TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Live attacks against the Norse honeypot infrastructure

149 pointsby dtournemillealmost 11 years ago

18 comments

eddygalmost 11 years ago
The Google&#x2F;Arbor Digital Attack Map[1] provides a similar view based on data from 270+ ISPs around the world. Hovering over an attack shows details, and sliding the timeline indicator to dates in the past lets you view some very large attacks (&gt;400 Gb of attack traffic).<p>[1] <a href="http://www.digitalattackmap.com/" rel="nofollow">http:&#x2F;&#x2F;www.digitalattackmap.com&#x2F;</a>
评论 #8156136 未加载
viraptoralmost 11 years ago
Couldn&#x27;t find much information about that visualisation, so I have to wonder - what kind of traffic do they count? Is it only showing detected known&#x2F;assumed attacks? Or does it count all connections? (i.e. does it include scans, or not)<p>If it includes scans - I&#x27;m surprised how few there are. (that&#x27;s about as many as you&#x27;d get on 5 randomly created VMs) If it doesn&#x27;t - I&#x27;m surprised how many active attacks there are.
评论 #8156415 未加载
recyclemealmost 11 years ago
&quot;The Norse live attack map is a visualization of a tiny portion (&lt;1%) of the data processed by the Norse DarkMatter™ platform every day.&quot;<p><a href="http://www.norse-corp.com/" rel="nofollow">http:&#x2F;&#x2F;www.norse-corp.com&#x2F;</a>
评论 #8155222 未加载
dtournemillealmost 11 years ago
Technical accuracy aside, it&#x27;s a great marketing tool. Nicely done.
ck2almost 11 years ago
Needs Missile Command sounds.<p>Of course the internet does not route in &quot;as the crow flies&quot; lines like this is showing. There is routing.
评论 #8155270 未加载
rpwverheijalmost 11 years ago
Does anyone know why so relativly many attacks come from the Netherlands? After running this for about 5 minutes it is the number one origin of attack at the moment.
评论 #8155146 未加载
评论 #8156668 未加载
th3iedkidalmost 11 years ago
where does it get data from?
评论 #8155080 未加载
评论 #8154989 未加载
ChuckMcMalmost 11 years ago
There is fairly rampant infection of something which uses port 21230 for its activities. I use the port numbers and verify that my iptables aren&#x27;t passing any of them, which is generally useful. And it is interesting to see the ones being &quot;attacked&quot; (as in people trying to either open them or send data to them via UDP)
coldcodealmost 11 years ago
It looks like a modern version of War Games. But how does it determine the origins and attack targets in real time?
评论 #8155815 未加载
0xdeadbeefbabealmost 11 years ago
Could they effectively DoS the IPs on the blacklist[1] and still play good defense?<p>1. <a href="http://www.norse-corp.com/darklist.html" rel="nofollow">http:&#x2F;&#x2F;www.norse-corp.com&#x2F;darklist.html</a>
评论 #8155793 未加载
richardwigleyalmost 11 years ago
When I use firefox it says &#x27;too slow? try chrome&#x27; - it is much slower on firefox - is firefox that bad or is it just optimized for Chrome?
评论 #8156677 未加载
jpmattiaalmost 11 years ago
A list of attacker IPs (from, say, the last 7 days) to block in iptables would be a very popular item.
Donzoalmost 11 years ago
Wow. So many attacks. Running this site is going to DOS my phone.
ErikRognebyalmost 11 years ago
Anyone know why 21320 is such a big target? Spybot S&amp;D?
评论 #8156642 未加载
评论 #8156644 未加载
baqalmost 11 years ago
is there nothing worth attacking in china or it&#x27;s simply that there aren&#x27;t many honeypots there?
gcb0almost 11 years ago
it is like watching a War match where everyones goal is &quot;conquer california, or 24 territories&quot;
rurounijonesalmost 11 years ago
heh, someone in china just tried a masss SSH login to the US, looked like a shotgun blast.
jk215almost 11 years ago
I have no idea whats going on but its very exciting looking.