• drkt@scribe.disroot.orgOP
    link
    fedilink
    English
    arrow-up
    6
    arrow-down
    1
    ·
    3 days ago

    nothing else behaves that way.

    This is quite wrong, but it doesn’t matter, because if your setup is insecure, then you’ll find out sooner or later anyway. The hacking space is pretty much automated at this point, which is why my honeypot works at all.

    Do you also think that anyone who puts Anubis in front of their website is getting the attention of anonymous illuminati master-hackers because it causes their bots to waste a few processing cycles? Tarpitting is no different. If your bot is written poorly, it will get stuck on even legitimate pages.

    • non_burglar@lemmy.world
      link
      fedilink
      English
      arrow-up
      3
      arrow-down
      5
      ·
      3 days ago

      it will get stuck on even legitimate pages

      what

      Please go to a local ctf, even just a high school-level one.

      • drkt@lemmy.dbzer0.com
        link
        fedilink
        English
        arrow-up
        3
        arrow-down
        2
        ·
        edit-2
        3 days ago

        I can’t engage with you when you can’t or won’t quote the full sentence. You are literally picking a section of a sentence, stripping it of context so it looks wrong, and then pretending I said that.

        If your bot is written poorly, it will get stuck on even legitimate pages.

        The point I am making is that the only way you’re getting into my network is if you’re sitting on a crazy 0day for Debian, Apache or PHP. My network isn’t a playground that I set up like a jigsaw for someone to “solve”. There’s nothing to solve, it’s not a CTF. You can’t dump points into a hacking skill and magically bypass some of the most vetted and battle-tested software in the world.

        • non_burglar@lemmy.world
          link
          fedilink
          English
          arrow-up
          2
          arrow-down
          1
          ·
          2 days ago

          You need to chill out and not get so worked up about someone calling out your promotion of honeypots in a forum where the vast majority don’t even know the difference between DNS and PKI, and aren’t clear on the delineation between their LAN and the internet.

          There’s nothing to solve, it’s not a CTF.

          You misunderstand, I’m not implying your network is a CTF. I mean go to your local security group and watch how pen testers work. I can tell you they certainly do not fall for “tarpits”, even the fairly new kids.

          Ultimately, you can do what you want, I obviously can’t stop you.