HNHacker News
TopNewBestAskShowJobs

mikaelchoni

75 karma · joined July 22, 2011

submissionscomments
mikaelchoni··on Fusker - a NodeJS security system that attacks back
Don't enable any payloads besides blacklisting then. Problem solved
mikaelchoni··on Fusker - a NodeJS security system that attacks back
Thanks for the suggestions. All of the detections are extremely primitive right now, I didn't get a lot of time to put work into them (the whole project has roughly 2-3 hours of time into it) but tomorrow they will be improved.

As I said to someone in another comment, the main purpose of the framework is socket.io packet analysis. The http detectives are merely for testing at this point while the framework itself matures

mikaelchoni··on Fusker - a NodeJS security system that attacks back
Hmm... this never occurred to me. The future of the project is going to be socket.io packet analysis with detectives. The current http request analysis is really weak and not intended to be the main focus

If you want to prevent this from happening there will be http-xss and socket-xss detectives in the future, just leave out the http-xss to keep it safe. Optionally you could always set your payloads to logging only

mikaelchoni··on Fusker - a NodeJS security system that attacks back
OP/Creator here

Entire project was created in a matter of hours so it's pretty basic for now. Not a fan of the "this is lame shitsux" mentality going around but I'll get used to it. All included modules will become much more sophisticated with time so please hold those comments off until I get more than 2 hours to put towards the project

If you have any detection/payload suggestions please comment in here and I will most likely add them. Keep in mind that this is all for the lulz

If you have anything you want to add, feel free to fork!

mikaelchoni··on Fusker - a NodeJS security system that attacks back
Blacklisting is done for small temporary amounts of time

And yes, some things are not finished yet. The project was started a matter of hours ago and not even close to it's full potential

EDIT: Keep in mind you are the one who decides what modules and payloads to use. Blacklisting is optional