GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    Ryan Castellucci :nonbinary_flag: (ryanc@infosec.exchange)'s status on Monday, 02-Sep-2024 06:48:03 JST Ryan Castellucci :nonbinary_flag: Ryan Castellucci :nonbinary_flag:

    Your SSH honeypot fakes a Linux system and logs the threat actor's commands.

    My SSH honeypot hijacks the threat actor's terminal to play the music video of Rick Astley's 1987 pop hit "Never Gonna Give You Up" while ignoring Ctrl-C.

    We are not the same.

    In conversation about 9 months ago from infosec.exchange permalink

    Attachments


    • mark repeated this.
    • Embed this notice
      Ryan Castellucci :nonbinary_flag: (ryanc@infosec.exchange)'s status on Monday, 02-Sep-2024 06:59:01 JST Ryan Castellucci :nonbinary_flag: Ryan Castellucci :nonbinary_flag:
      in reply to

      The CPU usage of this thing is absurd. Doesn't help that my files are encoded with "\n" newlines, but I need to use "\r\n" for an SSH pty for whatever reason.

      In conversation about 9 months ago permalink
    • Embed this notice
      Ryan Castellucci :nonbinary_flag: (ryanc@infosec.exchange)'s status on Monday, 02-Sep-2024 06:59:43 JST Ryan Castellucci :nonbinary_flag: Ryan Castellucci :nonbinary_flag:
      in reply to

      Also wondering if there's any way I can precompress the data...

      In conversation about 9 months ago permalink
    • Embed this notice
      Ryan Castellucci :nonbinary_flag: (ryanc@infosec.exchange)'s status on Monday, 02-Sep-2024 07:06:38 JST Ryan Castellucci :nonbinary_flag: Ryan Castellucci :nonbinary_flag:
      in reply to

      Oh, I didn't compile with --release. That'll do it. CPU usage reduced by 80% 😆

      In conversation about 9 months ago permalink
      Haelwenn /элвэн/ :triskell: likes this.
    • Embed this notice
      Rich Felker (dalias@hachyderm.io)'s status on Monday, 02-Sep-2024 07:56:29 JST Rich Felker Rich Felker
      in reply to

      @ryanc You should be able to set the newline conversion mode on the pty with stty/tcsetattr.

      In conversation about 9 months ago permalink
    • Embed this notice
      Ryan Castellucci :nonbinary_flag: (ryanc@infosec.exchange)'s status on Monday, 02-Sep-2024 07:56:29 JST Ryan Castellucci :nonbinary_flag: Ryan Castellucci :nonbinary_flag:
      in reply to
      • Rich Felker

      @dalias server side?

      In conversation about 9 months ago permalink
    • Embed this notice
      Wulfy (n_dimension@infosec.exchange)'s status on Monday, 02-Sep-2024 07:56:50 JST Wulfy Wulfy
      in reply to

      @ryanc

      Teach me Sensei!

      In conversation about 9 months ago permalink
    • Embed this notice
      Morten Linderud (foxboron@chaos.social)'s status on Monday, 02-Sep-2024 07:58:10 JST Morten Linderud Morten Linderud
      in reply to

      @ryanc

      This is funny. I wrote a SSH server that writes out the script to Hackers while ignoring Ctrl-C.

      In conversation about 9 months ago permalink
    • Embed this notice
      Ryan Castellucci :nonbinary_flag: (ryanc@infosec.exchange)'s status on Monday, 02-Sep-2024 07:58:55 JST Ryan Castellucci :nonbinary_flag: Ryan Castellucci :nonbinary_flag:
      in reply to
      • nex

      @nex windows terminal seems to have implemented DECPS... 🤔

      In conversation about 9 months ago permalink
    • Embed this notice
      nex (nex@fedi.transgender.ing)'s status on Monday, 02-Sep-2024 07:58:57 JST nex nex
      in reply to

      @ryanc@infosec.exchange SSH honeypot that hijacks the remote terminal to play the portal 1 ending, with music

      In conversation about 9 months ago permalink
    • Embed this notice
      SpaceLifeForm (spacelifeform@infosec.exchange)'s status on Monday, 02-Sep-2024 09:34:03 JST SpaceLifeForm SpaceLifeForm
      in reply to

      @ryanc

      Bonus points if you can make them hear the music thru the PC Speaker.

      In conversation about 9 months ago permalink
    • Embed this notice
      Dr David Mills (dtl@mastodon.social)'s status on Monday, 02-Sep-2024 16:26:15 JST Dr David Mills Dr David Mills
      in reply to
      • Morten Linderud
      • viq

      @viq @Foxboron @ryanc and a terminal beep after each character?

      In conversation about 9 months ago permalink
    • Embed this notice
      Ryan Castellucci :nonbinary_flag: (ryanc@infosec.exchange)'s status on Monday, 02-Sep-2024 16:26:15 JST Ryan Castellucci :nonbinary_flag: Ryan Castellucci :nonbinary_flag:
      in reply to
      • Morten Linderud
      • viq
      • Dr David Mills

      @Dtl @viq @Foxboron G

      In conversation about 9 months ago permalink
    • Embed this notice
      viq (viq@social.hackerspace.pl)'s status on Monday, 02-Sep-2024 16:26:17 JST viq viq
      in reply to
      • Morten Linderud

      @Foxboron @ryanc one character per second?

      In conversation about 9 months ago permalink
    • Embed this notice
      Ryan Castellucci :nonbinary_flag: (ryanc@infosec.exchange)'s status on Monday, 02-Sep-2024 16:30:15 JST Ryan Castellucci :nonbinary_flag: Ryan Castellucci :nonbinary_flag:
      in reply to
      • Bee O'Problem :godot:

      @beeoproblem actually, I know how to do that

      In conversation about 9 months ago permalink
    • Embed this notice
      Bee O'Problem :godot: (beeoproblem@mastodon.gamedev.place)'s status on Monday, 02-Sep-2024 16:30:16 JST Bee O'Problem :godot: Bee O'Problem :godot:
      in reply to

      @ryanc I now lowkey wish RickrollMEMZ was a thing

      Hijack the machine to display the video (and crash the system once the video is over) and also trash the BIOS to show the Rick Astley on boot.

      In conversation about 9 months ago permalink
    • Embed this notice
      Ryan Castellucci :nonbinary_flag: (ryanc@infosec.exchange)'s status on Monday, 02-Sep-2024 16:40:05 JST Ryan Castellucci :nonbinary_flag: Ryan Castellucci :nonbinary_flag:
      in reply to
      • unexpectedteapot

      @unexpectedteapot I'll post it eventually, but probably not the animation file (it's 50MB)

      I basically mashed this together with russh:

      https://github.com/ryancdotorg/ansi-player-rs/blob/main/src/main.rs

      You can see the animation via

      nc rya.nc 1987

      In conversation about 9 months ago permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: rya.nc
        Ryan Castellucci’s blog | rya.nc
        Ryan Castellucci’s blog - posts on computer security, programming, systems administration, electronics and general geekery
    • Embed this notice
      unexpectedteapot (unexpectedteapot@social.linux.pizza)'s status on Monday, 02-Sep-2024 16:40:07 JST unexpectedteapot unexpectedteapot
      in reply to

      @ryanc so since no one asked, I'll volunteer: do you have this software hosted on a gitsomething somewhere?

      In conversation about 9 months ago permalink
    • Embed this notice
      Ryan Castellucci :nonbinary_flag: (ryanc@infosec.exchange)'s status on Monday, 02-Sep-2024 16:43:29 JST Ryan Castellucci :nonbinary_flag: Ryan Castellucci :nonbinary_flag:
      in reply to
      • Joacim Jacobsson

      @jjacobsson I got it working last night, shitposted about it and went to bed.

      Will post the code in the next couple of weeks.

      I don't use container stuff, and it's Rust so you can just compile it to a single binary anyway.

      In conversation about 9 months ago permalink
    • Embed this notice
      Joacim Jacobsson (jjacobsson@mastodon.gamedev.place)'s status on Monday, 02-Sep-2024 16:43:30 JST Joacim Jacobsson Joacim Jacobsson
      in reply to

      @ryanc where can I get a container of this for arm please?

      In conversation about 9 months ago permalink
    • Embed this notice
      Ryan Castellucci :nonbinary_flag: (ryanc@infosec.exchange)'s status on Monday, 02-Sep-2024 16:48:52 JST Ryan Castellucci :nonbinary_flag: Ryan Castellucci :nonbinary_flag:
      in reply to
      • Joacim Jacobsson

      @jjacobsson the video itself viewable via

      nc rya.nc 1987

      No sound, but the whole thing is subtitled.

      In conversation about 9 months ago permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: rya.nc
        Ryan Castellucci’s blog | rya.nc
        Ryan Castellucci’s blog - posts on computer security, programming, systems administration, electronics and general geekery
    • Embed this notice
      Joacim Jacobsson (jjacobsson@mastodon.gamedev.place)'s status on Monday, 02-Sep-2024 16:48:53 JST Joacim Jacobsson Joacim Jacobsson
      in reply to

      @ryanc _nice_

      Having exactly 0 experience with running a honeypot so I did some googling and realized that is more complicated than I initially thought :D

      But I need to see this.

      In conversation about 9 months ago permalink
    • Embed this notice
      Ryan Castellucci :nonbinary_flag: (ryanc@infosec.exchange)'s status on Monday, 02-Sep-2024 16:49:41 JST Ryan Castellucci :nonbinary_flag: Ryan Castellucci :nonbinary_flag:
      in reply to
      • Morten Linderud
      • viq
      • Dr David Mills

      @Foxboron @Dtl @viq I can encode arbitrary movies the same way 🤔

      In conversation about 9 months ago permalink
    • Embed this notice
      Morten Linderud (foxboron@chaos.social)'s status on Monday, 02-Sep-2024 16:49:42 JST Morten Linderud Morten Linderud
      in reply to
      • viq
      • Dr David Mills

      @Dtl @viq @ryanc

      Love it. Totes doing that.

      https://github.com/Foxboron/ssh-the-planet

      In conversation about 9 months ago permalink
    • Embed this notice
      Ryan Castellucci :nonbinary_flag: (ryanc@infosec.exchange)'s status on Monday, 02-Sep-2024 18:00:01 JST Ryan Castellucci :nonbinary_flag: Ryan Castellucci :nonbinary_flag:
      in reply to
      • Morten Linderud
      • viq
      • Dr David Mills

      @Foxboron @Dtl @viq I'm extracting individual frames as low quality jpg (quality really doesn't matter here, lol) and then converting individual frames to ANSI.

      https://infosec.exchange/@ryanc/113039048229129925

      In conversation about 9 months ago permalink
    • Embed this notice
      Morten Linderud (foxboron@chaos.social)'s status on Monday, 02-Sep-2024 18:00:03 JST Morten Linderud Morten Linderud
      in reply to
      • viq
      • Dr David Mills

      @ryanc @Dtl @viq

      I tried getting ffmpeg to output Hackers through caca but it wasn't super easy as you need to render each frame from the nurses driver.

      In conversation about 9 months ago permalink
    • Embed this notice
      Ryan Castellucci :nonbinary_flag: (ryanc@infosec.exchange)'s status on Monday, 02-Sep-2024 18:01:30 JST Ryan Castellucci :nonbinary_flag: Ryan Castellucci :nonbinary_flag:
      in reply to
      • Joacim Jacobsson

      @jjacobsson It's pretty amazing how good it looks when you spam the terminal with unicode and 24 bit color escape sequences

      In conversation about 9 months ago permalink
    • Embed this notice
      Joacim Jacobsson (jjacobsson@mastodon.gamedev.place)'s status on Monday, 02-Sep-2024 18:01:31 JST Joacim Jacobsson Joacim Jacobsson
      in reply to

      @ryanc That is _amazing_

      In conversation about 9 months ago permalink
    • Embed this notice
      Ryan Castellucci :nonbinary_flag: (ryanc@infosec.exchange)'s status on Tuesday, 03-Sep-2024 01:56:44 JST Ryan Castellucci :nonbinary_flag: Ryan Castellucci :nonbinary_flag:
      in reply to
      • Morten Linderud
      • viq
      • Mathias Panzenböck
      • Dr David Mills

      @bloody_albatross @Foxboron @Dtl @viq the frame encoder (which I did not write, but plan to replace with my own to be written encoder) picks from one of 32 possible characters and two colors for each cell.

      In conversation about 9 months ago permalink
    • Embed this notice
      Mathias Panzenböck (bloody_albatross@chaos.social)'s status on Tuesday, 03-Sep-2024 01:56:45 JST Mathias Panzenböck Mathias Panzenböck
      in reply to
      • Morten Linderud
      • viq
      • Dr David Mills

      @ryanc @Foxboron @Dtl @viq Very cool! Did something similar myself a few months ago. (Also in Rust.) I always render 2 pixels per character and only support images, including animated GIFs. You seem to do more than one pixel per character, but quatize them to two colors?

      In conversation about 9 months ago permalink
    • Embed this notice
      Ryan Castellucci :nonbinary_flag: (ryanc@infosec.exchange)'s status on Tuesday, 03-Sep-2024 04:23:37 JST Ryan Castellucci :nonbinary_flag: Ryan Castellucci :nonbinary_flag:
      in reply to
      • Morten Linderud
      • viq
      • Mathias Panzenböck
      • Dr David Mills

      @bloody_albatross @Foxboron @Dtl @viq

      This is what I'm currently using to encode frames:

      https://github.com/daleroberts/tv

      In conversation about 9 months ago permalink
    • Embed this notice
      Mathias Panzenböck (bloody_albatross@chaos.social)'s status on Tuesday, 03-Sep-2024 04:23:39 JST Mathias Panzenböck Mathias Panzenböck
      in reply to
      • Morten Linderud
      • viq
      • Dr David Mills

      @ryanc @Foxboron @Dtl @viq That's cool! 32? What characters do you use? I know characters that would yield 4 (1x2 pixels per character), 64 (2x3), and 256 (2x4) different values. Though not all of those Unicode characters are well supported everywhere. I went with 1x2 because it's easy and no color compromise. Though low resolution.

      In conversation about 9 months ago permalink
    • Embed this notice
      Ryan Castellucci :nonbinary_flag: (ryanc@infosec.exchange)'s status on Tuesday, 03-Sep-2024 04:25:27 JST Ryan Castellucci :nonbinary_flag: Ryan Castellucci :nonbinary_flag:
      in reply to
      • Morten Linderud
      • viq
      • Mathias Panzenböck
      • Dr David Mills

      @bloody_albatross @Foxboron @Dtl @viq

      I would call it roughly an effective resolution of four to eight "pixels" per character.

      In conversation about 9 months ago permalink
    • Embed this notice
      Ryan Castellucci :nonbinary_flag: (ryanc@infosec.exchange)'s status on Tuesday, 03-Sep-2024 05:04:34 JST Ryan Castellucci :nonbinary_flag: Ryan Castellucci :nonbinary_flag:
      in reply to
      • Legion495

      @Legion495 wise

      In conversation about 9 months ago permalink
    • Embed this notice
      Legion495 (legion495@mk.absturztau.be)'s status on Tuesday, 03-Sep-2024 05:04:35 JST Legion495 Legion495
      in reply to

      @ryanc@infosec.exchange I am afraid

      In conversation about 9 months ago permalink
    • Embed this notice
      Tim Clevenger :donor: (timjclevenger@infosec.exchange)'s status on Tuesday, 03-Sep-2024 10:15:04 JST Tim Clevenger :donor: Tim Clevenger :donor:
      in reply to

      @ryanc That's amazing.

      In conversation about 9 months ago permalink
    • Embed this notice
      Ryan Castellucci :nonbinary_flag: (ryanc@infosec.exchange)'s status on Wednesday, 04-Sep-2024 03:55:10 JST Ryan Castellucci :nonbinary_flag: Ryan Castellucci :nonbinary_flag:
      in reply to
      • Ilya Shasham

      @IlyaShasham I'm building a custom ssh server with a built in animation player for this purpose. I have it working, but I want to clean it up before posting.

      In conversation about 9 months ago permalink
    • Embed this notice
      Ilya Shasham (ilyashasham@hachyderm.io)'s status on Wednesday, 04-Sep-2024 03:55:11 JST Ilya Shasham Ilya Shasham
      in reply to

      @ryanc is it possible to learn this power?

      In conversation about 9 months ago permalink
    • Embed this notice
      Ilya Shasham (ilyashasham@hachyderm.io)'s status on Wednesday, 04-Sep-2024 04:10:43 JST Ilya Shasham Ilya Shasham
      in reply to

      @ryanc best of luck to you, mate. Sounds quite interesting.

      In conversation about 9 months ago permalink
    • Embed this notice
      Ryan Castellucci :nonbinary_flag: (ryanc@infosec.exchange)'s status on Wednesday, 04-Sep-2024 04:10:43 JST Ryan Castellucci :nonbinary_flag: Ryan Castellucci :nonbinary_flag:
      in reply to
      • Ilya Shasham

      @IlyaShasham if you just want to see what gets played, run

      nc rya.nc 1987

      in a vaguely recent terminal emulator.

      In conversation about 9 months ago permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: rya.nc
        Ryan Castellucci’s blog | rya.nc
        Ryan Castellucci’s blog - posts on computer security, programming, systems administration, electronics and general geekery

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.