anthony.wingerter

homelab · honeypot

The honeypot

I left fake secrets lying around on this website: a .env file, a Git config, a database backup. Bots find them within hours. The AWS keys inside are fake too, but they ring a bell when someone uses them. This page is everything that has happened since.

00Right now connecting

bait grabbed

–

times a bot took a fake file

this month

–

from – different sources

stolen keys used

–

times someone tried them

last attempt

–

 

The first two tiles tick up the moment a bot hits a bait file. The key counts come straight from the keys' own tripwire and refresh every couple of minutes. No IP addresses are shown anywhere on this page: only countries and network names.

01How the trap works

1 · the bait

  • Files that every scanner on the internet asks for: .env, .git/config, .aws/credentials, backup.zip, database dumps and a few more
  • The site hands over a fake copy: made-up passwords, a made-up database, and AWS keys that do nothing. Every file has its own keys, so I can tell which one a thief opened
  • People in a browser get a surprise instead: see for yourself

2 · the tripwire

  • Those AWS keys come from a free service that watches them for me
  • The keys can't read, change or buy anything. But the moment anybody tries them, AWS tells the service, and the service tells me
  • It records the call, the country and the network. That is the log further down

3 · what I do with it

  • Count it, learn from it, and put it on this page
  • Nothing here touches my real systems: the bait lives on the public website only, and every real login sits behind the home network
  • The counters on the home page are the same numbers, live

02What bots go for

~ — most wanted files (30 days)
  • loading…
~ — grabs per day

 

03Two different crews

Taking the files and using the keys turn out to be two separate jobs.

the collectors

  • loading…

the key users

  • loading…

04What they asked AWS

Nobody can do anything with these keys, but you can learn a lot from the first thing a thief asks. Every call below is a question, not an action.

loading…

~ — which bait file the keys came from
  • loading…

Each bait file carries its own set of keys (10 tripwires in all), so a use points back to the file it was copied from.

05Where from

~ — countries
  • loading…
~ — networks
  • loading…

Country and network come from where the call reached AWS. Many are home internet connections, which usually means somebody's hijacked computer or a rented residential proxy, not the person behind the attack.

06The log

~ — tail -n 40 stolen-keys.log (no addresses)
  • loading…

"Source A, B, C…" just means the same sender: letters are handed out in order of first appearance, so you can see who came back.

07Fair questions

is this safe?

  • Yes. The files are made up and the keys are tripwires. The bait is served by the public website only; nothing on the home network is reachable from it

where are the IP addresses?

  • I don't. Attackers mostly hide behind hijacked home connections, so an address would just point at an innocent person

can I try it?

  • Open /.env in a browser to see the surprise, or fetch it with curl to see the bait. It's all fake, and if you try the keys, my phone buzzes