back
1 comments
Yeah, that’s pretty interesting! You can also see a live view of the ASN/ISP leaderboard by going to https://knock-knock.net and choosing ISP from the carousel. That’s ordered by bot transaction count rather than IP count though.

It never ceases to amaze me that these ISPs don’t bother to shut down the botnets. They could do so very easily. For example, they could identify the IP address of every bot that hit this honeypot with their ASN with one API call: https://api.knock-knock.net/check-asn?asn=<asn number>. (See https://knock-knock.net/api). They just don’t care!

The ISP's do not have a financial incentive to shut them down. To them that's a paying customer. The feds will go after the big botnets if they are touching financial networks or siphoning enough money from people because there is usually a few big bank accounts and virtual currency exchange accounts they can seize once big enough to look good in the media. That's why it's on us and a few big CDN's to block some of them.
What if I have a slimy TV box or nasty on my phone, living on my network?

You take IP down, you kill the cancer but you also end up killing the patient.

Nothing wrong with contacting the customer, and taking down the IP briefly until the customer can deal with their malware hosting toaster.

However, I can see the argument for giving the customer 24-48 hours to resolve the problem.

Better yet, it's the only CGNAT address for a little town in Brazil. You just banned an entire town from your site.
Not the person you are asking but site operators can not tell intent. It could be something nasty on the network or a botter feigning ignorance.

I'd say its probably an acceptable casualty in the battleground that is the internet especially for little one-off sites hosting blogs, forums, chat servers, etc... For a bigger site I would expect that person may have to open a ticket with the platform such as Amazon accepting that some CDN's and firewalls may be harder to get the block removed. This is why we can't have nice things.

thats the hard part, right - my 76 year old dad is on his banking app while his samsung TV is allowing a bot to try and take over other accounts at the same bank on the same IP.

IP Blacklists, no matter how good can't stop this. You have to start using stats or deep-diving telemetry.

https://darknetdiaries.com/episode/172/

thats the hard part, right - my 76 year old dad is on his banking app while his samsung TV is allowing a bot to try and take over other accounts at the same bank on the same IP.

So appeal to emotion doesn't fly with me. If grandpa is 76 in the year of our lord 2026 that means he was 50 when the internet was getting popular and 59 when cell phones became very popular on the internet. He's not much older than I. He knows what's up.

God help the makers of that television if he finds out it has been spying on him and dorking around with his traffic. If they are lucky he will just take a baseball bat to it. If they are unlucky he will fly to their headquarters and end up on a viral bodycam video likely with a lot of supporters that will bail him out of jail.

IP Blacklists, no matter how good can't stop this. You have to start using stats or deep-diving telemetry.

I use a myriad of methods including IP blacklists. That's my choice and every site operators choice. I do not have to use deep-diving telemetry but you are free to do so.

It doesn't dork around with his traffic, it makes its own traffic. In exchange for a discount.