https://knock-knock.net and choosing ISP from the carousel. That’s ordered by bot transaction count rather than IP count though. It never ceases to amaze me that these ISPs don’t bother to shut down the botnets. They could do so very easily. For example, they could identify the IP address of every bot that hit this honeypot with their ASN with one API call: https://api.knock-knock.net/check-asn?asn=<asn number>. (See https://knock-knock.net/api https://knock-knock.net/api). They just don’t care!
- Bender 2mo agoThe ISP's do not have a financial incentive to shut them down. To them that's a paying customer. The feds will go after the big botnets if they are touching financial networks or siphoning enough money from people because there is usually a few big bank accounts and virtual currency exchange accounts they can seize once big enough to look good in the media. That's why it's on us and a few big CDN's to block some of them.
- jwally 2mo agoWhat if I have a slimy TV box or nasty on my phone, living on my network? You take IP down, you kill the cancer but you also end up killing the patient.
- Bender 2mo agoNot the person you are asking but site operators can not tell intent. It could be something nasty on the network or a botter feigning ignorance. I'd say its probably an acceptable casualty in the battleground that is the internet especially for little one-off sites hosting blogs, forums, chat servers, etc... For a bigger site I would expect that person may have to open a ticket with the platform such as Amazon accepting that some CDN's and firewalls may be harder to get the block removed. This is why we can't have nice things.
- 2mo ago