GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    Viss (viss@mastodon.social)'s status on Thursday, 17-Jul-2025 06:20:00 JST Viss Viss

    if you put a webserver up on the internet. anywhere, hosting anything, you will see "the background radiation of the internet", and it looks like this:

    In conversation about 11 months ago from mastodon.social permalink

    Attachments


    1. https://files.mastodon.social/media_attachments/files/114/864/117/136/030/697/original/89c705122b24e5f9.png
    • Haelwenn /элвэн/ :triskell: and narcolepsy and alcoholism :flag: like this.
    • Embed this notice
      :blobcathug: (jain@blob.cat)'s status on Thursday, 17-Jul-2025 06:30:48 JST :blobcathug: :blobcathug:
      in reply to
      • Paul_IPv6
      • Sheldon
      @sysop408 @paul_ipv6 @Viss :blobcatthinkOwO: maybe i should start serving gzip bomb responses as those files :blobcathyper2:
      In conversation about 11 months ago permalink
    • Embed this notice
      Paul_IPv6 (paul_ipv6@infosec.exchange)'s status on Thursday, 17-Jul-2025 06:30:49 JST Paul_IPv6 Paul_IPv6
      in reply to
      • Sheldon

      @Viss @sysop408

      indeed. went from 1500+ attempts from a unique IP to maybe 15 in a week?

      In conversation about 11 months ago permalink
    • Embed this notice
      Sheldon (sysop408@sfba.social)'s status on Thursday, 17-Jul-2025 06:30:49 JST Sheldon Sheldon
      in reply to
      • Paul_IPv6

      @paul_ipv6 @Viss yes, thank goodness for fail2ban and CSF firewall.

      In conversation about 11 months ago permalink
    • Embed this notice
      Sheldon (sysop408@sfba.social)'s status on Thursday, 17-Jul-2025 06:30:50 JST Sheldon Sheldon
      in reply to
      • Paul_IPv6

      @paul_ipv6 that status message when you login to your root account letting you know there have been 2817 failed login attempts since the last time you signed in is absolutely lit!

      @Viss

      In conversation about 11 months ago permalink
    • Embed this notice
      Viss (viss@mastodon.social)'s status on Thursday, 17-Jul-2025 06:30:50 JST Viss Viss
      in reply to
      • Paul_IPv6
      • Sheldon

      @sysop408 @paul_ipv6 fail2ban!

      In conversation about 11 months ago permalink
    • Embed this notice
      Paul_IPv6 (paul_ipv6@infosec.exchange)'s status on Thursday, 17-Jul-2025 06:30:51 JST Paul_IPv6 Paul_IPv6
      in reply to

      @Viss

      yeah. if you ever want to be convinced that the internet is doomed, just put up your own email or web server and actually read the logs... ;)

      In conversation about 11 months ago permalink
    • Embed this notice
      Viss (viss@mastodon.social)'s status on Thursday, 17-Jul-2025 06:46:52 JST Viss Viss
      in reply to

      and if youre lucky, sometimetimes you catch one that may be actually interesting, possibly being used by an active malicious actor / campaign

      "GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application HTTP/1.1"

      never seen that one before, but I bet its working for SOMEONE out there

      In conversation about 11 months ago permalink
      Haelwenn /элвэн/ :triskell: likes this.
    • Embed this notice
      Viss (viss@mastodon.social)'s status on Thursday, 17-Jul-2025 06:46:53 JST Viss Viss
      in reply to

      and what you can take away from this log is that the reason they are blasting the entire internet, every webserver with these requests - most of which are 'im gonna hit myself in the face with a brick now' level of bad from a config/dev/admin perspective - is squarely because it has worked for them enough times that they feel spraying the internet will nab them more.

      look.
      just look at the shit they're collecting and how easily theyre doing it.

      this is because docker
      this is because k8s

      In conversation about 11 months ago permalink
    • Embed this notice
      Viss (viss@mastodon.social)'s status on Thursday, 17-Jul-2025 06:46:53 JST Viss Viss
      in reply to

      this is because everywhere has gone "DX" - or "optimizing for the developer experience above all else, at the cost of everyone else. "

      make things as easy as possible for the devs/devops, we dont care how bad the security becomes, how many layers of abstraction get installed, how many dozen new js frameworks appear this afternoon, how public the data is, how bad the architecture is - burn the building down

      just make sure the devs are comfy

      In conversation about 11 months ago permalink
    • Embed this notice
      Dr. Matt Lee (1800www.com) (mattl@social.coop)'s status on Thursday, 17-Jul-2025 07:16:38 JST Dr.  Matt Lee (1800www.com) Dr. Matt Lee (1800www.com)
      in reply to
      • Jack William Bell

      @jackwilliambell @Viss Nobody should redirect their 404s from weird user agents or bots looking for the WordPress login page to a 10gb file such as https://sin-speed.hetzner.com/10GB.bin

      In conversation about 11 months ago permalink

      Attachments


    • Embed this notice
      Jack William Bell (jackwilliambell@rustedneuron.com)'s status on Thursday, 17-Jul-2025 07:16:42 JST Jack William Bell Jack William Bell
      in reply to

      @Viss

      Is it possible to respond to every URN not referring to an actual reachable resource on the site with a zip bomb?

      I mean, it should be possible, but IDK.

      In conversation about 11 months ago permalink
    • Embed this notice
      Viss (viss@mastodon.social)'s status on Thursday, 17-Jul-2025 07:17:29 JST Viss Viss
      in reply to
      • Fritz Adalis

      @FritzAdalis no good comes from that ip

      In conversation about 11 months ago permalink
    • Embed this notice
      Dr. Matt Lee (1800www.com) (mattl@social.coop)'s status on Thursday, 17-Jul-2025 07:17:29 JST Dr.  Matt Lee (1800www.com) Dr. Matt Lee (1800www.com)
      in reply to
      • Fritz Adalis

      @Viss @FritzAdalis I know a guy with that IP address. Just downloads a bunch of shit all day.

      In conversation about 11 months ago permalink
    • Embed this notice
      Fritz Adalis (fritzadalis@infosec.exchange)'s status on Thursday, 17-Jul-2025 07:17:30 JST Fritz Adalis Fritz Adalis
      in reply to

      @Viss
      You should probably block that 127.0.0.1 address.

      In conversation about 11 months ago permalink
    • Embed this notice
      Dr. Matt Lee (1800www.com) (mattl@social.coop)'s status on Thursday, 17-Jul-2025 12:14:42 JST Dr.  Matt Lee (1800www.com) Dr. Matt Lee (1800www.com)
      in reply to
      • Scott Williams 🐧
      • Fritz Adalis

      @vwbusguy @Viss @FritzAdalis I think he must live near me. I keep finding him logging into my computers too, yet they're not public facing.

      In conversation about 11 months ago permalink
    • Embed this notice
      Scott Williams 🐧 (vwbusguy@mastodon.online)'s status on Thursday, 17-Jul-2025 12:14:43 JST Scott Williams 🐧 Scott Williams 🐧
      in reply to
      • Fritz Adalis
      • Dr. Matt Lee (1800www.com)

      @mattl @Viss @FritzAdalis That's the address of the guy that keeps logging into my machines!

      In conversation about 11 months ago permalink
    • Embed this notice
      Dr. Matt Lee (1800www.com) (mattl@social.coop)'s status on Friday, 18-Jul-2025 00:46:43 JST Dr.  Matt Lee (1800www.com) Dr. Matt Lee (1800www.com)
      in reply to
      • Jack William Bell
      • Ian Campbell
      • cR0w
      • Silverstar

      @Silverstar @Viss @jackwilliambell @cR0w @neurovagrant I suspect some will and some won’t. Some might just crash.

      In conversation about 11 months ago permalink
    • Embed this notice
      Viss (viss@mastodon.social)'s status on Friday, 18-Jul-2025 00:46:49 JST Viss Viss
      in reply to
      • Jack William Bell
      • Ian Campbell
      • Dr. Matt Lee (1800www.com)
      • cR0w

      @jackwilliambell @mattl oh, @cR0w and @neurovagrant have some fun here, with a zip that uncompresses to .. some tens of gigs? or hundreds of gigs?

      In conversation about 11 months ago permalink
    • Embed this notice
      Silverstar (silverstar@cyberplace.social)'s status on Friday, 18-Jul-2025 00:46:49 JST Silverstar Silverstar
      in reply to
      • Jack William Bell
      • Ian Campbell
      • Dr. Matt Lee (1800www.com)
      • cR0w

      @Viss @jackwilliambell @mattl @cR0w @neurovagrant would the bots actually download large files or stop because they expect small files?

      In conversation about 11 months ago permalink
    • Embed this notice
      Jack William Bell (jackwilliambell@rustedneuron.com)'s status on Friday, 18-Jul-2025 00:46:50 JST Jack William Bell Jack William Bell
      in reply to
      • Dr. Matt Lee (1800www.com)

      @mattl @Viss

      Yeah. I guess that would be bad.

      In conversation about 11 months ago permalink

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.