The Honeypot Diaries: Thousands of Daily Attacks on My Home Network
simone.org
simone.org
I remember years ago there was this vnc vulnerability that allowed one to login without a password. At the time I was doing "it support" for various small businesses in West Yorkshire, UK. All of my regulars had firewalls with (site to site) vpn for remote access, but often I'd get new clients I never saw before asking to fix something. When that vulnerability came out I was getting calls from such new customers daily about "their system is slow", "our email is not going out" (in these days even small businesses used to run their own email servers). Every single "new customer" I had during next few weeks was "hacked" by the vnc bug. It seems whoever used to do IT for them left vnc accessible from the Internet (not even limiting the source IPs on the firewall). Every single time the root kits I found had outputs in Chinese (it required changing windows cmds settings to even see it). Most were very basic, but they did manage to successfully kill the AV software and they all had their own storage drivers that hid certain folders unless I booted the system in the safe mode(tgese were mostly windows 2000/2003 sbs servers BTW). Frequently I'd find lists of other victims IPs on these systems and their scanning software. What was the goal of this campaign? Sending spam of course. As mentioned most clients only realised they were "hacked" when their system became horribly slow, or their outgoing email was cut off by their ISP blocking outgoing smtp traffic from their IPs following complaints. What was the spam? Viagra of course.... I saw lots of these. Many of these systems had personal data of people, I never noticed attempts to exfiltrate such data. The only time I dealt with proper attempt to steal money from a business account using the IT system was after a disgruntled it admin was fired.
This was almost 20 years ago. I'd love to find out how small network attackers try to "monetize" their victims today. Are they just searching for crypto, attempting "encrypting data" scams, or is there something more interesting? Curious minds want to know?
FFS.
I never want to know anything about CSAM and related. But it seems none of us can escape it.
I fear that if I ever make one of my hobby projects public, I'll be forced to learn all the security stuff.
Alas, I suck at security stuff. I left networking and admin for building CRUD apps, so many years ago, because I have no aptitude or interest. (Whereas I love solving customer use cases.)
What are noobs like me supposed to do?
> What are noobs like me supposed to do?
I'm not about to claim I'm some kind of expert on security but...
Don't let your computers talk to strangers. Your computers should only be talking or listening to you really and maybe other people who you trust and have authorized. If someone is not in that group, they should not even send back an error page, they should not even answer pings.
So set up single packet authorization so that your machines literally drop all network packets unless you send a cryptographically signed packet first. To these bots, it will be like the servers are not even there.
I was confused, too. Thought my ublock blocked the rest of the post there...I wonder where the upvotes come from. Do people actually click the link?
It feels to me like someone who has only just noticed that the majority of internet traffic is nowadays malicious.
In about 2002 I set up my first domestic mailserver, and was shocked (and frightened) at the proportion of traffic that was malicious. Then I started digging into other system logs. In those days most malicious traffic was from Eastern Europe. I've run honeypots, for entertainment. It was engaging for a while. Eventually I realised that running a home honeypot was a waste of effort, and I just hardened my systems and instituted a bit of monitoring.
Worse than that: running a home honeypot puts significant risk that malicious activity would be traced to you.
Crypto mining, installing software to sell access to the host as a “residential proxy”, good ole theft of data, using the host for DDoS, click fraud, etc
I learned some things about how bots fingerprint the honeypots, and patched it accordingly that they do not identify my service as a honeypot.
The funny thing about this was, that my ISP send me a letter (by post o.0), that i run a vulnerable service on my network.
The honeypot had a "MOD" from an old nuclear power plant, and did some random tarpit and randomly let random user/password combinations to log in.
It was a fun experiment
That being said: attributing those attacks to Chinese actors based on IP falls a little short. Proxychains exist and are used.
<Insert usual suspect here> high up can be read just as "many internet users there, whose PC or other device is infected with malware that tries to spread itself".
As the article states: originating device can be silly IoT device like a router, TV, printer, Ring-style doorbell, etc etc etc. In fact, chance of random IoT device being vulnerable and/or been 'recruited' in a botnet, may be bigger than the same with random PC / tablet etc. Many IoT devices are junk that rarely see firmware updates (if any).
1MB Club is a growing collection of performance-focused web pages weighing less than 1 megabyte.
EDIT: even in the green team! https://512kb.club/faq
Honeypot a popular, recent, public vulnerability and you’ll see a tonne of attacks.
The attempts are not because the author is a bank, but rather because the percieved difficulty is deemed to be trivial.
A) monitor traffic on my home network - especially in a MikroTik environment
B) identify malicious activity
Thx
You hardly have that letter somewhere?
This was ages ago. I try not to hold onto old corporate emails. And agree not to. I've honestly had mixed feelings about it given that some people probably got their door kicked in. In fairness to me they were DDoS'ing my customers. The CIDR blocks were part of a DDoS for hire farm.
“The best weapon against an enemy is another enemy”
Most people aren’t going to have any external ingress at all.
And for those who don't want to spend money buying it and prefer to DIY it, here are the instructions: https://www.youtube.com/watch?v=eMJk4y9NGvE