Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
Giving the bots what they want
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index Other Things Gentoo
View previous topic :: View next topic  
Author Message
joanandk
Apprentice
Apprentice


Joined: 12 Feb 2017
Posts: 169

PostPosted: Fri Aug 12, 2022 9:33 am    Post subject: Giving the bots what they want Reply with quote

Hi,

On my webserver I see attempts from bots to execute either wp-login.php or bin/sh. I know there is fail2ban which I could set up, but I want to give the poor bots what they want.

Question: Is it wise to create a .htaccess to rewrite anything to direct to randomize.php which then creates a stream of random characters. If the bot is poorly programmed, this could fill up their log and crash their machine after a while.

BR
PS: I have not hatred for bots, I find it funny if the aggressor gets some medicine of his own.
Back to top
View user's profile Send private message
pietinger
Moderator
Moderator


Joined: 17 Oct 2006
Posts: 4148
Location: Bavaria

PostPosted: Fri Aug 12, 2022 10:45 am    Post subject: Reply with quote

Maybe you are interested in Honeypots. See more here: https://linuxsecurity.expert/security-tools/honeypots
Back to top
View user's profile Send private message
pietinger
Moderator
Moderator


Joined: 17 Oct 2006
Posts: 4148
Location: Bavaria

PostPosted: Fri Aug 12, 2022 10:47 am    Post subject: Reply with quote

Moved from Portage & Programming to Other Things Gentoo.
Back to top
View user's profile Send private message
Hu
Moderator
Moderator


Joined: 06 Mar 2007
Posts: 21628

PostPosted: Fri Aug 12, 2022 3:08 pm    Post subject: Re: Giving the bots what they want Reply with quote

joanandk wrote:
Question: Is it wise to create a .htaccess to rewrite anything to direct to randomize.php which then creates a stream of random characters. If the bot is poorly programmed, this could fill up their log and crash their machine after a while.
I would not do this. I expect at least some of the attackers can spare more bandwidth than you can, so this would be a bigger drain on your server than the pain you can inflict on them, even if they fall for the trap.
Back to top
View user's profile Send private message
mrbassie
l33t
l33t


Joined: 31 May 2013
Posts: 772
Location: over here

PostPosted: Sat Aug 20, 2022 5:10 pm    Post subject: Re: Giving the bots what they want Reply with quote

joanandk wrote:
Hi,

I know there is fail2ban which I could set up, but I want to give the poor bots what they want.


net-misc/endlessh maybe
Back to top
View user's profile Send private message
Zucca
Moderator
Moderator


Joined: 14 Jun 2007
Posts: 3343
Location: Rasi, Finland

PostPosted: Sat Aug 20, 2022 6:49 pm    Post subject: Reply with quote

Oh boy.
cowrie sounds so tempting.
_________________
..: Zucca :..
Gentoo IRC channels reside on Libera.Chat.
--
Quote:
I am NaN! I am a man!
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index Other Things Gentoo All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum