• irmadlad@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    13 days ago

    Every so once in a while I get the notion to run a honeypot, but it doesn’t seem prudent for me to attract that much attention to my network. I can already see the traffic using ntopng, and pfsense/unbound/suricata/pfblockng and robust ruleset do all the heavy lifting. I block everything, then only allow what is absolutely necessary. If it were run solely on a small VPS or droplet, it’d be an interesting project, but I’m not sure I want to poke the bear that much on my local network.

    • drkt@scribe.disroot.orgOP
      link
      fedilink
      English
      arrow-up
      0
      arrow-down
      1
      ·
      13 days ago

      You shouldn’t run a honeypot for any other reason than fun and research, but if you’re into either of those, go for it!

  • non_burglar@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    14 days ago

    Op, if this is you, do not do this, especially not on your home IP.

    Honeypots are a great way to find out exactly what your place is in the hierarchy of real black hats.

      • non_burglar@lemmy.world
        link
        fedilink
        English
        arrow-up
        0
        ·
        14 days ago

        Hackers don’t poke around themselves, generally. They use bots and scripts to collect info and then return in person to pry open targets they want or find interesting.

        Op is tarpitting with a stream, which is a telltale sign of a honeypot, nothing else behaves that way. So a bot crawling for content? Fine. A bot collecting info for suitable targets? Might get the attention of the person looking. And once you have a hacker’s attention, you might be in trouble if they’re competent and start pressing buttons.

        You really have to know what you’re doing to understand where in the stack an attacker is going pull levers, which is as individual as people themselves.

        • drkt@scribe.disroot.orgOP
          link
          fedilink
          English
          arrow-up
          0
          arrow-down
          1
          ·
          14 days ago

          nothing else behaves that way.

          This is quite wrong, but it doesn’t matter, because if your setup is insecure, then you’ll find out sooner or later anyway. The hacking space is pretty much automated at this point, which is why my honeypot works at all.

          Do you also think that anyone who puts Anubis in front of their website is getting the attention of anonymous illuminati master-hackers because it causes their bots to waste a few processing cycles? Tarpitting is no different. If your bot is written poorly, it will get stuck on even legitimate pages.

      • drkt@scribe.disroot.orgOP
        link
        fedilink
        English
        arrow-up
        0
        arrow-down
        1
        ·
        14 days ago

        It does not; tarpitting is a normal practice.

        No one sitting on 0days are gonna waste them on randos, and my setup is secure besides. I’ve been doing this, and worse, for years.