Zum Hauptinhalt springen
tsecurity.de LIVE
Echtzeit-Radar & Feeds
Alle RSS Feeds
👥 Community & Social
Sichere ProgrammierungRefreshed repository pull requests page generally available(22.09.2026 um 03:25 Uhr)
Sichere ProgrammierungThe Joy of Learning the Basics Again(22.09.2026 um 03:28 Uhr)
Sichere ProgrammierungZero-Code OpenTelemetry Tracing for Dagster(22.09.2026 um 03:39 Uhr)
Linux Tipps & Hardening`prime-all`(22.09.2026 um 02:28 Uhr)
IT Security Toolsopensoho v0.15.2(22.09.2026 um 03:33 Uhr)
IT Security NachrichtenUS Proposes AI Incident Alert System in Talks With China, Bessent Says(22.09.2026 um 04:01 Uhr)
Sichere ProgrammierungRefreshed repository pull requests page generally available(22.09.2026 um 03:25 Uhr)
Sichere ProgrammierungThe Joy of Learning the Basics Again(22.09.2026 um 03:28 Uhr)
Sichere ProgrammierungZero-Code OpenTelemetry Tracing for Dagster(22.09.2026 um 03:39 Uhr)
Linux Tipps & Hardening`prime-all`(22.09.2026 um 02:28 Uhr)
IT Security Toolsopensoho v0.15.2(22.09.2026 um 03:33 Uhr)
IT Security NachrichtenUS Proposes AI Incident Alert System in Talks With China, Bessent Says(22.09.2026 um 04:01 Uhr)
Intelligence View
⚡ tsecurity.de Intelligence

How we tricked 1M+ bots and hackers with our honeypot

Hi guys we just wrapped up a 90-day experiment with Krawl's deception honeypot on a Kubernetes deploy and the numbers are wild. Figured this community would appreciate a proper writeup. GitHub: https://github.com/BlessedRebuS/Krawl TL;DR:…

0
↗ Quelle (reddit.com)
Reagiere als Erste:r — dein Feedback zählt!

Hi guys we just wrapped up a 90-day experiment with Krawl's deception honeypot on a Kubernetes deploy and the numbers are wild. Figured this community would appreciate a proper writeup.

GitHub: https://github.com/BlessedRebuS/Krawl

TL;DR: We deployed a fake but realistic-looking API surface with plausible-sounding endpoints, seeded fake credentials in crawlable HTML, and watched what happened. Over 1,400,000 (on our instance) unique non-human sessions hit it. Here's everything we learned.

Stats at a glance:

  • 1.4M bot sessions trapped
  • 18% of the attacks were command injections
  • 539 distinct attacker profiles identified

https://preview.redd.it/dsr73ww2olrg1.png?width=1442&format=png&auto=webp&s=eca8ba381d8c56a7f63a9694366d6c3caa0721e8

How the honeypot works:

Krawl's deception layer creates a shadow version of your infrastructure: fake /admin, /.env, /cedentials.txt, and even a plausible /api/v1/users and /api/v1/secretsthat returns fabricated but structurally correct data. Any real user would know it's a dead end or a bait. But scrapers and exploit kits? Nah.

The key feature is the behavioral fingerprinting. Instead of blocking bots at the edge (which just teaches them to evade), you let them in, observe their full request sequence, and build a dossier.

The most interesting findings:

AI scraper bots were the #1 category by volume. Most were poorly rate-limited and didn't respect robots.txt at all, expecially Meta and OpenAI bots (sus).

Credential stuffers were not to much and they used mostly basic credentials.

Several bots attempted lateral movement simulation, they probed internal-looking paths and subdomains that we'd leaked in fake HTML pages. Also notable: a significant portion of bots probed classic Unix paths like `/etc/passwd` and `/etc/shadow`, confirming that LFI playbooks are still very much alive and automated.

We're planning to open-source the attackers knowledge base we are building from this, happy to answer questions about the setup.

Live demo dashboard: https://demo.krawlme.com/das_dashboard

Let us know your thoughts! You are welcome if you want to help us with the project or deploy your own Krawl instance.

submitted by /u/ReawX
[link] [comments]
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten How we tricked 1M+ bots and hackers with our honeypot

Thematisch verwandte Begriffe: tricked, bots, hackers, with · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-49449 | Joplin is an open source note-taking and to-do application that organise…
Advisory →
TTS Reader • tsecurity.de Voice
tsecurity.de Icon
tsecurity.de App
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag
Themen-Radar & Intelligence Matrix
Echtzeit-Taxonomie nach Angriffsvektoren & Plattformen

tsecurity.de Live Threat Radar

🔴 LIVE RADAR
MONITORING
AKTIV
CVE-DATENBANK
LIVE
🔍
Community Radar & Live Chat
Sentinel Bot online • Live-Stream
Dein Cluster: Security Explorer
Match:
lädt…
Verbindung zum Community-Stream wird aufgebaut...
Bearbeitungsmodus — Senden überschreibt deine Nachricht
Community-Puls — was gerade passiert
lädt…
Aktivitäten deiner Analysten
lädt…
Neues Thema oder Eilmeldung einreichen

Reiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung.

Heiß diskutierte Einreichungen
🔖 Gespeicherte Artikel
📂 Keine gespeicherten Artikel vorhanden.
Zurück Ziehen Vor
Links: vorheriger Artikel Rechts: nächster Artikel unten: schließen
News NIS-2 Frühwarnung Tier-1 Intel ⏱️ 3 Min vor 10 Min
Artikeldaten werden geladen...

Zurück: vorheriger Vor: nächster
↗ Original-Quelle
Social Reaktionen Deine Reaktion zählt
Einstufung & Relevanz-Poll 0 Stimmen
In sozialen Netzwerken teilen 1-Klick