ADMIN magazine · @adminmagazine
611 followers · 168 posts · Server hachyderm.io

From the ADMIN Update newsletter: Matthias Wübbeling examines the OpenCanary honeypot for detecting attacks admin-magazine.com/Archive/202

#security #honeypot #opencanary #network #docker

Last updated 1 year ago

ADMIN magazine · @adminmagazine
295 followers · 97 posts · Server hachyderm.io
SecuriLee · @Lob
2 followers · 36 posts · Server twit.social

my birds are now filling new dashboards in Splunk. is on!

ciso.pm/the-race-to-the-bottom

#opencanary #theracetothebottom

Last updated 1 year ago

SecuriLee · @Lob
2 followers · 29 posts · Server twit.social

my tells me 18/20 of the top credential sets it sees are related to the defaults exploited by Mirai: sc.ciso.pm/miraipasswords

#opencanary

Last updated 1 year ago

SecuriLee🇨🇭 · @SecuriLee
34 followers · 81 posts · Server infosec.exchange

According to my , 18 of the top 20 credential combos it gets given are related to Mirai: sc.ciso.pm/miraipasswords

#opencanary

Last updated 1 year ago

SecuriLee🇨🇭 · @SecuriLee
34 followers · 80 posts · Server infosec.exchange

Here's the ranking of Mirai credentials hitting my - bottom figures being where the creds rank in those seen by the honeypot.

#opencanary

Last updated 1 year ago

SecuriLee🇨🇭 · @SecuriLee
34 followers · 79 posts · Server infosec.exchange

More reporting, this time pulling the cross-section of credentials that intersect with the Mirai creds:

#opencanary #top40 #tyrannyofthedefault

Last updated 1 year ago

SecuriLee · @Lob
2 followers · 29 posts · Server twit.social

After one month of collecting passwords with , not a monkey in sight.....

#opencanary

Last updated 1 year ago

SecuriLee🇨🇭 · @SecuriLee
29 followers · 74 posts · Server infosec.exchange

Another host at has fallen in love with the MS SQL port on my 😂​

#ovhhostinginc #opencanary

Last updated 1 year ago

SecuriLee🇨🇭 · @SecuriLee
28 followers · 73 posts · Server infosec.exchange

Someone decided my MSSQL port is very, very interesting. Trust me, it‘s not but thanks for your 300‘000 connnections on Sunday 😳

192.99.9.170, my new best friend from Canada 🤣

#opencanary

Last updated 1 year ago

SecuriLee · @Lob
2 followers · 27 posts · Server twit.social

logging to over for a week now, giving some great statistics.

ciso.pm/opencanary-one-week-in

#opencanary #splunk #Tailscale

Last updated 1 year ago

SecuriLee · @Lob
2 followers · 26 posts · Server twit.social

Evidence that the Internet is a dirty place

#opencanary

Last updated 1 year ago

SecuriLee🇨🇭 · @SecuriLee
27 followers · 71 posts · Server infosec.exchange

My is now logging into Splunk (from Oracle Cloud via Tailscale) with a dashboard for weekly, monthly and yearly stats. The Internet is a dirty place!

#opencanary

Last updated 1 year ago

SecuriLee🇨🇭 · @SecuriLee
27 followers · 71 posts · Server infosec.exchange

@katzmandu I have VMs in my DMZ at home and also on my network at home 😂​

#opencanary #teenagers

Last updated 1 year ago

SecuriLee🇨🇭 · @SecuriLee
24 followers · 69 posts · Server infosec.exchange

My Splunk dashboard is now fairly indicative of trends hitting my . Including the latest usernames and passwords being attempted

#opencanary #dirtyinternet

Last updated 1 year ago

SecuriLee🇨🇭 · @SecuriLee
26 followers · 70 posts · Server infosec.exchange

logging to Splunk via Webhooks and JSON being translated into dashboards. Bye-bye one-week logging limit and basic statistics:

ciso.pm/improving-opencanary-l

#opencanary

Last updated 2 years ago

SecuriLee · @Lob
2 followers · 26 posts · Server twit.social

I managed to bring my into logging to Splunk with webhooks. It's really cool!

ciso.pm/improving-opencanary-l

#opencanary

Last updated 2 years ago

SecuriLee · @Lob
1 followers · 6 posts · Server twit.social

My in the Internet still has gaps in logging (too many webhooks configured = gaps) but sees 120'000 intrusion attempts per week.

With the gaps eradicated, I expect around 150'000 attempts per week which would be just shy of 8 million per annum.

On Monday in a 3 hour period, there were 12'000 attempts alone.

SSH and Telnet for were the main targets.....

#opencanary #pwnership #securitynow

Last updated 2 years ago

SecuriLee🇨🇭 · @SecuriLee
20 followers · 44 posts · Server infosec.exchange

My in the Internet still has gaps in logging (too many webhooks configured = gaps) but sees 120'000 intrusion attempts per week.

With the gaps eradicated, I expect around 150'000 attempts per week which would be just shy of 8 million per annum.

On Monday in a 3 hour period, there were 12'000 attempts alone.

SSH and Telnet for were the main targets.....

#opencanary #pwnership

Last updated 2 years ago

SecuriLee🇨🇭 · @SecuriLee
11 followers · 34 posts · Server infosec.exchange

I put together the steps I went through for in Oracle's Cloud: sc.ciso.pm/opencanarysetup
someone else might enjoy putting together their own honeypot :)

#opencanary

Last updated 2 years ago