fun to watch until the ssh user input exploits the web interface :P
Show HN: Watch bots interact with an SSH honeypot in real time
41–50 of 75 posts
Re: Show HN: Watch bots interact with an SSH honeypot in real time
#42Re: Show HN: Watch bots interact with an SSH honeypot in real time
#43Earlier quoted context omitted.
Nah, Spur (a company tracking residential proxies) doesn't flag it at all. He's most likely just not very smart.
They're not doing a very good job at it, tried a few disposable free residential proxies - not flagged. Tried my CGNAT home connection - flagged. My phone connection - also flagged.
Where are you finding free residential proxies?
> Tried my CGNAT home connection - flagged. My phone connection - also flagged.
Why does that mean they're doing a bad job? Since both are CGNAT, you're sharing the IP with lots of other people, and it's not unlikely that one of your network neighbors is infected.
Re: Show HN: Watch bots interact with an SSH honeypot in real time
#44Re: Show HN: Watch bots interact with an SSH honeypot in real time
#45Earlier quoted context omitted.
Nah, Spur (a company tracking residential proxies) doesn't flag it at all. He's most likely just not very smart.
>Nah, Spur (a company tracking residential proxies) doesn't flag it at all. I looked into it and so far as I can tell it works off a blacklist system, rather than any sort of automatic analysis (eg. TCP or MTU fingerprinting). If you set up a "residential proxy" in the form of a home VPN, it won't be detected. It also means the detection is only as good as whatever their backlist source is. If it's a niche provider,…
Re: Show HN: Watch bots interact with an SSH honeypot in real time
#46Re: Show HN: Watch bots interact with an SSH honeypot in real time
#47Earlier quoted context omitted.
> Some kind of source IP masking would be prudent. As you pointed out, some of those machines are compromised, and you aren't making their owners' lives any easier. Hard for me to find much sympathy for negligent users who unintentionally allowed their home computers or phones to join a malicious botnet, or their ISPs who aren't stopping the activity. Even if it is my own grandma's PC. I agree about the content thoug…
Easy for you to say, assuming your PC is clean. I don't think negligent is the right word though. Ignorant maybe? Or some form of naivety? The negligence might be on software or hardware vendors, but grandma isn't to blame for the problem.
Re: Show HN: Watch bots interact with an SSH honeypot in real time
#48fun to watch until the ssh user input exploits the web interface :P