this post was submitted on 03 Jan 2026
40 points (93.5% liked)

Selfhosted

54412 readers
1073 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

  1. Be civil: we're here to support and learn from one another. Insults won't be tolerated. Flame wars are frowned upon.

  2. No spam posting.

  3. Posts have to be centered around self-hosting. There are other communities for discussing hardware or home computing. If it's not obvious why your post topic revolves around selfhosting, please include details to make it clear.

  4. Don't duplicate the full text of your blog or github here. Just post the link for folks to click.

  5. Submission headline should match the article title (don’t cherry-pick information from the title to fit your agenda).

  6. No trolling.

  7. No low-effort posts. This is subjective and will largely be determined by the community member reports.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] kayzeekayzee@lemmy.blahaj.zone 7 points 1 week ago (2 children)

Howso? Does it attract hackers?

[–] non_burglar@lemmy.world 12 points 1 week ago (2 children)

Hackers don't poke around themselves, generally. They use bots and scripts to collect info and then return in person to pry open targets they want or find interesting.

Op is tarpitting with a stream, which is a telltale sign of a honeypot, nothing else behaves that way. So a bot crawling for content? Fine. A bot collecting info for suitable targets? Might get the attention of the person looking. And once you have a hacker's attention, you might be in trouble if they're competent and start pressing buttons.

You really have to know what you're doing to understand where in the stack an attacker is going pull levers, which is as individual as people themselves.

[–] fort_burp@feddit.nl 4 points 6 days ago

Oh wow you totally had me at first with your username.... but now I'm on to you!!

[–] drkt@scribe.disroot.org 4 points 1 week ago (1 children)

nothing else behaves that way.

This is quite wrong, but it doesn't matter, because if your setup is insecure, then you'll find out sooner or later anyway. The hacking space is pretty much automated at this point, which is why my honeypot works at all.

Do you also think that anyone who puts Anubis in front of their website is getting the attention of anonymous illuminati master-hackers because it causes their bots to waste a few processing cycles? Tarpitting is no different. If your bot is written poorly, it will get stuck on even legitimate pages.

[–] non_burglar@lemmy.world -2 points 6 days ago (1 children)

it will get stuck on even legitimate pages

what

Please go to a local ctf, even just a high school-level one.

[–] drkt_@lemmy.dbzer0.com 1 points 6 days ago* (last edited 6 days ago) (1 children)

I can't engage with you when you can't or won't quote the full sentence. You are literally picking a section of a sentence, stripping it of context so it looks wrong, and then pretending I said that.

If your bot is written poorly, it will get stuck on even legitimate pages.

The point I am making is that the only way you're getting into my network is if you're sitting on a crazy 0day for Debian, Apache or PHP. My network isn't a playground that I set up like a jigsaw for someone to "solve". There's nothing to solve, it's not a CTF. You can't dump points into a hacking skill and magically bypass some of the most vetted and battle-tested software in the world.

[–] non_burglar@lemmy.world 1 points 6 days ago

You need to chill out and not get so worked up about someone calling out your promotion of honeypots in a forum where the vast majority don't even know the difference between DNS and PKI, and aren't clear on the delineation between their LAN and the internet.

There’s nothing to solve, it’s not a CTF.

You misunderstand, I'm not implying your network is a CTF. I mean go to your local security group and watch how pen testers work. I can tell you they certainly do not fall for "tarpits", even the fairly new kids.

Ultimately, you can do what you want, I obviously can't stop you.

[–] drkt@scribe.disroot.org 3 points 1 week ago* (last edited 1 week ago)

It does not; tarpitting is a normal practice.

No one sitting on 0days are gonna waste them on randos, and my setup is secure besides. I've been doing this, and worse, for years.