<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: F4LCON</title>
    <description>The latest articles on DEV Community by F4LCON (@f4lcon).</description>
    <link>https://dev.to/f4lcon</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4150771%2F650be44b-4cc2-4ba2-80bd-aa3ac45a16e3.jpg</url>
      <title>DEV Community: F4LCON</title>
      <link>https://dev.to/f4lcon</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/f4lcon"/>
    <language>en</language>
    <item>
      <title>Building a Real Time Attack Visualizer: SSH Honeypot and Cloudflare Workers</title>
      <dc:creator>F4LCON</dc:creator>
      <pubDate>Tue, 29 Sep 2026 18:41:47 +0000</pubDate>
      <link>https://dev.to/f4lcon/building-a-real-time-attack-visualizer-ssh-honeypot-and-cloudflare-workers-3104</link>
      <guid>https://dev.to/f4lcon/building-a-real-time-attack-visualizer-ssh-honeypot-and-cloudflare-workers-3104</guid>
      <description>&lt;p&gt;Every second, bots scan the internet for open SSH ports. I wanted to see exactly what they were doing, so I built a honeypot that catches them all and puts them on a live world map.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;HIVE&lt;/strong&gt; is a low-interaction honeypot written in Rust. A small sensor pretends to be an SSH server and a forgotten nginx box. Bots find it on their own. Every login attempt and web probe goes to a Cloudflare Worker, and the map at &lt;a href="https://xivlabs.tech" rel="noopener noreferrer"&gt;xivlabs.tech&lt;/a&gt; shows them as they happen.&lt;/p&gt;

&lt;p&gt;Right now it's catching around 7000 attempts a day from ~130 unique IPs. The most-tried password is &lt;code&gt;123456&lt;/code&gt;.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F9b3t8veezexv31hp6vjg.gif" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F9b3t8veezexv31hp6vjg.gif" alt="Live SSH attempts hitting the honeypot"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  How it works
&lt;/h2&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;bots ──▶ :22 / :80
           │
           ▼
      hive-sensor (Rust, VM)
      counts every event, hourly buckets on disk
           │  1 signed request/min
           ▼
      hive Worker (Rust/WASM)
           │
           ▼
      D1  ──▶ /stats, /recent (30s edge cache) ──▶ xivlabs.tech
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The sensor runs on an Oracle Cloud Always Free VM. The Worker runs on Cloudflare's free tier. The whole thing costs nothing to run.&lt;/p&gt;

&lt;h2&gt;
  
  
  The interesting constraint
&lt;/h2&gt;

&lt;p&gt;Cloudflare's free plan allows 100k D1 row writes per day across the whole account. A public port 22 can draw tens of thousands of attempts a day, so one row per attempt would burn the quota and break every other project on the account.&lt;/p&gt;

&lt;p&gt;So the sensor does the counting instead. It keeps hourly buckets in memory for 7 days, saves them to &lt;code&gt;stats.json&lt;/code&gt; so restarts don't lose history, and caps distinct keys per bucket so memory stays bounded. Once a minute it ships a single signed request with the stats snapshot and the 10 newest events. The Worker upserts one snapshot row, inserts those events, and prunes the feed back to 500 rows.&lt;/p&gt;

&lt;p&gt;That's about 21 rows written per minute — roughly 30k a day — no matter how hard the honeypot gets hit. &lt;code&gt;/stats&lt;/code&gt; reads one row, &lt;code&gt;/recent&lt;/code&gt; reads only what it returns, both behind a 30s edge cache.&lt;/p&gt;

&lt;h2&gt;
  
  
  Nobody gets in
&lt;/h2&gt;

&lt;p&gt;This is the part people ask about first:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;No shell.&lt;/strong&gt; Every SSH login is rejected. There's no channel, no command execution. The HTTP side never reads request bodies and always returns the same static page.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Bounded.&lt;/strong&gt; 256 open connections max (10 per IP), 30–60s session limits, capped string lengths, and an in-memory queue that drops the oldest events when full.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Sandboxed.&lt;/strong&gt; Runs as an unprivileged &lt;code&gt;hive&lt;/code&gt; user under systemd with a read-only filesystem, no new privileges, and a syscall filter. &lt;code&gt;systemd-analyze security&lt;/code&gt; exposure: 1.5. It gets &lt;code&gt;CAP_NET_BIND_SERVICE&lt;/code&gt; only, to bind ports 22 and 80.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Isolated.&lt;/strong&gt; Its own VM. Not a home network, not a box holding anything else.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Privacy
&lt;/h2&gt;

&lt;p&gt;The live map and the public API only show masked networks (&lt;code&gt;203.0.113.x&lt;/code&gt;) and countries. Full addresses leave the VM only for the blocklist: anything that hit the honeypot at least 3 times in 7 days gets shipped hourly, kept in one D1 row behind an authenticated &lt;code&gt;/export&lt;/code&gt;, and published every Monday to &lt;a href="https://github.com/itsF4LCON/hive-blocklist" rel="noopener noreferrer"&gt;hive-blocklist&lt;/a&gt; in iptables, nginx and plain-text formats. Private and reserved ranges are never listed.&lt;/p&gt;

&lt;h2&gt;
  
  
  The API
&lt;/h2&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Endpoint&lt;/th&gt;
&lt;th&gt;What&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;GET /stats&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;24h/7d totals, unique sources, top usernames, passwords, paths, countries, user agents, map points&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;GET /recent?limit=50&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Latest events (max 100)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;GET /export&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Bearer-auth. Snapshot + blocklist, used by the weekly Action&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;POST /ingest&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Sensor only. HMAC-SHA256 signed, 5-minute clock skew window&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;Public endpoints are cached at the edge for 30s and only send CORS headers to allowed origins.&lt;/p&gt;

&lt;h2&gt;
  
  
  Try it
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Live map:&lt;/strong&gt; &lt;a href="https://xivlabs.tech" rel="noopener noreferrer"&gt;xivlabs.tech&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Source:&lt;/strong&gt; &lt;a href="https://github.com/itsF4LCON/hive" rel="noopener noreferrer"&gt;github.com/itsF4LCON/hive&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Blocklist:&lt;/strong&gt; &lt;a href="https://github.com/itsF4LCON/hive-blocklist" rel="noopener noreferrer"&gt;github.com/itsF4LCON/hive-blocklist&lt;/a&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The README has full setup instructions if you want to run your own. It takes about 20 minutes on a free Oracle VM.&lt;/p&gt;

&lt;p&gt;If you've run a honeypot before, I'd like to hear what you did with the data — the blocklist is the obvious use, but there's a lot more in there.&lt;/p&gt;

</description>
      <category>cloudflare</category>
      <category>rust</category>
      <category>security</category>
      <category>honeypot</category>
    </item>
  </channel>
</rss>
