frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

TarPit.pro – honeypot that catches and auto-bans attackers

https://tarpit.pro/
1•chka•1h ago

Comments

chka•1h ago
I kept seeing the same brute-force attempts on every VPS I run, virtually on every service that opened a port. fail2ban or similar tools definitely help but they only act after hackers/bots hit real services. I wanted to catch them a lot earlier.

So I built tarpit.pro: it opens fake ports (SSH, MySQL, Redis, Telnet, etc and you can configure any port you want) sending realistic banners (you can specify what your instance sends). Nobody with good intentions connects uninvited to a fake MySQL on port 3306 and that means anyone who does gets banned via firewall (linux/macOS/windows) immediately. It also acts as a centralized graphical firewall management (webUI) for all the servers you manage. You can blacklist, whitelist IPs and ports. But more importantly, you can create fleets of servers (groups that share security) and any action (automated or manual bans, whitelists, etc) on one of your servers propagates to all the servers on the fleet.

I have been running agents on 5 of my own servers for about 9 days now. Here are some real and true statistics:

- attacks caught: ~18k , unique IPs: ~8k, ~7.5k banned (ban last for 24h - AI decides if the hacker deserves a permanent ban)

- SSH gets hammered the most by far (so fail2ban saves the day), then Telnet (yes, telnet in 2026 - who is using telnet? I guess some still do)

- Top source countries: Russia, US, China, Netherlands (I guess too many hacked VMs), UK (???)

- My asian VMs gets most hits (11k), then US (10k) then european VMs (600!!!)

- Most tried passwords: 123456, admin, password, foobared (the Redis default) - it's so funny seeing hackers trying different passwords

- First attack showed up about 90 seconds after going live

Few things about the technology: - it's a single Go binary, installs as a systemd service

- all user information (emails, names, IP addresses, servers) are encrypted and stored on a HashiCorp Vault. So even if the database is compromised the attacker gets UUIDs and ciphertext

- all connections between any service component is secured with mTLS

- brute force protection: 3 failures in 15 min means 1 hour lockout

- binary signature verification for the protection agent, modified binaries get rejected

Free tier is FREE forever and gets you 2 servers and a basic but useful cloud dashboard. There's a launch offer (code LAUNCH100) if you want to try Pro on up to 4 servers for a month, so you can try all the pro features and see if it makes sense.

To get started: register at tarpit.pro and pick a tier. Then add server licenses at the pricing tier you want (you can register for the free tier but upgrade to pro) paste the install command, watch the dashboard light up. You can upgrade and downgrade any time you want.

Happy to answer questions about the architecture or the attack data and I'm open to suggestions (either here or via the platform's ticketing system)

Show HN: Multigres Kubernetes Operator

https://github.com/multigres/multigres-operator
1•sougou•1m ago•0 comments

The "One Brain, Many Mouths" Problem in Multi-User AI Agents

1•niel_hu•3m ago•0 comments

Show HN: Prototype for internalized AI values using shame/pride mechanisms

1•renaissancebro•3m ago•0 comments

Paper Cuts #2: RAG is dead, long live memory

https://sderosiaux.substack.com/p/paper-cuts-2-agents-that-remember
1•chtefi•5m ago•0 comments

How HN: Uldl.sh – Persistent file storage for AI agents via MCP and curl

https://uldl.sh
1•thedanielforum•6m ago•0 comments

Rory Sutherland's 2026 Predictions [video]

https://www.youtube.com/watch?v=6SXCJhqXubU
1•Lio•7m ago•0 comments

Moving the Critic into My Editor

https://www.joshbeckman.org/blog/practicing/moving-the-critic-into-my-editor
1•bckmn•7m ago•0 comments

Natural-Language Agent Harnesses

https://arxiv.org/abs/2603.25723
1•Jimmc414•7m ago•0 comments

FreeBSD Forums defaced

https://forums.FreeBSD.org/
1•xinayder•7m ago•1 comments

Mac App Store Review Times Increasing

https://mjtsai.com/blog/2026/03/02/mac-app-store-review-times-increasing/
4•tosh•7m ago•0 comments

AutoClaw: AI assistant, right inside your chats

https://autoglm.z.ai/autoclaw/
1•pretext•8m ago•0 comments

Tools and Toolmaking

https://unsung.aresluna.org/on-tools-and-toolmaking/
1•bobbiechen•8m ago•0 comments

DJI Romo robovac had security so poor, this man remotely accessed thousands

https://www.theverge.com/tech/879088/dji-romo-hack-vulnerability-remote-control-camera-access-mqtt
1•chbint•8m ago•1 comments

Nubank Morse: A graphical, interactive tool for browsing Clojure data

https://github.com/nubank/morse/tree/main
1•tosh•11m ago•0 comments

CardRoundup – Free tracker for credit card credits that expire

https://www.cardroundup.com/
1•kimboxbt•11m ago•1 comments

Cloudflare Client-Side Security: smarter detection, now open to everyone

https://blog.cloudflare.com/client-side-security-open-to-everyone/
2•Brajeshwar•12m ago•0 comments

Reverse Engineering Crazy Taxi, Part 2

https://wretched.computer/post/crazytaxi2
1•wgreenberg•13m ago•0 comments

Datomic at Clojure/Conj 2025

https://blog.datomic.com/2026/01/conj2025.html
1•tosh•14m ago•0 comments

Natajutempe

https://rtnf.substack.com/p/natajutempe
1•altilunium•16m ago•0 comments

OCR For construction documents does not work

https://www.getanchorgrid.com/developer/docs/endpoints/drawings-doors
1•wcisco17•17m ago•0 comments

How to Get to Tomorrow

https://campedersen.com/kardashev
2•ecto•17m ago•0 comments

Bytemine MCP Search 130M+ B2B contacts from Claude, Cursor, or any AI assistant

https://github.com/kzarov/bytemine-bytemine-mcp
1•kzarov•18m ago•0 comments

Ask HN: Google Finance Replacement Without AI Slop?

3•rurp•20m ago•0 comments

Moon phase today: What the Moon will look like on March 29

https://mashable.com/article/moon-phase-today-march-29
1•01-_-•21m ago•0 comments

User-Mode Linux

https://en.wikipedia.org/wiki/User-mode_Linux
1•gurjeet•21m ago•0 comments

Show HN: Local meeting transcription that writes straight to your Obsidian vault

https://github.com/Gremble-io/Tome
1•grembleio•21m ago•0 comments

Software in the Age of Agent Orchestration

https://opuslabs.substack.com/p/the-agent-layer-is-rewriting-software
1•opuslabs•21m ago•0 comments

AI agents are breaking web analytics in a way nobody is solving

https://leoanalysis.substack.com/p/ai-agents-are-breaking-web-analytics
1•leo123456•21m ago•0 comments

Meta-Harness: End-to-End Optimization of Model Harnesses

https://yoonholee.com/meta-harness/
1•mbeissinger•22m ago•0 comments

Airlines surprise passengers with 'flights' that are buses

https://www.washingtonpost.com/travel/2026/03/26/american-airlines-flight-bus-ride/
2•mooreds•22m ago•1 comments