Article may be outdated

This article is 86 days old. Some details may have changed since publication.

Hacker News·4 min read·hard

TFTP Honey Pot Results

S
speckx
✦AI Summary

A security researcher analyzed traffic captured by a TFTP honey pot, finding that the vast majority of probes originated from automated scans by cybersecurity companies rather than malicious actors. The author details the technical challenges of identifying and categorizing these repetitive, daily network requests.

Why it matters

This provides insight into the noise levels in cybersecurity monitoring and the prevalence of automated scanning by infosec firms.

✦Dive DeeperCreate a free account to unlock

2026-07-12 (Last Modified: 2026-07-13) My TFTP honey pot has been running for over a month, continuously on my $5 a month VPS, and intermittently on my Dell R530 home server. It's time to see what surprises it has captured.

When the TFTP honey pot runs, both servers see between 20 and 50 TFTP packets per day. Both servers see mostly the same traffic. I was extremely excited when I got daily UDP port 69 traffic, most of it in TFTP format. I was let down when I realized most of the traffic was regularly scheduled scans from seven infosec companies.

Continue reading on Headlinne

Create a free account to read the full article.

Read full article →
technologyscience
✦

Get smarter about the news

Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.

Create free account

Already have an account? Sign in