SIEGE IN PROGRESS · LIVE
The gates hold.
Every bot that knocks on a door it shouldn't is marked, logged, and reported. These are the attackers at the wall, right now.
THE FALLEN0
TARPIT
The field is quiet. No raiders yet.
Knight = login attack
Thief = secret hunter (.env, .git)
Forger = email spoofer (forged seal)
Brute = one bot that keeps coming back
Scout = probing for scripts (.php)
Sinks = caught in tarpit
Ghost = reported to AbuseIPDB
–Attackers at the wall today
–Reported to AbuseIPDB
–Traps sprung all-time
–Lands sending raiders
–Bot time wasted in the tarpit
Siege map
where the raiders march fromSiege log
updates every 30 secondsTIME
LAND
ATTACKER
ABUSE SCORE
WEAPON (TRAP HIT)
FATE
The Dungeon
One cell for each land. The more bots a country sends, the fuller its cell gets.
PRISONERS: 0
The Treasury
The keys raiders try at the fake gates. Every one of them is wrong.
– keys tried
– thieves
– different passwords
Most-tried usernames
Most-tried passwords
Favorite combos
Keys only one attacker has tried are partly hidden, in case a real person typed a real password. They show in full once a second attacker tries them.
Honored Guests
Good bots that read the rules and keep to the open roads. They're welcome here, and never reported.
The road is quiet. No guests yet.
GATE CHECK
–Guest visits
–Different guests
–Read robots.txt first
–Last guest
–Impostors turned away
–Most impersonated
Rules of the Keep
- The rules are posted. Every forbidden door is listed in robots.txt, the file well-behaved bots read before they visit.
- Travelers are counted, never logged. People browsing the keep are welcome. The Tavern counts who's here using only a country and a random ID for each open tab, never an address, and forgets them within two days. Travelers are never reported.
- Honored guests are welcome. Search engines and other verified good bots follow the rules, so they're greeted, not reported.
- Raiders are reported. No visible link leads to the forbidden doors. A bot that opens one went looking for it and ignored the posted rules, so it's logged and reported to AbuseIPDB right away.
- One report at a time. The same raider is reported at most once every 15 minutes. If it comes back sooner, the hit is still logged but marked "Repelled."
- Shared with the realm. Each night, the day's raiders are sent to AlienVault OTX, and the last 7 days are in the public blocklist.
Traps on the wall
Doors no real visitor ever opens. Only a bot goes looking for them, so anyone who does is an attacker.
/wp-login.phpFake WordPress login.
/.envFake config file full of fake keys. Bots love it.
/.git/configLooks like an exposed code repo.
/phpmyadmin/Fake database admin panel.
/xmlrpc.phpOld WordPress endpoint, now a tarpit.
/actuator/envFake Java app debug page.
/backup.zipEndless slow download that wastes the bot's time.
/adminGeneric admin doors that don't exist.
/cgi-bin/, /server-statusClassic old-server probes.
robots.txt → /secret-vault/Listed as "forbidden." Bad bots go straight there.
Hidden linkInvisible to people; crawlers follow it.
Fake form fieldA hidden field only bots fill in.
/.aws/credentialsFake cloud keys. Among the most-scanned files online.
/wp-config.php.bakA "forgotten" WordPress backup with fake database login.
/config.jsonFake app secrets, served with a smile.
VPN and firewall loginsFake remote-access portals at the addresses scanners hit most. Every password tried goes to the Treasury.
Any .php fileThis keep runs no PHP at all, so anything asking for a .php file is a bot. Same for .asp, .jsp and .cgi.
Run a firewall? Every attacker from the last 7 days is in the public blocklist.txt, one IP per line.