https://drkt.eu/

This is an alt account, you may see it around. I am not ban-dodging intentionally, I promise!

This is the main
https://scribe.disroot.org/u/drkt

  • 1 Post
  • 55 Comments
Joined 17 days ago
cake
Cake day: March 16th, 2025

help-circle




  • Reading comprehension and organized harassment is such a problem for your community that the entire rest of the fediverse knows and jokes about it. I can appreciate that you might not see most of that because most instances defederate from yours and most users block you after the first interaction.

    It’s totally normal and organic that entire groups of tankies show up at the same time to dunk on low-interaction comments in low-interaction posts, often several replies deep in a thread that nobody’s reading anymore, and it’s always the most meaningless shit where they clearly didn’t read the post and formed a cohesive rebuttal to any points but just spew the first vaguely relevant zinger they find in the text file of one-line zingers they seem to share amongst each other.




  • I wouldn’t even know where to begin, but I also don’t think that what I’m doing is anything special. These NVR IPs are hurling abuse at the whole internet. Anyone listening will have seen them, and anyone paying attention would’ve seen the pattern.

    The NVRs I get the most traffic from have been a known hacked IoT device for a decade and even has a github page explaining how to bypass their authentication and pull out arbitrary files like passwd.



  • I have plenty of spare bandwidth and babysitting-resources so my approach is largely to waste their time. If they poke my honeypot they get poked back and have to escape a tarpit specifically designed to waste their bandwidth above all. It costs me nothing because of my circumstances but I know it costs them because their connections are metered. I also know it works because they largely stop crawling my domains I employ this on. I am essentially making my domains appear hostile.

    It does mean that my residential IP ends up on various blocklists but I’m just at a point in my life where I don’t give an unwiped asshole about it. I can’t access your site? I’m not going to your site, then. Fuck you. I’m not even gonna email you about the false-positive.

    It is also fun to keep a log of which IPs have poked the honeypot have open ports, and to automate a process of siphoning information out of those ports. Finding a lot of hacked NVR’s recently I think are part of some IoT botnet to scrape the internet.