Live SSH honeypot dashboard streams botnet login attempts as they happen
A new Show HN project, HoneypotLive, exposes an SSH honeypot’s telemetry through a real-time web dashboard. Visitors can watch inbound automated attacks as they arrive, seeing the source IPs, username and password guesses, client fingerprints, and the commands attackers try to run once they think they’ve landed on a real shell. It functions as a live window into the constant background noise of internet-wide credential stuffing and botnet reconnaissance.
The operator frames the tool as a resource for threat intelligence, research, and education rather than attribution. Their notice stresses that a source IP rarely points to the actual attacker: connections typically originate from compromised hosts, proxies, VPNs, scanners, cloud instances, or botnet nodes. The captured data is also explicitly untrusted — it can include attacker-supplied credentials, URLs, public keys, and malware delivery attempts — so nothing on the dashboard should be treated as verified or as safe-to-run code.
The project’s value is largely illustrative. It makes the scale and mechanics of automated SSH abuse tangible for a technical audience, while the accompanying privacy and abuse-reporting language reflects the practical and ethical care required when publishing live attacker telemetry that may contain sensitive or malicious content.
Read the full article
Continue reading at Hacker News →This is an AI-generated summary. Read the original for the full story.