homelab · honeypot
The honeypot
I left fake secrets lying around on this website: a .env file, a Git config, a database backup. Bots find them within hours. The AWS keys inside are fake too, but they ring a bell when someone uses them. This page is everything that has happened since.
00Right now connecting
bait grabbed
–
times a bot took a fake file
this month
–
from – different sources
stolen keys used
–
times someone tried them
The first two tiles tick up the moment a bot hits a bait file. The key counts come straight from the keys' own tripwire and refresh every couple of minutes. No IP addresses are shown anywhere on this page: only countries and network names.
01How the trap works
1 · the bait
- Files that every scanner on the internet asks for: .env, .git/config, .aws/credentials, backup.zip, database dumps and a few more
- The site hands over a fake copy: made-up passwords, a made-up database, and AWS keys that do nothing. Every file has its own keys, so I can tell which one a thief opened
- People in a browser get a surprise instead: see for yourself
2 · the tripwire
- Those AWS keys come from a free service that watches them for me
- The keys can't read, change or buy anything. But the moment anybody tries them, AWS tells the service, and the service tells me
- It records the call, the country and the network. That is the log further down
3 · what I do with it
- Count it, learn from it, and put it on this page
- Nothing here touches my real systems: the bait lives on the public website only, and every real login sits behind the home network
- The counters on the home page are the same numbers, live
02What bots go for
~ — most wanted files (30 days)
03Two different crews
Taking the files and using the keys turn out to be two separate jobs.
the collectors
the key users
04What they asked AWS
Nobody can do anything with these keys, but you can learn a lot from the first thing a thief asks. Every call below is a question, not an action.
~ — which bait file the keys came from
Each bait file carries its own set of keys (10 tripwires in all), so a use points back to the file it was copied from.
05Where from
Country and network come from where the call reached AWS. Many are home internet connections, which usually means somebody's hijacked computer or a rented residential proxy, not the person behind the attack.
06The log
~ — tail -n 40 stolen-keys.log (no addresses)
"Source A, B, C…" just means the same sender: letters are handed out in order of first appearance, so you can see who came back.
07Fair questions
is this safe?
- Yes. The files are made up and the keys are tripwires. The bait is served by the public website only; nothing on the home network is reachable from it
where are the IP addresses?
- I don't. Attackers mostly hide behind hijacked home connections, so an address would just point at an innocent person
can I try it?
- Open /.env in a browser to see the surprise, or fetch it with curl to see the bait. It's all fake, and if you try the keys, my phone buzzes