It was online for 3 seconds before getting a 404 request for /.git/config
honeypot.net
honeypot.net
I'd added a new hostname to a long-existing domain. Then I added that hostname as a new virtual host to a Caddy server I've been running for a long time. The requests were to that vhost, i.e. using the `Host: my-new-host.example.com` header, not just running `curl http://1.2.3.4`. They were asking for the brand-new host by name.
After hashing it out with some friends on Mastodon, I think it's most likely because Caddy acquired a Let's Encrypt cert, those certs are logged[0], and attackers pounce on new hosts as soon as they're in the logs.
This led me to paths that I wouldn't otherwise be able to find and a complete server takeover through remote code execution. One of their developers left test code for a website template and an unrestricted file upload form.
I don’t have an answer. This normal isn’t OK. I don’t know what to do about it though.
This is not a popular opinion and it often gets dunked on reflexively, but I truly believe the default is low-trust. We are one evolutionary step away from chimpanzees, with barely enough "society" grafted on to our world, which mostly doesn't function. You need to assume you are under potential attack at all times and be prepared to defend against it. Whether it be a physical attack, social engineering, scams, advertisements... in cyber-space and in meat-space. Any other security posture, long term will eventually open you up to a breach by an adversary.
I think it's a tiny minority of people doing this, with the Internet amplifying their reach.
This world runs on trust. For example it's extremely easy to shoplift, yet the vast majority of people don't. Because people are not like that. It's easy to forge things, yet most people don't, it's easy to snatch and grab random objects from people or places, yet, people don't.
The next time you are out, think like a criminal and see just how much stuff you would be able to do, yet you don't, and neither does anyone else.
It's a tiny minority who do abuse that trust.
(And we are not "one evolutionary step", we are several orders of magnitude steps away from chimps. In intelligence chimps are more similar to dogs than they are to humans, chips are smart - for animals. In comparison to humans they just aren't.)
And IMHO it's better that way, because the alternative --- which some seem to be slowly encouraging us towards --- is dystopia.
I suspect this is one of the overall effects that have come about on account of individuals judging the inequity across the world.
Personally I don't really know how to draw a clear line between acceptable and unacceptable here. Sure we can assume intent when requesting a users API from a standard WordPress install or plugin, but can we really say what the person's intent is? There are white hat hackers after all, and a law blocking this would almost certainly stop anyone interested in discovering these vulnerabilities and making them known before someone with bad intent finds them.
I'm always very hesitant to see any top-down changes trying to change public sentiment though, whether by some kind of intervention to change norms or through law. Norms and laws should reflect, rather than coerce, public opinion. If a majority of people would, of their own accord, agree that hitting common API endpoints on servers publicly connected to the internet is too dangerous to be allowed, I guess we could try to draw a line between that and hacking or penetration testing with good intent.
Short of that though, is it really our place to convince people that this is wrong? Sure we can absolutely do a better job of raising awareness of what's going on, but at least to me awareness of the facts should be the extent of it. People can make up their own decisions on whether or not something is okay, or if its bad enough that we need to further empower the government to enforce more laws.
The FBI is responsible for super serious and intrastate crimes like terrorism, kidnappings and trafficking. Those resources get redirected to policing copyright violations at the behest of the MPAA and other IP orgs.
ICE resources are redirected from border safety to protecting profit margins impacted by knockoff goods.
Whatever entity gets setup to address your concerns will eventually be captured by major corporate interests.
This shouldn't be hard. If we can't fix that then good luck tracking down bad actors on the interwebs
an authoritarian global government and cameras you aren't allowed to turn off in every room of your home
If you’re relying on obscurity
Presumably the former caused your new hostname to be published for all of the Internet to see? That doesn't sound like obscurity to me.
I've had a service running on a high port for many years at the same IP. I've seen it get the occasional "knock" from some scanner or bot, but it has been generally quiet. It probably also depends on your IP, as some parts of the Internet are likely scanned far more frequently and aggressively than others.
What do you mean? You don't connect to ssh in the VPS directly, but through a VPN? How does this protects the VPS from attacks?
Exposing wireguard to the world isn't much better than exposing ssh
For hosting, one of those layers is going to be: Don't expose ports publicly, if you don't want people connecting to them.
Unless you're hosting a public SSH service, you shouldn't expose SSH on a public network.
It protects the VPS from a few avenues of attack:
- SSH vulnerabilities (either current, or because the server has not been updated regularly) - SSH server misconfiguration - Credentials leaked/stolen - Denial of Service (hammering SSH in an effort to either consume resources on the host, and make it harder to fix/patch an issue, or to force your hosting provider to block SSH)
[1] https://en.wikipedia.org/wiki/Survivability#Military (at the bottom of the section)
OpenSSH is probably one of the most audited pieces of software running on your system.
> SSH server misconfiguration
Just like with TLS use tools to validate your config (like https://www.ssh-audit.com/) and you'll be mostly safe.
> Denial of Service
Usually it's easier to DoS whatever other service your server is running, like a web backend och mail server or similar.
---
On the other hand you now need to manage two keys, the wireguard one and the SSH one, and you still need to expose your wireguard server (which is not necessarily more secure than OpenSSH).
Just disable SSH password auth, run one of the ssh audit tools like the one I linked above and use hardware keys like the openssh yubikey feature (optional but nice to know that the key can't be cloned).
If you really don't want people trying to ssh to you move it to another port or use port-knocking.
But you still have to maintain it, and vulnerabilities do still get found.
---
As for exposing Wireguard, that's not necessarily true - You can have your server dial-out to another host instead.
Additionally, because Wireguard operates on UDP, and doesn't respond unless you pass the right credentials - it's very hard to detect from a cursory scan. You would have to already know what IP and port that Wireguard was listening on.
SSH because it's TCP based can be detected by any random scanner, regardless of it's port. Unless you're using some conditional firewalling, such as like with port-knocking.
Would like to learn more though.
I've always wanted to setup an interactive honeypot ssh server which prints the standard message for a rejected login and then pretends to close the connection, while running a keylogger to hopefully intercept some command which asks for password. The major obstacle is that people customize their prompts, although many probably use whatever is set by default on Ubuntu.
I did a bunch of Devops a few years ago on a Startup, and whenever i started a new AWS EC2 instance, i started getting request for Wordpress files, and other common CMS files.
(this is not a prejudice; >80% of auto-bans my servers are issuing are for Tencent IPs. I should grab some exact numbers at some point.)
was there some alternative development path or is this inherent in the physical network design?
If it cost some amount of money to connect to a server, all of this would stop almost immediately.
And trying to attach a price to a transaction that makes it unprofitable for bad actors but not be a burden on legitimate users is intractable.
Even if ISPs quickly shut this stuff down the existence of botnets would allow it to continue.
It’s like spam. Just tragedy of the commons.
> having an all purpose 1000kloc http server. > serving your source code root > not using any permissions system
With hostnames is just another layer, that may have more requirements, but the motivations are similar.
And then there’s .DS_Store.
What’s the point of that? In case you find a Mac to launch more targeted attacks against known bugs? To know if the developer is in a Mac and just copied files without filtering out dot files?