Stood up a fresh honeypot in Madrid, pointed a domain I registered in 2008 at it, and just watched. 36 hours in, my logs are full of domain-name-flavored usernames and passwords, generously seasoned with 2008, 2009, 2010, all the way to 2030 and other years that line up a little too well with when I actually regisstered the thing. I did not publish my registration date anywhere. The bots found out anyway and are now trying it as both a username AND password, just to cover their bases. Efficient. Rude. Efficient. Something in the pipeline is pulling WHOIS data and using domain age as a password hint. Not earth shattering, not life changing, but in just about a day you start to see the patterns. Now I will wait to see the payloads they drop and further exploration of the 2 additional "hosts" connected to this little decoy. What are you doing on this fabulous Wednesday? yes yes, so I'm a nerd - I admit it. And you? Will you admit it too? Do you also have a friendly Flamingo helping set these up? #cybersecurity #Infosec #honeypot #nerd #SashaTheFlamingo @sashatheflamingo@infosec.exchange