Live data from Hacker News

Humiliating IIS servers for fun and jail time

mll.sh

31–40 of 106 posts

Re: Humiliating IIS servers for fun and jail time

#32
post #6

This is extremely well done design (at least on full desktop browsers). Amazing content as well.

> This is extremely well done design (at least on full desktop browsers).

I can't tell if you're being sarcastic, but on my full desktop browser the side bar overlaps the main panel, putting text on top of other text.

P.S. Other than this, I do like the presentation.

Re: Humiliating IIS servers for fun and jail time

#35
post #32
post #6

This is extremely well done design (at least on full desktop browsers). Amazing content as well.

> This is extremely well done design (at least on full desktop browsers). I can't tell if you're being sarcastic, but on my full desktop browser the side bar overlaps the main panel, putting text on top of other text. P.S. Other than this, I do like the presentation.

It looks decent on my 1920x1080p window running on a 4K monitor, but I have overlapping problems on my M1 Macbook.

Re: Humiliating IIS servers for fun and jail time

#36

I front all my honeypots with the IIS landing page precisely because it attracts black hat jagoffs. Nothing makes me happier than knowing I've wasted hours of their time chasing their own tails.

Unless you're honeypotting in the IP range of an established organization, all you're doing is getting bot traffic. High-tier blackhats focus on big targets, and low-tier ones focus on low-hanging fruits they find off shodan or application 0days they've found.

"Guys, guys, guys, listen, listen, listen. So I'm in this computer, right? So I'm lookin' around, lookin' around, throwing commands at it, I don't know where it is or what it does or anything..."

Re: Humiliating IIS servers for fun and jail time

#37
post #15

Does anyone use IIS anymore?

Back in the early-2000s, I passed the Microsoft certification exam for IIS. I had never even heard of the product (I was told my company had some extra credits at the testing center, I was there taking another exam (Solaris 8 certification), so I figured why not?) I know, MCSE exams were notoriously simple back then, but good god - usually, for every question, 3 of the 4 possible answers didn't even make sense. Anyway, I figured there was no way IIS would last if any dipshit could become "certified" in the product.

Re: Humiliating IIS servers for fun and jail time

#39
post #36

Earlier quoted context omitted.

Unless you're honeypotting in the IP range of an established organization, all you're doing is getting bot traffic. High-tier blackhats focus on big targets, and low-tier ones focus on low-hanging fruits they find off shodan or application 0days they've found.

"Guys, guys, guys, listen, listen, listen. So I'm in this computer, right? So I'm lookin' around, lookin' around, throwing commands at it, I don't know where it is or what it does or anything..."

Some ATM in bumsville Idaho spit $700 into the middle of the street.

Re: Humiliating IIS servers for fun and jail time

#40
post #15

Does anyone use IIS anymore?

Back in the early-2000s, I passed the Microsoft certification exam for IIS. I had never even heard of the product (I was told my company had some extra credits at the testing center, I was there taking another exam (Solaris 8 certification), so I figured why not? ) I know, MCSE exams were notoriously simple back then, but good god - usually, for every question, 3 of the 4 possible answers didn't even make sense. Anyw…

That's the value add. Any dipshit can be trained in the Windows server stack, so you can staff your back office with dipshits. For a while in the early 2000s—before the cloud era—Windows was routinely found to have a lower TCO than Linux as a server OS for precisely this reason. More actual deployments too, especially in corporate intranets.
Post reply on HN