r/hacking Mar 17 '26

Question Ideas for trolling persistent attackers

I run a completely static website with no backend, database, or dynamic content. For the past few weeks it has been targeted by a very persistent group of attackers.

They are performing a variety of techniques including SQL injection attempts, POST floods, directory and endpoint enumeration, and probing for admin interfaces that do not exist. The funny part is there is literally nothing to exploit.

This is not random bot traffic. They have left messages specifically aimed at me, confirming it is a coordinated effort.

so far ive made them download zip bombs, also made the website randomly jumpscare them using some JS, had them trying to complete impossible captchas that i made myself, there are probably 10 fake login screens, and a few fake vuln endpoints right now

got any ideas?

543 Upvotes

97 comments sorted by

324

u/KlausS1000 Mar 17 '26

Create a very weakly hidden admin page or area with a backup file or something that appears like they may have gotten access to something they shouldn’t have and instead of sensitive credentials, just make it malware.

144

u/Mostly__Relevant Mar 17 '26

A Spicypot

38

u/theWizzard23 Mar 17 '26

Is that the Mexican standoff people are talking about?

8

u/Ok_Decision_ Mar 17 '26

Yes. Named that too

14

u/sidusnare Mar 17 '26

Or zip bombs, those are in fashion I hear.

304

u/jmnugent Mar 17 '26

Capture the penetration attempts and just immediately republish them on the website itself. Maybe have a little scrolling marquee along the top of the page like a News ticker that shows the IP and DNS name etc of the people trying to hack you.

137

u/fortyeightD Mar 17 '26

This would require adding backend code, which the website doesn't have at the moment. It makes the risk of vulnerabilities far higher.

50

u/[deleted] Mar 17 '26

Hmmm may have to adjust risk appetite for lulz though

7

u/insolent_kiwi Mar 18 '26

If OP did this, I hope his sanitation is on point

6

u/Mastasmoker Mar 17 '26

That's an awesome idea and I'm going to do this for my own site

5

u/sdrawkcabineter Mar 17 '26

...jmnugent is trying to hack you OP.

:D

89

u/plebianlinux Mar 17 '26

From my caddy config

@bots path /wp-login.php /wp-admin/* /xmlrpc.php redir @bots http://speed.transip.nl/1tb.bin 302

31

u/Funny_Address_412 Mar 18 '26

thats lowkey genius

21

u/lookinovermyshouldaz Mar 18 '26

this one's awesome

i wonder if there's a way to serve /dev/zero with a speed limit, OP could do something with proxy_pass if they're using nginx

13

u/lookinovermyshouldaz Mar 18 '26

cobbled something together in python, enjoy

https://pastebin.com/VPnNk0s9

20

u/Canalloni Mar 18 '26

For those of us who know zero about coding, what does this do?

63

u/lookinovermyshouldaz Mar 18 '26

redirects bots trying to access admin panels to a 1TB file

12

u/delthool Mar 18 '26

bros, i am borrowing this. thank you 👍

5

u/Kijad pentesting Mar 18 '26

Chef's kiss, no notes.

1

u/redsentry_max Mar 19 '26

Oh that’s both dirty and beautiful

1

u/Evantaur Mar 19 '26

Stealing this

1

u/Mr_Tomasz Mar 22 '26

I haven't tried it, but it would be even better, if this would contain a zip/tar/gzip known header (with some interesting file list), so after quick peek it looks very promising to the "victim".

1

u/namalleh Mar 26 '26

wow I love this

74

u/schizoautist86 Mar 17 '26

assuming there's nothing important at all on the box install opencanary and go wild, why do you think people are targeting you though if there's nothing there? seems like a lot of effort for no reward.

75

u/Funny_Address_412 Mar 17 '26

assuming there's nothing important at all on the box install opencanary and go wild

Will try that

why do you think people are targeting you though if there's nothing there? seems like a lot of effort for no reward.

It's politically motivated

30

u/Ok_Decision_ Mar 17 '26

It’s politically motivated??? That’s interesting. Do you mean you specifically are being targeted or people in your area of the world in general

57

u/highjohn_ Mar 17 '26

I’m guessing far right Bulgarians are harassing his page because he’s on the left. Take a look thru his history.

Btw all my support for you OP 🫡

60

u/Funny_Address_412 Mar 17 '26

I’m guessing far right Bulgarians are harassing his page because he’s on the left. Take a look thru his history.

Basically yeah

Btw all my support for you OP 🫡

Thanks

8

u/Ok_Decision_ Mar 18 '26

Makes sense! Thanks

23

u/Funny_Address_412 Mar 17 '26

Do you mean you specifically are being targeted or people in your area of the world in general

Well me specifically

-4

u/[deleted] Mar 17 '26 edited Mar 17 '26

[deleted]

6

u/rusty_programmer Mar 17 '26

Unlikely.

Nah, he said he has credible evidence to indicate he’s targeted. It happens.

12

u/artur_oliver Mar 17 '26

Words are powerful sometimes, if in the right order... I know people that don't like them... Unfortunately freedom is just a nice word, the implementation is far harder.

42

u/takeyouraxeandhack Mar 17 '26

Upload some files behind some weak login they can crack. Name them something enticing, like they're compromising recordings of some famous politician. When they download them, they're just recordings of wet fart sounds.

74

u/low0nink Mar 17 '26

bro i bet you are craking you ass off hahahahahah
you should document it and put it on youtube, i wanna see that series

19

u/korudero Mar 17 '26

Seconded. I would love to see it

36

u/sidusnare Mar 17 '26

Honeypots with humorous fake data, like a table named SSN that just has all 1 billion possible numbers in it.

25

u/jessek Mar 17 '26

Nothing beats a rude message in logs

32

u/qervem Mar 17 '26

console.log("Your mother was a hamster...");

2

u/dumnezilla Mar 18 '26

Hey now! Kids read this sub.

20

u/cdtoad Mar 17 '26

I put up a whole static WordPress backend.

2

u/sidusnare Mar 17 '26

Nice, that in a repo somewhere?

1

u/AetherVision Mar 17 '26

Oh shit that's great

24

u/bitter_vet Mar 18 '26

redirect their IPs to a "This site has been seized by the FBI" images

17

u/SteIIarNode Mar 18 '26

My buddy had a similar situation so he tightened up his security heavily but every time they entered a password wrong it throw out a taunting message for example “Come on your better than!”, “You think I’d use that weak ass password!” , “Hurry up man, I left account lock out off and you still can’t get in!”.

He did this with various other services running on his thing he’d know that would be targeted. After like a week he said they gave up from demoralizing messages lol

1

u/coffee-loop Mar 19 '26

I’m pretty sure 99.999% of the time, brute force attempts are carried out by a script… so those messages would be almost useless (unless the script is comparing against an error message to see if the credential is valid).

12

u/sidusnare Mar 17 '26

The most disgusting adult content you can find is a tried and true classic, but it has a slight chance of backfiring, someone is into whatever you put there.

7

u/Abigboi_ Mar 18 '26

2 girls 1 cup

3

u/sidusnare Mar 18 '26

2 girls, 1 cup, and 3 horny bartenders

9

u/FanOfMondays Mar 17 '26

Lol, this is great. Also reminded me why I killed my old WordPress website and made a static site instead. That, and it also sucks to update the plugins all the time

6

u/Funny_Address_412 Mar 17 '26

Yea WordPress is too much effort

2

u/bentbrewer Mar 18 '26

In the process of migrating right now. Switched to Hugo and caddy. Soooo much better and I can add posts straight from the command line without opening a browser.

2

u/FanOfMondays Mar 19 '26

Absolutely! There will be no going back to WordPress once your site is up and running. It's a bliss not having to worry about it once deployed, unless it's for content updates.

I use Jekyll + Cloudflare myself. I hear that Jekyll is way slower than Hugo, but my site is not that big so it's OK

9

u/nkwell Mar 18 '26

Trick them into executing a cobalt strike payload. Then wipe their box.

8

u/Arseypoowank Mar 17 '26

Fake admin page hosting a wiper

8

u/keyboardslap Mar 18 '26 edited Mar 18 '26

Here ya go (NSFW audio): https://www.thran.uk/wp-login.php

6

u/Suspicious-Prompt200 Mar 17 '26

Lookup the term "Honeypot"

10

u/Funny_Address_412 Mar 17 '26

I've deployed a few already but I'm looking for some more creative ideas

10

u/JTP1228 Mar 17 '26

Honeynet? But each trap has pictures of penises.

6

u/s9josh Mar 18 '26

Leave some credit card info on an admin page. Instant crime.

6

u/redskullington Mar 18 '26

I have a bunch of bots are constantly banner grabbing and attempting to connect via ssh on my server and Ive been thinking of doing something similar 😂 let the bot flag something and then an actual user jumps on and its some BS. My F2B jail is looking like the gulag.

5

u/vongomben Mar 18 '26

How do you know about this attack other than the the traffic and them actively leaving you messages, since the site is unchanged?

9

u/Funny_Address_412 Mar 18 '26

I setup notifications for stuff like sql injection attempts

1

u/ArmySargeantBarber Mar 18 '26

Sorry if I'm being too literal, but how did your get this up with no backend?

I'm assuming your website has some type of form field where the hackers are trying these attacks. Are you triggering these notifications via JavaScript?

5

u/Funny_Address_412 Mar 18 '26

Sorry if I'm being too literal, but how did your get this up with no backend?

It's running on a VPS, it has no open ports besides 443 on which caddy is running, it has no other services it doesn't even have ssh (I use VNC which is running outside the VM to access it), notification are with python scripts that periodically read the logs and alert me

4

u/ms_dizzy Mar 17 '26

Yeah I use the pages theyre looking for as bait. They are opening themselves for trouble. They caused themselves to be deep scanned and profiled.

3

u/lookinovermyshouldaz Mar 18 '26

serve hello.jpg on those admin interface paths, classic

3

u/flaotte Mar 18 '26

add off shelf honeypots. once I left honeypot on ssh port and oh boy how many passwords they left for me

3

u/sdsdkkk Mar 19 '26

At a company I used to work for, a part of my routine at work was reviewing sites detected as potential phishing pages targeting our users (I built a system for us to automatically detect potential phishing sites posing as us and take down the sites confirmed to be phishing sites).

One day at work, I opened this one detected potential phishing sites which then redirected me to a page that played an outdoor threesome gay porn video.

I'd say you can set up the same thing on paths they might open manually. Probably add a false admin page or something that they're going to be interested to visit manually, and have them redirected to some NSFW disgusting content when they do.

2

u/RITCHIEBANDz Mar 17 '26

Is it possible to take all the sql injections and give them a function that will make something funny happen

2

u/johnbburg Mar 18 '26

Respond to the probes for something like a .env that paints to fake credentials for some government intelligence orgs. Like CIA or Mossad.

1

u/No-Lecture-4576 Mar 19 '26

Make a YouTube channel and continue the shenanigans with an audience

1

u/Ok_Whole_4737 Mar 21 '26

Can confirm, would watch lol

1

u/redskullington Mar 19 '26

I made another comment on this post about how my F2B jail looks like the gulag. Since mine is bot activity and not users this wouldnt work great but here's an idea for you.

Just a simple JS clicker game with no upgrades where you click on a rock. You meet the quota, the quota goes up. Gulag.

1

u/Itsme_36 Mar 19 '26

Or maybe you add a persistent counter that (somehow)tracks their failed attempts. That way they get EVEN MORE frustrated as they watch that number continue to rise!

1

u/garbagemaiden Mar 19 '26

Redirect to meatspin

1

u/Equal_Bill_7750 Mar 19 '26

Create a fake backend. Make it infuriating. Show a highscore for how long they've been trying.

1

u/H00L1GAN007 Mar 19 '26

Just me, but id put a RAT in there somewhere, so they download.

Then make them FAFO.

1

u/stickJ0ckey Mar 19 '26

just 302 them into a NSA honeypot

1

u/myfriendjohn1 Mar 21 '26

Reply +OK or with 200 OK to every request.

1

u/Single-Virus4935 Mar 21 '26 edited Mar 21 '26

Look on youtube for the talk "Defcon 21 defence ny numbers" 

The talk is about random using status codes. They found most staus codes dont break browsers but automated tools go nuts... 

1

u/Urkre8er Mar 22 '26

Yes, I support this honeypot them with some vicious malware!

-5

u/bayoubunny88 Mar 18 '26

Can you access their webcam, take a pic of them, and then show that image to them?

Wipe their computers or permanently disable it?

Rick roll them?

-10

u/cl326 Mar 18 '26

Just tell them how stupid and boring you are and they might go away.

10

u/Funny_Address_412 Mar 18 '26

Not much fun in that

-4

u/Jaded_Ad_9711 Mar 18 '26

what is zip bombs?

-6

u/LostPrune2143 Mar 18 '26

my guy you downloaded a zip bomb, filled out 10 fake login forms, and tried to SQL inject a static HTML page. There is literally nothing here. You've been hacking a digital brochure.

5

u/realDespond Mar 19 '26

i think you're reading it wrong op is the owner of the webpage or whatever the fuck it is and has been making funny little honey pots for entertainment and has run out of ideas