Перейти к содержимому

What Hits an Open SSH Port — One Hour of Real Honeypot Logs, 552 Machines, 74 Countries

Busy Work Labs

0:00 / 0:00

What Hits an Open SSH Port — One Hour of Real Honeypot Logs, 552 Machines, 74 Countries

196 просмотров · 10 дней назад
Busy Work Labs
21 подписчик
196 просмотров · 10 дней назад
A cowrie SSH honeypot on a public IP, port 22 open to the internet, left alone for ten days. This is what arrived: 1,050 sessions from 552 distinct machines in 74 countries, 133 of them getting all the way to a shell prompt. Ten days of capture, played through once in an hour, every line carrying the real timestamp it was recorded at. Most of it is not exciting, and that is the point. Bots connect, try one password, get a shell, run `uname -s -v -n -r -m` to see what architecture they landed on, and disconnect two seconds later without doing anything else. Hundreds of those, from Argentina, Ukraine, Uzbekistan, Chile. Sessions that open and close in the same second. The client strings are their own small story. 154 of them announce themselves as plain `SSH-2.0-Go` — one toolchain doing most of the scanning on the internet. Twenty-two are `ZGrab SSH Survey`, an academic scanner that is at least honest about it. Four are `MGLNDD_address_22`, a fingerprint nobody has ever fully explained. And fifteen are not SSH at all: `GET / HTTP/1.1`, and then `GET /favicon.ico`, arriving at port 22 from something that never checked what it had connected to. Twelve times over the hour the feed cuts to a real terminal recording, replayed at reading speed so you can actually follow what the bot typed. One dumps 12 KB of shell in a single paste — a fingerprinting script with a lookup table of every ARM core ID from Cortex-A5 to Neoverse-V3, just to identify the CPU. One `cat`s `/bin/echo` and reads the ELF header off the screen to get the architecture. One drops a binary named `sshd` in a dot-directory and launches it with a list of forty addresses to go hit next. And one, at 08:57 on the fourteenth, quietly checks whether it has been caught: `ls -d /home/cowrie /opt/cowrie /srv/cowrie`, then `/proc/1/cmdline`, then `/proc/version` — a honeypot-detection routine, running inside the honeypot. Every source address on screen is a stable pseudonym (`ATTACKER-IPv4-207`), not a real address. The machines scanning port 22 are mostly compromised themselves and belong to third parties, so they are pseudonymised — consistently, so you can still follow one host across its sessions. City and country come from an offline GeoIP database. The honeypot's own location is not shown. No narration and no typing sounds — instrumental music only. Made to sit on a second monitor: coding, studying, or ambience. 1 hour, 1920×1080, with sound. Music from Uppbeat: https://uppbeat.io/t/eversafe/spume — License code: VROTTK4WWOJGZUHS https://uppbeat.io/t/sky-cassette/the... — License code: WI6PTX9JPQPR26JF https://uppbeat.io/t/struktura/saturi... — License code: YLMBPYF09XHLIZAK https://uppbeat.io/t/adi-goldstein/bl... — License code: AHEPUNRFAKBBGUEK #honeypot #cowrie #sshhoneypot #cybersecurity #infosec #linux #sysadmin #busyworklabs #musiconly #ambient #focus #deepwork #studywithme #terminal #longform