Still a #centralized, #SingleVendor & #SingleProvider service that snitches on users if it ain't yet another #Honeypot like #ANØM...
Still a #centralized, #SingleVendor & #SingleProvider service that snitches on users if it ain't yet another #Honeypot like #ANØM...
Give it a rest, person in Romania who really wants to use my #honeypot to make VoIP phone calls!
That's one hell of a WHOPPER
#nsfw #spreadlegs #pov #nude #selfie #girlsjustwannahavefun #tease #hotasfuck #daddylikes #aycaramba #sweetnspicy #sexy #naughty #erotic #horny #yummy #ebony #princess #babe #fuckdoll #thatface #openthatmouth #wifeymaterial #perky #pierced #nipples #tits #pink #pussy #burgers #nectar #honeypot
Sasha’s Step 2: Now With Extra Chaos
So, you built a #honeypot. You watched a few bots faceplant into your fake SSH server. You got a taste of deception and now you're craving MORE.
Let me introduce you to your next obsession: ADHD (Active Defense Harbinger Distribution) from the fine humans at Black Hills InfoSec.
It’s a full Linux distro pre-loaded with tools for:
Honeypots
Honeytokens
Tarpits
Credential bait
And general attacker frustration
ADHD is like a honeypot buffet—with all the weird sauces already installed. Want to frustrate attackers with Endless SSH? Drop them in a Maze. Want to play with Kippo, Glastopf, or Artillery without building from scratch? ADHD says, “Come on in, the traps are fine.”
BUT LISTEN: This is not something you drop on your public-facing VPS or neighbor’s Comcast router. This is #homelab territory only. Sandboxed. Segmented. Safe. (Or Sasha will give you The Look™.)
Download it here: https://www.blackhillsinfosec.com/tools/adhd/
Flap wisely, my friends.
#Honeypots #CyberDeception #SashaTheDancingFlamingo #InfosecFun @rnbwkat
@kibcol1049 This is funny because I work in #cybersecurity. The term #honeypot has a totally different meaning for us.
We set up systems we call honeypots to lure in malicious hackers. They look vulnerable, they look like they have juicy data on them. But they actually are not really used for anything but lures. Anything connecting to that system is automatically suspicious because the system serves no other purpose. We are hoping that bad guys try to attack the honeypot so we can identify them; figure out what methods they’re using, and protect ourselves from them.
So the idea of a honeypot being something innocent and good (just popular) is the opposite of how I usually use that word.
2025-03-28 RDP #Honeypot IOCs - 181569 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSec
Top IPs:
138.199.24.6 - 91545
156.146.57.110 - 42849
156.146.57.52 - 10716
Top ASNs:
AS60068 - 93561
AS212238 - 64269
AS135161 - 10653
Top Accounts:
hello - 181455
Test - 33
eltons - 15
Top ISPs:
DataCamp Limited - 93561
Datacamp Limited - 64269
GMO-Z.COM PTE. LTD. - 10653
Top Clients:
Unknown - 181569
Top Software:
Unknown - 181569
Top Keyboards:
Unknown - 181569
Top IP Classification:
hosting & proxy - 160374
hosting - 10710
Unknown - 10440
Pastebin links with full 24-hr RDP Honeypot IOC Lists:
https://pastebin.com/BiF6s8Jh
@signalapp It's not #disinfo when one points out that you demand #PII aka. #PhoneNumbers from Users and that is literally a architectural vulnerability, alongside your #proprietary & #Centralized #Infrastructure.
Not to mention the lack of @torproject / #Tor support with an #OnionService or the willingness to fulfill #cyberfacist "Embargoes" or shilling a #Shitcoin #Scam named #MobileCoin!
And don't get me started on the #cyberfacism that is #CloudAct.
I may nit have allvthe.evidence yet, but #Signal stenches like #ANØM: #Honeypot-esque!
@alwayscurious @froge @fj #CloudAct alone not, but it's just the tip of the iceberg.
Again: The only #security is #decentralization!
#Signal is as vulnerable as #EncroChat if it's not a #Honeypot like #ANØM!
@licho @osman provide evidence the code @signalapp released is actually being deployed.
git
and builds it from source.Not to mention pushing a #Shitcoin-#Scam (#MobileCoin) disqualifies #Signal per very design!
https://www.youtube.com/watch?v=tJoO2uWrX1M
And don't even get me started on the fact.it's not sustainable to run it as a #VCmoneyBurningParty!
Same as identifying users: They already got a #PhoneNumber which in many juristictions one can't even obtain without #ID legally, thus making it super easy to i.e. find and locate a user. Even tze cheapest LEAs can force their local M(V)NOs to #SS7 a specific number...
Again: Signal has a #Honeypot stench, and you better learn proper #E2EE, #SelfCustody and #TechLiteracy because corporations can't pull the 5th [Amendment] on your behalf!
@osman If your #OpSec, #InfoSec, #ComSec and/or #ITsec relies on @signalapp and/or @Mer__edith risking jail or worse, you fucked up!
Seriously, to me #Signal stenches #Honeypot like #ANØM & #CryptoAG.
That's why I get people setup with it!
@ip6li @heiseonline @briar und natürlich #XMPP+#OMEMO sowie #PGP/MIME.
IMHO ist @signalapp eh nen #Honeypot!
It's just crazy how phpmyadmin mass exploitation remains popular (read: effective) to this day. The only developments I have seen in these exploit attempt is that the list of locations that are checked for phpmyadmin installations gets longer and more creative.
Other than that: pretty boring stuff
@abschleppgruppe@verkehrswende.social @abschleppgruppe@bird.makeup @bacwberlin Der weiße Pferdecontainer wurde ja gestern auf meine Aufforderung an die Truppen der 110 kostenpflichtig um 5 Meter aus dem Kreuzungsbereich nach links versetzt - um dem nächsten PKW Platz zu machen, dessen Besitzy auch gerne mal die Konsequenzen der #Wochendbrigade der @abschleppgruppe@verkehrswende.social am eigenen Geldbeutel erleben wollte ... 110 anruf, VBH- Meldung #honeypot Regensburger @falschparkenber
@truls46 Ein gutes Gegenbeispiel zu @signalapp ist @monocles / #monoclesChat:
Es werden keine persönliche Daten verlangt!
Es wird ein offener Standard (#XMPP+#OMEMO) genutzt, sodass #SelfCustody und #Datenhoheit gewährleistet ist!
Der Dienst ist zwar kostenpflichtig (€2 p.m.), aber komplett anonym bezahlbar (inkl. #Monero & #CashByMail)!
Nutzung von @torproject #Tor wird nicht verhindert oder blockiert; @guardianproject / #Orbot wird unterstützt!
In #Deutschland gibt's immernoch #Rechtsstaatlichkeit, anders als in den #USA!
Anders als #Signal ist #monocles ehrlich, was Sicherheit und Datenschutz angeht...
Ich denke mal das sollte hinreichend meine Argumebte darlegen.
@streetcoder @inaruck @monocles ich weiß nur #XMPP+#OMEMO ist battle-tested und soweit grundsolide.
@signalapp ist bestenfalls von gemeingefählrich-inkompetenten Menschen betrieben wenn nicht sogar nen #Honeypot!