Honeypot Recon: New Variant of SkidMap Targeting Redis
ARTICLESAn unauthenticated Redis instance, a base64 cron job, and a rootkit-equipped cryptominer that ClamAV walked straight past.
When an idea pops into
my head and keeps me awake at night, I know I have to
explore it further, no matter how much time it takes. Quite
a few projects are waiting to be finished or to overcome the
next barriers. Some of them I'll never finish. But I like to
dig deep, sometimes off course, and those crazy things I
stumble upon along the way are usually the best bit. I
suppose it's this journey that says the most about me.
An unauthenticated Redis instance, a base64 cron job, and a rootkit-equipped cryptominer that ClamAV walked straight past.
Six countries, nine database engines, four months of data - and one engine absorbing over 93% of every login attempt.
Two PyPI packages impersonated popular libraries with a single lookalike character, then harvested SSH and GPG keys.
Radek Zdonczyk's notebook - professional cybersecurity, hardware hacking, a bit of SDR radio in spare time, learning, curiosity and the countless ideas that develop from it all.
Over twelve years in cybersecurity: security engineering, threat hunting and malware analysis. Hardware since I was a kid. Lately, AI agents that break other agents. It all lands here - dead ends, science, champagne and everything in between.