Live data from Hacker News

Show HN: Watch bots interact with an SSH honeypot in real time

honeypotlive.cc

41–50 of 75 posts

Re: Show HN: Watch bots interact with an SSH honeypot in real time

#43
post #25

Earlier quoted context omitted.

Nah, Spur (a company tracking residential proxies) doesn't flag it at all. He's most likely just not very smart.

They're not doing a very good job at it, tried a few disposable free residential proxies - not flagged. Tried my CGNAT home connection - flagged. My phone connection - also flagged.

> tried a few disposable free residential proxies

Where are you finding free residential proxies?

> Tried my CGNAT home connection - flagged. My phone connection - also flagged.

Why does that mean they're doing a bad job? Since both are CGNAT, you're sharing the IP with lots of other people, and it's not unlikely that one of your network neighbors is infected.

Re: Show HN: Watch bots interact with an SSH honeypot in real time

#44
post #33
post #25

Earlier quoted context omitted.

Nah, Spur (a company tracking residential proxies) doesn't flag it at all. He's most likely just not very smart.

Maybe he is doing it for fun and not actually trying to hack the website with Rick Astley lyrics?

That doesn't make it less illegal?

Re: Show HN: Watch bots interact with an SSH honeypot in real time

#45
post #27
post #25

Earlier quoted context omitted.

Nah, Spur (a company tracking residential proxies) doesn't flag it at all. He's most likely just not very smart.

>Nah, Spur (a company tracking residential proxies) doesn't flag it at all. I looked into it and so far as I can tell it works off a blacklist system, rather than any sort of automatic analysis (eg. TCP or MTU fingerprinting). If you set up a "residential proxy" in the form of a home VPN, it won't be detected. It also means the detection is only as good as whatever their backlist source is. If it's a niche provider,…

[dead]

Re: Show HN: Watch bots interact with an SSH honeypot in real time

#47

Earlier quoted context omitted.

> Some kind of source IP masking would be prudent. As you pointed out, some of those machines are compromised, and you aren't making their owners' lives any easier. Hard for me to find much sympathy for negligent users who unintentionally allowed their home computers or phones to join a malicious botnet, or their ISPs who aren't stopping the activity. Even if it is my own grandma's PC. I agree about the content thoug…

Easy for you to say, assuming your PC is clean. I don't think negligent is the right word though. Ignorant maybe? Or some form of naivety? The negligence might be on software or hardware vendors, but grandma isn't to blame for the problem.

Software providers generally lack a duty to their clients to create and sell secure software. Further, generally, when you get hacked, there is only an interrupted causal chain between the software and your loss. Interrupting that chain is the intervening superseding cause of a criminal third-party. Finally, no states allow punitive damages, absent gross negligence in a software context.

Re: Show HN: Watch bots interact with an SSH honeypot in real time

#49
post #44
post #33

Earlier quoted context omitted.

Maybe he is doing it for fun and not actually trying to hack the website with Rick Astley lyrics?

That doesn't make it less illegal?

In many jurisdictions, "intent" is an element of the law
Post reply on HN