James Woolley

429 posts

James Woolley banner
James Woolley

James Woolley

@Xtrato

Interested in Network security and Technology

Herefordshire, England Katılım Mart 2008
322 Takip Edilen2.2K Takipçiler
James Woolley
James Woolley@Xtrato·
@Paul_Reviews The fact we have gotten into this mess of users having to submit sensitive information just to verify age is insane. Its only a matter of time before a data breach of one of these verification authorities happens. This is a much better solution for a very simple issue.
English
1
5
48
1.7K
James Woolley
James Woolley@Xtrato·
I recently created a VNC honeypot. Many people asked me how I went about setting it up, so I've created a blog post describing the process. You can read about it at: ja.meswoolley.co.uk/vnc-honeypot/
James Woolley tweet media
English
8
59
312
22.4K
Julian Harris
Julian Harris@julianharris·
@Xtrato Really brings to life the question “are hackers trying to break into your computer?”. Yes. Most definitely yes.
English
1
0
4
448
Alex Elliott
Alex Elliott@alexpotato·
@Xtrato These are great! Looking forward to see what you do next.
English
1
0
2
313
André Bação
André Bação@Andr3Baca0·
@Xtrato @JimmyMcShill Thanks for sharing. I would love a detailed process. There were some lines in the "ps" regarding a ffmpeg. is the user john anything to do with the recording? Have you even tried to hide the backend? All is being done in that particular instance right?
English
1
0
1
139
James Woolley
James Woolley@Xtrato·
I left a server online with VNC wide open to see how it would be interacted with. This is one of the more interesting interactions:
English
168
362
5.8K
743.2K
James Woolley
James Woolley@Xtrato·
@DaAlphaPanda I haven't gotten around to checking the files properly. I have them saved and intend to though.
English
0
0
1
764
James Woolley
James Woolley@Xtrato·
@re_skob Probably scanned for it, it found it in a Shodan listing or something similar.
English
0
0
11
4.9K
RE:Skob
RE:Skob@re_skob·
@Xtrato how did they find the server?
English
1
0
4
5.4K
James Woolley
James Woolley@Xtrato·
@ptkatchouk They would scan for them, yes. There are also services like Shodan that can be used to find VNC servers.
English
2
0
5
1.2K
James Woolley
James Woolley@Xtrato·
@FiveOhFour @InternBerry They are both different protocols, but achieve the same thing. RDP is more Windows-based, although it can be used on Linux as well.
English
1
0
1
67
James Woolley
James Woolley@Xtrato·
@_romeopeter You won't see the commands entered into SSH on the VNC session, if that's what you mean. Unless you look at the bash history.
English
1
0
0
2.4K
Romeo
Romeo@_romeopeter·
@Xtrato So someone tell me… if I access service terminal via SSH and leave the VNC open, will it output instructions from local machine terminal?
English
2
0
1
2.7K
Alexis Paques
Alexis Paques@AlexisPaques·
@Xtrato How long was the time to first connection?
English
2
0
10
5.5K
Alex Elliott
Alex Elliott@alexpotato·
@Xtrato I’m impressed they got the tar command switches in the first try. Also, as a DevOps/SRE, you get a follow just for making this whole scenario happen.
English
16
1
275
24.6K
intern.🍓
intern.🍓@InternBerry·
@Xtrato try leaving an open RDP server next time i think you'll see more fun stuff
English
3
0
131
27.4K
Joris Mak bsky: @jorismak.nl
@Xtrato in my experience (and hacked drupal sites on my servers) they don't care if has a kind of gpu or not... it just runs, specially on servers. Every 0.01% of performance is free for them :).
English
1
0
11
2.9K
James Woolley
James Woolley@Xtrato·
@AlessandroDuico Yes they could have. Fred user runs the service. I guess they just didn't spot it 😆
English
0
0
113
19.1K
Alessandro Duico
Alessandro Duico@AlessandroDuico·
@Xtrato Why didn't they kill the ffmpeg grab? Was the fred user allowed to?
English
2
0
43
20.6K