frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: Knock-Knock v2 – Visualizing bot attacks in multi-protocol Technicolor

https://v2.knock-knock.net
2•djkurlander•1h ago

Comments

djkurlander•1h ago
OP here. Check out the new https://knock-knock.net. v1 got 40,000+ visits from HN alone, hoping you'll find v2 worth checking out too.

Watch bots trying to break into my honeypots, gain access to my files, place expensive VOIP calls, attack my HTTP server, and relay SPAM email. The new knock-knock.net shows you SSH, Telnet, FTP, RDP, SMB, SIP, HTTP, and SMTP attacks in real-time: where they are coming from (check out the spinning globe heat-map!), the most common usernames and passwords, info on why some of those usernames and passwords are being used, the worst offending IPs, and of course the ISP wall of shame. View the stats for the protocols together, or filter by protocol. All presented in what I hope is a very cool UI.

The new knock-knock.net aggregates attack info from multiple servers around the world and presents the info in one place, hence you'll see attacks come in at a furious pace, and may want to use the pause button (or space bar). Turning on audio (the speaker icon) lets you hear what some have called the "background radiation of the internet" on a virtual geiger counter. This is intended to be a fun, educational site, not a serious cybersecurity tool.

A few random, interesting things:

1) The locations of the bots doing the various protocol attacks differ pretty dramatically. For example, Romania, Poland, and the Netherlands are currently big for SSH bots, India leads for SMB, China is tops for RDP, and France for SIP, but the US is #1 overall.

2) SMTP attempts are usually sentry emails. SMTP bots first try to send an email to themselves so they can tell the server is a working relay. Notice that nearly all of the emails include my IP address in the subject or body (it appears here redacted as <target-ip>) so they can tell the relay is operative.

3) The Internet has been blocked for nearly all of the citizens of Iran since the January protests. However, I found it surprising that attacks still originate from servers there.

4) RDP and SIP bots will connect to a server and spam it practically non-stop. I had to set up an autoban for these protocols at 2,000 knocks - much lower than the 10,000 knock ban set for the other protocols.

5) As of this posting, we're still waiting for knocks from several African countries. They tend to have fewer internet servers than the rest of the world. However, we did get knocks from Jersey (the island, not the state or cow), Nauru (~10K people), and Monaco (~2 km^2). Surprising that we're still waiting for EU member Slovenia!

6) We've even seen knocks from space! Well from ISP SpaceX/Starlink anyway. You would think this would be expensive, but bots are often replicated on machines they infect, and they aren't paying the bills.

7) The worst offending ISP is ironically named "Unmanaged Ltd." Interestingly, it was previously DigitalOcean, but shortly after v1 was posted to HN and r/digital_ocean, and user comments skewered that ISP, their bot attacks dropped over 99%! Coincidence? Maybe. Maybe not.

Works great on desktop or mobile — try it out and let me know what you think. Happy to answer questions and take suggestions.

For a tutorial, see https://knock-knock.net/summary.

To see the original v1 knock-knock.net (collecting data for 90 days), visit: https://v1.knock-knock.net.

If the aggregated v2 site is too fast for you, visit a single feeder server (e.g. https://la5.knock-knock.net).

The source lives at https://github.com/djkurlander/knock-knock.

Datahenge•1h ago
I love the use of color and the retro-style UI. Your INSTRUCTIONS.md was comprehensive.

Appears to be CPU-heavy sometimes in the browser (spiked one of my CPUs to 100%), so could be an opportunity for optimization later.

I've often wanted to show my clients how risky their brand-new VPS is without proper firewall configuration. Your Knock-Knock tool would be a great way of helping them visualize that.

Very nice app; great job!

djkurlander•1h ago
The goal is to educate people (originally my kids) about one particular aspect of cybersecurity. I love it when people use the site for this purpose.

Yep, with ~80 knocks coming in per second and two 3D globe visualizations, it does make a lot of use of the browser. That said, it runs smoothly even on an iPhone browser. The server scales really well (longtime load average of 0.05 on a $6.75/year VPS :-).

Thanks!

Show HN: Parlor Jarvis – Realtime AI (audio+screen in, voice out) & multilingual

https://github.com/typomonster/parlor-jarvis
1•unusual_typo•3m ago•1 comments

Ask HN: Why hasn't automation testing been disrupted with LLMs?

1•grandimam•4m ago•0 comments

GPT cannot even count beans correctly

https://chatgpt.com/share/69ee4690-60ac-83ea-b28c-f4ce6284a75a
1•OutOfHere•7m ago•0 comments

Sub two-hour marathon record broken

https://www.espn.com/olympics/trackandfield/story/_/id/48598786/sabastian-sawe-wins-london-marath...
1•staplung•7m ago•0 comments

Google's new gradient icons for Gmail, Calendar, Drive, and other apps

https://9to5google.com/2026/04/26/gmail-google-gradient-redesign/
2•meetpateltech•10m ago•1 comments

Sabastian Sawe becomes the first man ever to break 2 hours in a marathon

https://twitter.com/ChrisChavez/status/2048357328894759363
1•ndr42•11m ago•0 comments

PRowhammer: Propagating Bit-flips from CPU to GPU [pdf]

https://www.cse.iitb.ac.in/~biswa/ISCA2026.pdf
1•matt_d•11m ago•0 comments

Proposed New Test of AI Capabilities:)

1•VikRubenfeld•13m ago•0 comments

Seemingly Conscious AI Risks

https://papers.ssrn.com/sol3/papers.cfm?abstract_id=6588659&trk=comments_comments-list_comment-text
1•andy99•14m ago•0 comments

Dockframe, modular USB-C hub based on framework adapter cards

http://dockframe.com
1•heatmiser•17m ago•1 comments

Jay Shetty: "I Read 10 Books That Changed My Life"

https://www.youtube.com/watch?v=HfNYp5k2wf8
1•Brysonbw•17m ago•0 comments

The Quantization Robustness of Diffusion Language Models in Coding Benchmarks

https://arxiv.org/abs/2604.20079
1•matt_d•17m ago•0 comments

Memory-harness: Linux Rust CLI for low-overhead peak-RSS and memory profiling

https://github.com/mjgil-rust/memory-harness
1•mjgil•17m ago•0 comments

GoDaddy Gave a Domain to a Stranger Without Any Documentation

https://anchor.host/godaddy-gave-a-domain-to-a-stranger-without-any-documentation/
2•jamesponddotco•18m ago•0 comments

Paramount Is Down (UK)

https://downdetector.co.uk/status/paramountplus/
1•librasteve•18m ago•1 comments

Awesome Codex Automations

https://github.com/onurkanbakirci/awesome-codex-automations
1•onurkanbkrc•20m ago•0 comments

10x Is a Lot

https://www.quarter--mile.com/10x-Is-a-Lot
1•gkolli•21m ago•0 comments

Ben Horowitz on What Makes a Great Founder

https://www.youtube.com/watch?v=dFT4xj57D7U
1•Brysonbw•26m ago•0 comments

I scanned 1M domains and found the web's AI instruction layer

https://dialtoneapp.com/2026/april/i-scanned-1M-domains
2•fcpguru•27m ago•1 comments

Quick tutorial to get a blog online from Org Mode thanks to Org Social

https://en.andros.dev/blog/c68f00c3/quick-tutorial-to-get-a-blog-online-from-org-mode-thanks-to-o...
2•ibobev•30m ago•0 comments

Toolchain Horizons: Exploring Rust Dependency-Toolchain Compatibility

https://tigerbeetle.com/blog/2026-04-24-toolchain-horizons/
1•ibobev•30m ago•0 comments

The predictable failure of the QDay Prize

https://algassert.com/post/2601
1•firefly284•30m ago•0 comments

Staying a Spell with the Exidy Sorcerer

https://bumbershootsoft.wordpress.com/2026/04/25/staying-a-spell-with-the-exidy-sorcerer/
1•ibobev•31m ago•0 comments

A weekend with LoRA on Gemma 4 E2B: instrumenting what fine-tuning changes

https://aiexplr.com/post/fine-tuning-5b-code-assistant-three-lessons
1•mailharishin•31m ago•0 comments

New robotic control software avoids jamming their joints

https://arstechnica.com/science/2026/04/kinematic-intelligence-helps-robots-learn-their-limits/
2•Brajeshwar•33m ago•0 comments

The West forgot how to make things, now it's forgetting how to code

https://conduit.arewefriends.org/s/the-west-forgot-how-to-make-things-now-its-forgetting-how-to-8...
2•01-_-•34m ago•0 comments

The Visible Zorker: Zork 1

https://eblong.com/infocom/visi/zork1/
3•PLenz•34m ago•0 comments

One last trip to the internet in 2009 with The Rough Guide 14

https://www.planetjones.net/blog/19-04-2026/one-last-trip-to-the-internet-in-2009-with-the-rough-...
1•planetjones•34m ago•0 comments

I worked just as hard, failed just as hard–then saw it was rigged

https://comuniq.xyz/post?t=996
3•01-_-•35m ago•0 comments

pvlib: Open-source Python library for solar power modeling

https://github.com/pvlib/pvlib-python
1•ep_jhu•38m ago•0 comments