cernec1999 / ssh-honeypot

5 stars 1 forks source link

Add flag to db if connection is a Tor exit node #22

Closed cernec1999 closed 3 years ago

cernec1999 commented 4 years ago

Issue Summary

From testing, I see a lot of traffic from Tor exit nodes. Apparently, these nodes are brute forcing SSH servers and trying to forward their exit node traffic through exposed SSH servers over the internet.

We should implement the Tor exit node list (https://check.torproject.org/torbulkexitlist) and have an option to block traffic from here. Additionally, we should add a flag to the DB if it is a tor exit node.

cernec1999 commented 4 years ago

Tor exit node user accessing sport betting website IP Address of the connection

The connection depicted also accessed pornographic content (on a popular, legal pornographic website), but I am not going to share the HTTP response from that.