There are too many damn honeypots
vulncheck.com
vulncheck.com
I wouldn't conclude that to be a honeypot. If anything, BIG-IP and Confluence are frequently used by the same kinds of companies, so I would expect the majority of that first query to be real Confluence servers. Queries 2-4 probably did a better job filtering out real honeypots.
In reality, there might be about as many honeypots as there are real Confluence servers, which is still far too many, but not quite as extreme a disparity as suggested by the numbers in this article.
And those are just the headers! Just taking a cursory look at [4], I can see it is claiming to be a ASP.net server being served by a TP-Link device on one port, all the while also being a QNAP device on another, and also another PHP application served through thttpd. All the while running on AWS...
[1] https://www.shodan.io/host/44.204.245.187
[2] https://www.shodan.io/host/13.246.35.40
If nothing else, it's fun to see who pokes you, even if I don't actually follow up on it.
You could imagine it wasting the resources of hackers convincingly enough that it would water down the potential effect of hacking online generally. It could even make up fake internal documents and state secrets.
I'm only half joking (I think)?
Unfortunately, I can't remember the name of the place that denied the leak, which makes it hard to search for amongst the torrent of attacks that I find in search results.
It was Europcar https://twitter.com/BleepinComputer/status/17524608970316843...
And it wasn't LLM/AI generated, just good old faker apparently https://twitter.com/KasadaIQ/status/1753201379043365326?t=IZ...
Because they're really good at this, and even idiots can use them.
What I want to know is why people capitalise things that aren't acronyms or initialisms, e.g. "MAC"[0], "SWIFT"[1], the "S" in "LLMS", and the "HAT" in "CHATGPT" :P
[0] The brand which is a contraction of Macintosh, not to be confused with Medium Access Control or several other things.
[1] As in the language, not the Society for Worldwide Interbank Financial Telecommunication.
It's ZIP code.
Annoys the heck out of me...
Someone quotes from the novel here: https://news.ycombinator.com/item?id=14554765
I’ve ran honeypots, I still run some - it’s not hard to do properly. There’s hundreds of thousands of ones clogging up search results on Shodan, etc, though that are absolute rubbish
There's nowhere near enough honey pots. I'm running endless on my home server, and a WordPress "login" that just delays 5 seconds before denying on a VPS. I've run Cowrie and a full blown WordPress honey pot in the past.
If everyone who could did run honey pot(s) the scanners, spammers and bottom feeding low life's would find it unprofitable to do simple, dumb things. Same as if everyone picked up every phone call and chatted up the scammers.
Scum of the earth.
In case anyone is not aware, this is an entire Twitch/YouTube genre.
Sure some metrics around "number of instances out in the wild" will determine if threat actors put resources into developing mass-scale exploitation, but if you are patching for a company it doesn't REALLY matter.
If you are a target and are exploitable it doesn't matter how many honeypots are reporting as Confluence -- you will be breached if your Confluence server is vulnerable and exposed.
The best argument against honeypots would be that if we had some active group that was working with all affected users to patch and verify patches, if that was the case then the honeypots are a detractor. News outlets should do their best to get the best information, but this is the least-worst thing around vulnerability reporting IMO.
> Understanding the scale of an issue is important, and therefore, being precise about the number of potentially impacted hosts is important too. Those who copy overinflated statistics or haven’t done their due diligence are making vulnerabilities appear more impactful than they truly are.
I don’t really understand the logic here. What does it mean for a vulnerability to “pop off?” I can see some argument for worrying about the number of “friends” you have in the vulnerable population in the case of something like a worm, since all of your “friends” are potential attackers. But for normal vulnerabilities you should fix it regardless of the popularity. Who cares if it becomes widespread?
And of course any effort wasted in honeypots is great.
But the Internet at large? Those numbers don't matter.
I don't care if there's 4,000 vulnerable confluence servers or if there's 247,000. I can if my confluence server is vulnerable
So many questions