The author describes a collection of defensive-offensive techniques deployed on their VPS to deter automated scanners and bots, including fake WordPress logins, endlessh SSH tarpitting, TFTP honey pots, fake web pages, and LLM prompt poisoning. They argue that if even 10% of internet machines adopted similar offensive postures, the cost of automated scanning would rise enough to deter 'bottom feeders.' The piece also mentions potential future additions like SMTP/Telnet/FTP honey pots and a full WordPress honeypot.
Background
Automated scanning and bot traffic is a persistent problem for website operators, with billions of malicious requests daily targeting vulnerabilities, scraping content, and attempting credential stuffing. Techniques like endlessh (an SSH tarpit) and honeypots have existed for years but are rarely discussed as a coordinated defensive strategy.
- Source
- Lobsters
- Published
- Aug 5, 2026 at 08:34 PM
- Score
- 5.0 / 10