SIEGE LOG
SIEGE IN PROGRESS · LIVE

The gates hold.

Every bot that knocks on a door it shouldn't is marked, logged, and reported. These are the attackers at the wall, right now.

Knight = login attack Thief = secret hunter (.env, .git) Forger = email spoofer (forged seal) Brute = one bot that keeps coming back Scout = probing for scripts (.php) Sinks = caught in tarpit Ghost = reported to AbuseIPDB
–Attackers at the wall today
–Reported to AbuseIPDB
–Traps sprung all-time
–Lands sending raiders
–Bot time wasted in the tarpit

Siege map

where the raiders march from

Siege log

updates every 30 seconds
TIME
LAND
ATTACKER
ABUSE SCORE
WEAPON (TRAP HIT)
FATE

The Dungeon

One cell for each land. The more bots a country sends, the fuller its cell gets.

The Treasury

The keys raiders try at the fake gates. Every one of them is wrong.

– keys tried – thieves – different passwords

Most-tried usernames

    Most-tried passwords

      Favorite combos

        Keys only one attacker has tried are partly hidden, in case a real person typed a real password. They show in full once a second attacker tries them.

        Honored Guests

        Good bots that read the rules and keep to the open roads. They're welcome here, and never reported.

        –Guest visits
        –Different guests
        –Read robots.txt first
        –Last guest
        –Impostors turned away
        –Most impersonated

        Rules of the Keep

        1. The rules are posted. Every forbidden door is listed in robots.txt, the file well-behaved bots read before they visit.
        2. Travelers are counted, never logged. People browsing the keep are welcome. The Tavern counts who's here using only a country and a random ID for each open tab, never an address, and forgets them within two days. Travelers are never reported.
        3. Honored guests are welcome. Search engines and other verified good bots follow the rules, so they're greeted, not reported.
        4. Raiders are reported. No visible link leads to the forbidden doors. A bot that opens one went looking for it and ignored the posted rules, so it's logged and reported to AbuseIPDB right away.
        5. One report at a time. The same raider is reported at most once every 15 minutes. If it comes back sooner, the hit is still logged but marked "Repelled."
        6. Shared with the realm. Each night, the day's raiders are sent to AlienVault OTX, and the last 7 days are in the public blocklist.

        Traps on the wall

        Doors no real visitor ever opens. Only a bot goes looking for them, so anyone who does is an attacker.

        /wp-login.phpFake WordPress login.
        /.envFake config file full of fake keys. Bots love it.
        /.git/configLooks like an exposed code repo.
        /phpmyadmin/Fake database admin panel.
        /xmlrpc.phpOld WordPress endpoint, now a tarpit.
        /actuator/envFake Java app debug page.
        /backup.zipEndless slow download that wastes the bot's time.
        /adminGeneric admin doors that don't exist.
        /cgi-bin/, /server-statusClassic old-server probes.
        robots.txt → /secret-vault/Listed as "forbidden." Bad bots go straight there.
        Hidden linkInvisible to people; crawlers follow it.
        Fake form fieldA hidden field only bots fill in.
        /.aws/credentialsFake cloud keys. Among the most-scanned files online.
        /wp-config.php.bakA "forgotten" WordPress backup with fake database login.
        /config.jsonFake app secrets, served with a smile.
        VPN and firewall loginsFake remote-access portals at the addresses scanners hit most. Every password tried goes to the Treasury.
        Any .php fileThis keep runs no PHP at all, so anything asking for a .php file is a bot. Same for .asp, .jsp and .cgi.

        Run a firewall? Every attacker from the last 7 days is in the public blocklist.txt, one IP per line.