Hacker News new | ask | show | jobs
by duskwuff 2802 days ago
Eh, it depends on how it's exposed.

I used to run a Kippo[1] honeypot on port 22. I'd regularly see automated intrusion attempts, often followed up by users manually interacting with the server (and slowly coming to realize that it was fake). Nowadays I expect the exploitation process is typically much more automatic, so it'd be less interesting to watch.

[1]: https://github.com/desaster/kippo