Exploiting MySQL arbitrary file read: a honeypot that kicks
abclinuxu.cz
abclinuxu.cz
shutdown -h now
The segment at risk is almost exclusively black-hat, although maybe you could MiTM a connection....
But I think the main scenario is where the MySQL server is compromised and the attacker wants to pivot to the client machine.
This would be akin to "But officer he stole my drugs", sure they committed a crime but in reporting it you implicated yourself.
I eagerly await your entrapment defense argument.
https://www.wired.com/2016/05/history-fbis-hacking/
If they have a search warrant for your server and you hack back, you're liable to have a bad time.
You might _think_ that ec2 instance is "your server", but the FBI are unlikely to serve you with that warrant. I'd guess it'll go to Amazon, who may or may not care about whether you even know of its existence. (Especially if the warrant is for someone else with a VPS on the same piece of hardware that "your server" is on...)
Cracking passwords in that file and using those credentials to log in to someone else's box is a _loooooong_ way over the line though...
https://www.washingtonpost.com/news/the-switch/wp/2014/04/11...
weev was actively initiating that connection to somebody else's server. In this case, the honeypot is sitting idly, and _responding_ to someone else's connection (in a manner that's clearly unauthorised), and it's responding with something valid but unexpected.
Not that I'd want my lawyer having to explain that difference to a jury...