Honeypot on the boykisser forum
4 points by FedericoSchonborn
4 points by FedericoSchonborn
all these IP seems to come from third-world countries. But there are some that are coming from normal countries
bruh
When I read that I immediately checked if the author was dutch and sure enough. I'm dutch and it's weird habit lots of dutch people have to consider their own culture the baseline. 'Normaal' / 'Doe 'normaal' (be/act normal) is used a lot.
I think it is a bit of a language quirk but I also think its a pretty bad habit. Usually when you point it out they realize how insane it sounds. I don't think it sounds much better in Dutch fwiw
I'm choosing to interpret this as just exceptionally poor wording ("normal" as in "the usual suspects") but yeah this immediately gave the post bad vibes
i even observed a request from Germany
(like addison I assume this was just unintentionally awkward but yeah..)
Based on the impenetrable text, I am going to assume English is not the author’s first language.
Worth noting it is corrected now, with this somewhat funny addition in the notes:
Sorry third world countries… And germany
unskippable title
I've noticed similar traffic to my servers in the past few days coinciding with severe degradation of availability unless mitigated with firewall blocks. I also found the honeypot route effective for deciding whether to ban an IP. In my case I just used an uninteresting cgit repository as a trap.
Your uninteresting cgit repository post is paradoxically quite interesting. Even though I have taken measures against OpenAI and Anthropic crawlers, I occasionally see them asking for URLs they could not have know about directly, due to measures. I assumed they were picking these up indirectly from RSS aggregators. Finding new web sites through CA issuance logs is an interesting method (derogatory). I wonder if OpenAI/Anthropic are getting newly registered domain names from DNS providers? I bet there are some other grey-area methods of finding new domains and URLs that I just won't be able to think of.
Speaking from experience, one could be passive DNS resolution data from e.g., DomainTools, but I have no idea if the companies you named do that
I usually get hit by various kinds of bots and scrapers as little as a minute after I get a cert issued for a domain, plenty of actors monitor them.
This is also why you shouldn't include the name of whatever software you're exposing in a subdomain, one of the honeypots on one of my domains get a lot of exploits tailored for WordPress because they just find all domains with "wordpress" in the domain.