I’ve recently dug into my firewall logs and the most traffic I seem to receive from internet is targeting port 3389.

While I could just blacklist the source IPs and call it a day, I would like to actually listen on this port and “trap” them in a fake RDP connection.

There are tools like endlessh, and I’ve found that you can do the same for http by sending an endless stream of headers. I would like to do the same for RDP, and before I start digging into the whole spec, I was wondering if there is already something similar for RDP.

Is anyone aware of that ? Is that even a thing ?

  • @[email protected]
    link
    fedilink
    51 year ago

    You’re looking for a honeypot Be careful with installing something like that with docker(or anything), docker is very unsafe

    • @kylian0087
      link
      31 year ago

      Docker is not very unsafe at all. Although something like podman would be better.

      • 520
        link
        fedilink
        11 year ago

        It’s not as safe as people expect it to be either. Container breakouts are very much a thing and not necessarily relegated to those that did something stupid in configurations

    • z3braOP
      link
      fedilink
      21 year ago

      Yeah that was my question. I never mentioned docker though ?