frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Ask HN: Do you have any SSH bot scripts?

2•Bender•2h ago
I do not have any SSH bot scripts and would like to play around with the default OpenSSH_10.0p2 capabilities to slow bots to a crawl or see if I can get them stuck rather than playing whack-a-mole.

To prove I temporarily control the IP in question one can SFTP as mirror@104.200.16.195 on port 22 with no password and there is a __README__.txt. Feel free to brute force or crash sshd.

If you have scripts that work fine I would love if you SFTP them to me. If your scripts get stuck I will show my work being done to slow bots via SFTP. Beyond that of what OpenSSH 10 is already doing to deprecate fail2ban.

The goal is to bend the default applications and OS in a way most should be able to without installing anything.

Comments

flamesofphx•1h ago
I get rid of my bot attempts.. by doing this:

1. Make all port not respond (Stealth in the firewall), unless they are public like http..

2. Change the SSH port # (over 8192 also)..

3. Setup port knocking watchdog so they have to knock first in a specific order on three ports before being allow to connect to real port.

4. Setup fail2ban. Including if someone pings the knocking ports (in the incorrect order) or real ssh (Without knocking first) then after a couple of times, add their ip to fail2ban list for 48hours..

You get rid of 99.98% of the lookers instantly, by just doing step 2...

This assume you have control over the server, there are several script online that help you provision something like that with ansible.. (Most of them helper related to configuring fail2ban.

Bender•1h ago
I too change my default port on all nodes except public SFTP servers. I also restrict the TCP SYN MSS, Window and TTL and allowed CIDR blocks for non public SFTP servers. It keeps most things very quiet. Quiet makes it easier to spot more serious and targeted attempts.

This is an attempt to see what fun I can have with the bots on public SFTP servers. I am also curious if I can crap-up their logs a bit, depending on what they log. It's also fun to get them stuck using OpenSSH rather than depending on netfilters tarpit which AFAIK is not available via nftables.

This poor bot for example is stuck in a loop and can't even try to authenticate because of something I put in the sshd_config a copy of which is available on the SFTP server. Legit SSH clients can attempt to authenticate however.

    srclimit_penalise: ipv4: new 128.199.x.x/24 deferred penalty of 9 seconds for penalty: connections without attempting authentication

    # since I cleared the logs this morning
    logread | grep -c "128.199"
    591

Show HN: Data Formulator 0.5 – interactive AI agents for data visualization

https://data-formulator.ai/
1•chenglong-hn•42s ago•0 comments

Elon Musk's $1T pay deal is a troubling display of corporate capture

https://www.economist.com/business/2025/11/07/elon-musks-1trn-pay-deal-is-a-troubling-display-of-...
1•1vuio0pswjnm7•3m ago•0 comments

Contributing to Open-Source Should Be Required, Like Jury Duty

https://www.joshbeckman.org/blog/practicing/contributing-to-opensource-should-be-required-like-ju...
2•bckmn•3m ago•0 comments

FBI Seeks to Unmask Anonymous Web Archiving Service Owner

https://www.zerohedge.com/technology/fbi-seeks-unmask-anonymous-web-archiving-service-owner
1•Master_Quant•5m ago•0 comments

Week After Week, the US Is Dismantling Knowledge Infrastructure

https://www.techpolicy.press/week-after-week-the-us-is-dismantling-knowledge-infrastructure/
1•robtherobber•5m ago•0 comments

VolleyBots: A Testbed for Multi-Drone Volleyball Games

https://sites.google.com/view/thu-volleybots
1•parsley•6m ago•0 comments

Newsom mounts a lonely stage at COP30

https://www.politico.com/newsletters/power-switch/2025/11/10/newsom-mounts-a-lonely-stage-at-cop3...
1•geox•7m ago•0 comments

Wigner's cats with high-entropy random numbers

https://github.com/msuzen/leymosun
1•northlondoner•9m ago•1 comments

Show HN: Vexor – A semantic grep that finds files by meaning, not by text

https://github.com/scarletkc/vexor
1•scarletkc•11m ago•0 comments

US states could lose $21B of broadband grants after Trump overhaul

https://arstechnica.com/tech-policy/2025/11/us-states-could-lose-21-billion-of-broadband-grants-a...
5•ndsipa_pomu•11m ago•0 comments

Pentagon Demands Verified Cybersecurity from Contractors

https://www.securityweek.com/cmmc-live-pentagon-demands-verified-cybersecurity-from-contractors/
3•Bender•14m ago•0 comments

Copy-paste now exceeds file transfer as top corporate data exfiltration vector

https://www.scworld.com/news/copy-paste-now-exceeds-file-transfer-as-top-corporate-data-exfiltrat...
1•Bender•15m ago•0 comments

AI magic dust, conference coziness and the illusion of managed risk

https://www.scworld.com/resource/owasp-global-appsec-ai-magic-dust-conference-coziness-and-the-il...
2•Bender•16m ago•0 comments

GPULend

1•Vxtzq•16m ago•0 comments

Analyzing Darktable OpenCL Memory Use

https://op-co.de/blog/posts/darktable_opencl_memory/
2•ge0rg•17m ago•0 comments

We ran over 600 image generations to compare AI image models

https://latenitesoft.com/blog/evaluating-frontier-ai-image-generation-models/
1•kalleboo•18m ago•0 comments

Kimi CLI has a zsh Plugin

https://github.com/MoonshotAI/zsh-kimi-cli
1•mjakl•18m ago•0 comments

Orbital Characterization of a Newly Discovered Small Satellite Around Quaoar

https://arxiv.org/abs/2511.07370
1•bikenaga•18m ago•0 comments

Practice answers with yourself. I made a thing that I didn't want to pay for

https://look.imwithstupid.fun
2•samrocksc•19m ago•1 comments

Dhrystone performance charted across systems released between 1976 and 2023

https://www.tomshardware.com/pc-components/cpus/veteran-devs-newest-computer-is-200-000-times-fas...
1•phront•20m ago•0 comments

Show HN: I built a tool that lets you ask questions on previous World Cups

https://query.new
1•eportet•20m ago•0 comments

Bitbucket Is Offline

https://bitbucket.status.atlassian.com
7•nathabonfim59•25m ago•0 comments

Authorities took down Streameast, the largest illegal sports streaming site

https://www.nytimes.com/athletic/6742754/2025/11/11/streameast-illegal-streaming-raid/
1•jonwachob91•25m ago•1 comments

Why Textbook Statistical Methods Aren't as Effective in IT (2021)

https://theartofmachinery.com/2021/12/01/textbook_stats_and_tech.html
1•bariumbitmap•25m ago•0 comments

Show HN: Enact – 60-second pitch analyzer (score/100 and 3 edits, no signup)

https://getenact.com/
1•cotreasoner•28m ago•0 comments

Font recognition reimagined with FasterViT-2

https://www.collabora.com/news-and-blog/blog/2025/11/11/font-recognition-reimagined-with-fastervi...
2•losgehts•29m ago•0 comments

A CHIP-8 emulator in Ada/Spark

https://github.com/moehr1z/chip8
2•hggh•29m ago•0 comments

The AI Cold War

https://www.wsj.com/tech/ai/the-ai-cold-war-that-will-redefine-everything-4e1810b2
1•perihelions•29m ago•1 comments

New test can flag drugs that could be harmful to cats

https://phys.org/news/2025-10-flag-drugs-cats.html
1•PaulHoule•29m ago•0 comments

Training GPT in Sheets

https://zalex.co/p/i-trained-gpt-in-google-sheets
1•alex_zhezherov•30m ago•0 comments