How to Trick Hackers & Web Crawlers with Spidertrap

  Рет қаралды 45,462

John Hammond

John Hammond

11 ай бұрын

j-h.io/pwyc || Jump into Pay What You Can training for Active Defense & Cyber Deception -- at whatever cost makes sense for you! j-h.io/pwyc
🔥 KZbin ALGORITHM ➡ Like, Comment, & Subscribe!
🙏 SUPPORT THE CHANNEL ➡ jh.live/patreon
🤝 SPONSOR THE CHANNEL ➡ jh.live/sponsor
🌎 FOLLOW ME EVERYWHERE ➡ jh.live/discord ↔ jh.live/twitter ↔ jh.live/linkedin ↔ jh.live/instagram ↔ jh.live/tiktok
💥 SEND ME MALWARE ➡ jh.live/malware

Пікірлер: 56
@jmr
@jmr 11 ай бұрын
I'm adding this to my honeypot.
@walturowhite69
@walturowhite69 11 ай бұрын
Yes please.
@Meletion1
@Meletion1 8 ай бұрын
Second comment on verified 3 letter username 2 months really?
@jmr
@jmr 8 ай бұрын
@@Meletion1 What does that mean?
@aaronflippens2149
@aaronflippens2149 11 ай бұрын
The hacker tears😢
@theCuriousMindsCollective
@theCuriousMindsCollective 11 ай бұрын
Love the simplicity of this script :D. I think this idea is like an April 1 gift for script kiddies. Nice content, by the way. :)
@jjann54321
@jjann54321 11 ай бұрын
I'm still holding out for the *Hack Like Hammond* training camp. C'mon, it's even catchy, do it, do it, do it. Great video as always!
@tomaeduard9891
@tomaeduard9891 11 ай бұрын
The PoC seems ok, but you'd have to think about that a crawler that gets stuck in your domain might be causing other issues like unintentional DoS, especially on low resource machines.
@PostMeridianLyf
@PostMeridianLyf 11 ай бұрын
I think the point was to slow the threat actor so that you have time to make decisions, like blocking the same recurring ip making the request or throttling. By that time you should be bale to work on prevention
@_..-_-.._
@_..-_-.._ 11 ай бұрын
maybe bypassable by matching only pages having a specific word in page src code .(u'll definitely get a word that appears on all true pages and not on fake ones) , it could also be bypassed by response time filtering (fake pages will load much faster). ffuf -mr(match regex)/-ft (response time filter) ....
@ariseyhun2085
@ariseyhun2085 10 ай бұрын
I think it would make sense to add a delay for the fake pages, such as 1 second to load, would make it way slower for the pages to be crawled
@sulcy_techtips3622
@sulcy_techtips3622 11 ай бұрын
Thanks a John I really appreciate all your videos highly informative
@spaniardspqr
@spaniardspqr 10 ай бұрын
This was neat, Thank you!
@user-lf3qv3rp9i
@user-lf3qv3rp9i 11 ай бұрын
On burp you can see the Page Lenght and notice that you're on a tool quickly. Light pages dont call much attention, specially with a page that only contain anchors.
@jasonpreston2703
@jasonpreston2703 11 ай бұрын
I had an idea but too many ongoing rn. Basically the idea was that if it detected someone was crawling it would start injecting hidden links that go to an endpoint that returns a location header sending malicious get requests to internal ips. Eg known router exploits. I was thinking of making it as a flask module just as a fun project I'm not sure of the legality of writing and publishing it anyway since it would be illegal to deploy
@mohammedissam3651
@mohammedissam3651 11 ай бұрын
That is sick man Cyber Deception I like that You could use triggers in the database whenever any of the links clicked a notification will be send to the operator meaning we are under attack also enhance the look of the site 😂 Nice camouflage tool good stuff Thanks for sharing 😊
@AntiAtheismIsUnstoppable
@AntiAtheismIsUnstoppable 11 ай бұрын
I understand the idea, and I will investigate how much power my server needs to do this stuff. Because I am currently just giving evil bots a blank page with random status codes. I think those tools are very dependent on status codes, right? So, if the status codes are random, will they give useful results? But I will find out which takes less power. Thanks for the advice.
@lancemarchetti8673
@lancemarchetti8673 11 ай бұрын
This may be cool to deter indiscriminate site scrapers, but last week wget helped me grab a php script for a website service that slices images online, and I really needed to see how the tool was scripted. General website cloners struggle to retrieve most php files. But wget saved my day Yay!
@jeremyparker9394
@jeremyparker9394 11 ай бұрын
Loving The content .. 🎉 good show
@kaitotaro5994
@kaitotaro5994 10 ай бұрын
Thank you for the amazing content. Note: On-Demand courses are not available as Pay-What-You-Can course offerings. Says unfortunately.
@manisharrora9525
@manisharrora9525 11 ай бұрын
Hey John kindly teach us how to do the malware analysis of a PE file that will be very helpful.
@techwithantics
@techwithantics 11 ай бұрын
Cool one
@kodeish
@kodeish 11 ай бұрын
CORS fetch data from different websites and API is also doing the same, then what's the different between in this two?
@anonp2958
@anonp2958 11 ай бұрын
Great concept, however, would running SpiderTrap not be open to being abused by an attacker via a DOS attack? Constantly creating new sites multiplied by however many threads would use up a lot of resources.
@franciscopena7859
@franciscopena7859 11 ай бұрын
Just resource limit it, limit cpu and ram on containers or vm size. You could probably port this easily to go
@franciscopena7859
@franciscopena7859 11 ай бұрын
Going further block ips per networking quota, just the usual
@logiciananimal
@logiciananimal 11 ай бұрын
I assume that wget actually has a "maximum" setting of some sort or other; dynamic vulnerability scanners like ZAP or the like do precisely because of tools like Spidertrap (and also because of designs that might result in loops that are not detected). (Never let beginning developers build a spider - there are just so many ways that it can go wrong.)
@jmr
@jmr 11 ай бұрын
Cat and mouse game. 🤷‍♂️
@neiltropolis
@neiltropolis 11 ай бұрын
Well good thing I'm not a developer, my spider should be just fine 😅
@randomlegend631
@randomlegend631 11 ай бұрын
Good stuffs
@perryuploads776
@perryuploads776 11 ай бұрын
If you use a spidertrap , then you are more interesting for hackers. They will think, what are you hiding sir? Sometimes it is best to do nothing, just listen. Every force you create has an echo. Your own bad energy will be your undoing - Gogeta SSJ2. Don't annoy hackers, let them scan, just learn and mitigate. Just leave everything normal. Make it seems normal, there is nothing to see here, that is the key. Think like a firewall, are you doing to annoy (infinite loop), deny (send mesage back) or drop (ignore). Just drop and leave it, continue your life. Thanks for the great video!
@jjann54321
@jjann54321 11 ай бұрын
Or, spin up a "free" *cloud* webserver that's not sitting on your home/business network, have fun and live life. If you can make something "work" and learn something why wouldn't you? Not everything has to be sanitized and cold. Just food for thought, but your point is valid.
@user-lt2rw5nr9s
@user-lt2rw5nr9s 11 ай бұрын
I agree. If you had a regular webserver up, maybe a minimal landing page, it would seem like any other server. If you cause their scanner to get stuck or have a false positive, you're making yourself stand out. It acts as a puzzle that's going to peak their curiosity. In my opinion, I'd prefer an IP ban after x words in dirbuster or x junk links followed.
@neiltropolis
@neiltropolis 11 ай бұрын
I'm on the fence about your comment. On one hand your building a moat around your castle, and this will draw unwanted attention to people who are up for a fight. So your saying to not piss off the enemy as for fear of attack? I'm not the quickest of cat's so go easy on me. I mean if they (5 eyes) wants to know who did what, I think they can figure it out. No one has flown anymore jets into buildings since the last time for a reason.
@MikeInAble
@MikeInAble 11 ай бұрын
This seems reasonable for public facing servers, but in my case I'm part of an internal blue team and if someone is already inside our network doing scans, then I think we are past that point and anything to slow them down and detect their presence would be of more benefit.
@darshanakhare6676
@darshanakhare6676 11 ай бұрын
Notifications after comment
@ycart_tech6726
@ycart_tech6726 11 ай бұрын
To make it absolutely clear, those links don't actually have to be interpreted into the version of the website our user navigates on, right?
@xsploit
@xsploit 11 ай бұрын
i wonder if shodan crawlers would get stuck
@castercs
@castercs 11 ай бұрын
Pay what you can is only .. when its LIVE training .. not on demand .. so u kind of have to wait
@Gunzmo
@Gunzmo 9 ай бұрын
I've built something like this in php a long time ago.
@terraflops
@terraflops 11 ай бұрын
> Having used Scrapy Python web crawler
@MrEndzo
@MrEndzo 11 ай бұрын
Sometime I feel like I'm in an infinite loop.
@ahr0cdovlzk3my1lahqtbmftdw7
@ahr0cdovlzk3my1lahqtbmftdw7 11 ай бұрын
If you try to download the content of the web page with wget, it will only work until the entire word list has been downloaded. This is not a real loop at all
@taywinkarroon5470
@taywinkarroon5470 11 ай бұрын
cool stuf
@Mitch-xo1rd
@Mitch-xo1rd 11 ай бұрын
Me creating 300 of these on sub-domains to troll google
@beyblade3331
@beyblade3331 11 ай бұрын
filter results to website content in fuff it'd be -fw
@ReligionAndMaterialismDebunked
@ReligionAndMaterialismDebunked 11 ай бұрын
Early. :3
@balloney2175
@balloney2175 11 ай бұрын
Sorry, but I just don't get it. What is the purpose of this app? Will someone explain to me in plain English?
@kingkong1040
@kingkong1040 11 ай бұрын
don't forget to block legit robots from crawling these so it doesn't destroy your SEO/rankings lol
@ThisIsJustADrillBit
@ThisIsJustADrillBit 11 ай бұрын
Dope
@PabloPazosGutierrez
@PabloPazosGutierrez 11 ай бұрын
The idea is pretty basic, what would be useful is to return valid content for script kiddies looking for WordPress vulnerabilities or doing SQL injection then give them BS data.
@nrvous67
@nrvous67 11 ай бұрын
hahh hacker cries :)
@GameWithSNAKE
@GameWithSNAKE 11 ай бұрын
I am 999 liker 🙌 by the way thank 👍
@cerilza_kiyowo
@cerilza_kiyowo 11 ай бұрын
First
@mindout3492
@mindout3492 11 ай бұрын
Can software engineer become a Hacker with self study ?? 🤖
"Please Hack My Computer"
17:50
John Hammond
Рет қаралды 1 МЛН
Web Crawling vs. Web Scraping: The battle for data extraction dominance!
6:11
Jelvix | TECH IN 5 MINUTES
Рет қаралды 58 М.
Backstage 🤫 tutorial #elsarca #tiktok
00:13
Elsa Arca
Рет қаралды 44 МЛН
Must-have gadget for every toilet! 🤩 #gadget
00:27
GiGaZoom
Рет қаралды 7 МЛН
MEU IRMÃO FICOU FAMOSO
00:52
Matheus Kriwat
Рет қаралды 19 МЛН
How To Pivot Through a Network with Chisel
33:45
John Hammond
Рет қаралды 120 М.
how hackers hack any websites in minutes?!
23:17
Loi Liang Yang
Рет қаралды 219 М.
The A to Z Uses & Abuses Of Python In The Hacking World.
9:46
Chill Circuit
Рет қаралды 468
Where People Go When They Want to Hack You
34:40
CyberNews
Рет қаралды 1,1 МЛН
a Hacker's Backdoor: Service Control Manager
17:49
John Hammond
Рет қаралды 91 М.
Fileless Malware Analysis & PowerShell Deobfuscation
26:42
John Hammond
Рет қаралды 47 М.
I Stole a Microsoft 365 Account. Here's How.
19:57
John Hammond
Рет қаралды 329 М.
Hunt for Hackers with Velociraptor
13:51
John Hammond
Рет қаралды 93 М.
How do hackers get caught? - the hunt for the hacker.
13:07
Grant Collins
Рет қаралды 91 М.
The Hidden Secrets of Alien Resurrection on the PS1
11:02
Modern Vintage Gamer
Рет қаралды 599 М.
Backstage 🤫 tutorial #elsarca #tiktok
00:13
Elsa Arca
Рет қаралды 44 МЛН