Live data from Hacker News

Someone is running mass vulnerability scans, spoofing AI bots like ClaudeBot

knownagents.com

31–40 of 242 posts

Re: Someone is running mass vulnerability scans, spoofing AI bots like ClaudeBot

#31
post #6

Every server with port 80/443 open has thousands of hits a day from random boxes looking for wordpress login pages. The only new thing is that they're pretending to be a different type of annoying bot. There's a new layer of sophistication and subterfuge, but it's the same junk traffic we've always dealt with.

Another interesting thing here is the paths they're targeting, many are for newish AI coding tools

There are a few novel ones but I’ve been seeing most of them in my logs for longer than generative AI has existed. This isn’t remotely new, the vector is just getting bigger.

Re: Someone is running mass vulnerability scans, spoofing AI bots like ClaudeBot

#32
post #4

Earlier quoted context omitted.

There are many possibilities but one of them could be some new vuln was released and they are looking for it. That would require looking at the URL's they are requesting. Botters run their own purpose built campaigns. Do you also have a summary of URL's requested by unique counts?

Looks like many of the paths relate to AI coding tools. There are some examples below the chart

You keep repeating this about a small minority of the tools that were posted.

Re: Someone is running mass vulnerability scans, spoofing AI bots like ClaudeBot

#34
post #17

Earlier quoted context omitted.

It's still not really anything special. Thousands isn't even large scale. Any random bozo can trigger that.

This is a random sample of completely unrelated websites, which indicates that the total scale is much larger. This is not saying that it is difficult to make thousands of requests.

Is this your company? If it is, your cheerleading makes you very hard to trust. If it’s not, I’m sure that everyone gets the point - you adore everything about this research and can’t see any possible problems.

Re: Someone is running mass vulnerability scans, spoofing AI bots like ClaudeBot

#36
post #34

Earlier quoted context omitted.

This is a random sample of completely unrelated websites, which indicates that the total scale is much larger. This is not saying that it is difficult to make thousands of requests.

Is this your company? If it is, your cheerleading makes you very hard to trust. If it’s not, I’m sure that everyone gets the point - you adore everything about this research and can’t see any possible problems.

Not asking for trust, just sharing the data/math

Re: Someone is running mass vulnerability scans, spoofing AI bots like ClaudeBot

#37
post #28
post #5

Someone is always running mass vulnerability scans. That's a "water is wet" state of the Internet.

I think this is more of a "if you left your AI tools exposed someone is looking for them" change. Hacking someone else's agents sounds like a great way to spend less on your own tokens.

Nah these are just the typical vuln scans that try all kinda basic shit, looking for anything commonly used AI tools included.

Re: Someone is running mass vulnerability scans, spoofing AI bots like ClaudeBot

#38

On average about 100 (TCP) requests hit my home router per minute doing various probing and scanning. Lots of checking for the telnet port obviously. Sometimes you can see a swarm of entirely different IPs scanning the full port range (probing the ports one-by-one). You'll see a lot of deepfield, censys-scanner, visionheight.com, shadowserver.io, etc., but also the usual suspects of Chinese or Russian IPs. With OpenW…

I have ubiquity UniFi for this reason (amongst others). OpenWRT is a good choice as well. Most home router software is such junk, might as well leave the door open..

Re: Someone is running mass vulnerability scans, spoofing AI bots like ClaudeBot

#39
post #26
post #11

Earlier quoted context omitted.

Same for the origin IP address. The fiber leaving your country is tapped, and those people can inject packets with any origin IP that they want. Your ISP has no way to check if their peer actually received a certain packet from a certain country or not. From a technical perspective, all this "china/russia" attribution is built on a quite shaky foundation. As a sysadmin you'd never know if it would be the British crow…

Problem here is there are not single fibers attaching (most) countries, but a bunch of them. If you control both the ingress and egress for some particular users it's possible, but if you don't then your probing packing may end up back in China with a lot of evidence of backscatter.

I'd be surprised if there is a single route from EU to non-EU countries which does not pass through British control.

Re: Someone is running mass vulnerability scans, spoofing AI bots like ClaudeBot

#40
post #34

Earlier quoted context omitted.

Is this your company? If it is, your cheerleading makes you very hard to trust. If it’s not, I’m sure that everyone gets the point - you adore everything about this research and can’t see any possible problems.

Not asking for trust, just sharing the data/math

You forgot the "Yes, that's my company" part in your reply (https://ghking.co)
Post reply on HN