131
submitted 3 weeks ago* (last edited 3 weeks ago) by exu@feditown.com to c/technology@lemmy.world

Edit: The post was probably heavily AI written and contains mistakes to that effect, which is unfortunate. The data in general is still interesting though.

all 33 comments
sorted by: hot top new old
[-] Retro_unlimited@lemmy.world 87 points 3 weeks ago

If they used AI, then I consider they lost all credibility.

[-] sircac@lemmy.world 19 points 3 weeks ago* (last edited 3 weeks ago)

For me it is not only that they used AI for the writing, is that they did not care to review/recheck/polishing it before releasing it to the public, so my effort in consuming it will be reciprocal

[-] KatherinaReichelt@feddit.org 2 points 3 weeks ago* (last edited 3 weeks ago)

I really struggle to see the point of posts like this. It is an interesting article about an interesting topic.

[-] Glitchvid@lemmy.world 28 points 3 weeks ago

The Belgian traffic? Almost entirely from a single residential IP — one box that sent over 156,000 login attempts, more than the entire country of Germany. It just sat there, hammering echo "\x6F\x6B" over and over, every single second, for weeks. Relentless.

Had a funny similar thing, there's some weird person/people that randomly probe and attack a specific game's community hosted dedicated servers; and one week this specific IP address out of Virginia was just hammering one of mine, with what amounts to a specific byte sequence, then an incrementing number of the packet (until it wrapped around). Then it stopped. Weird shit.

[-] frongt@lemmy.zip 5 points 3 weeks ago

It's possible it was something misconfigured, a poorly-written script, or a bug in some software causing unexpected behavior. At the scale of the Internet, all of those are very possible.

It could also be the Internet equivalent of a numbers station.

[-] Glitchvid@lemmy.world 3 points 3 weeks ago

It's was a pretty specific non standard port on UDP. It's not even doing proper scanning since the byte sequence used isn't one that would trigger a response challenge/ack. My guess is someone trying to DOS using an older byte sequence that used to choke/kill the server software on older versions.

[-] XLE@piefed.social 23 points 3 weeks ago

Thanks for the warning OP

[-] sommerset 10 points 3 weeks ago

Honeypot as a Python script in a docker container?
Isn't that not really a true isolation?

[-] baller_w@lemmy.zip 6 points 3 weeks ago

Please say more.

I use both on a daily basis and from what I understand, there’s no implicit access from within a container. If you set it up right, there’s no access outside the container of any sort unless you explicitly say so.

[-] trolololol@lemmy.world 11 points 3 weeks ago

Unless the container had a bug that they know but you don't know.

[-] Valmond@lemmy.dbzer0.com 2 points 3 weeks ago

Yeah the system isn't protecting you (like it does preventing a normal user accessing another user), "only" the docker code does.

Or so I have understood it.

[-] mal3oon@lemmy.world 3 points 3 weeks ago

endlessh + fail2ban

[-] null@lemmy.zip 9 points 3 weeks ago

I'm kind of disappointed that bigboobz wasn't on the top of the password list.

[-] kratoz29@lemmy.zip 7 points 3 weeks ago

and contains mistakes to that effect

What mistakes?

[-] AbidanYre@lemmy.world 16 points 3 weeks ago* (last edited 3 weeks ago)

At one point it said only 28 IPs came back and those 31 were clever. Or something to that effect.

[-] magnue@lemmy.world 6 points 3 weeks ago

Weird I did the exact same thing on a VPS. Basically the same data.

[-] vinyl@lemmy.world 4 points 3 weeks ago

tf is a web scraper engineer, gen ai?

[-] uenticx@lemmy.world 3 points 3 weeks ago* (last edited 3 weeks ago)

A professional web scraper and data extraction expert ...

Looks like he's a tool ... maybe sed/awk?

[-] muusemuuse@sh.itjust.works 4 points 3 weeks ago

Years ago I had a synology NAS that was sleeping itself to death. Support told me open up port 22 and forward the port to the open internet. They would get to and poke around. I told them it was a terrible idea, can I at least set a password?

No. But you can set up ip autoban.

I no longer use synology. I gave it away.

[-] phoenixz@lemmy.ca 3 points 3 weeks ago

So is there a socket container for this? Wi wouldn't mind wasting some hacker assholes time with this

[-] sakphul@discuss.tchncs.de -1 points 3 weeks ago

That was an interesting read. I didn't have a lot If knowledge about this topic. So thanks for that!

Was ist using AI for assisted writing? Maybe. But I don't have a Problem with that. I assume everyone ist using it to some extend (me included) and uses it as a tool as any other tool.

The Data is the actual interesting Thing. Would be cool If the author could share his data (of course IP's or other personel information must be anonymized/hashed). If that is made up by AI...Well there goes your credibility. But I don't assume that from the beginning.

this post was submitted on 28 Apr 2026
131 points (80.5% liked)

Technology

84920 readers
3905 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 3 years ago
MODERATORS