unauth

Live honeypot

Bot watch

We keep a box on the internet running Ollama, n8n and Langfuse with no authentication — the exact misconfigurations this scanner flags. Nobody uses it. Everything below is unsolicited traffic from bots and attackers. Updated every 15 minutes.

Last probe

3 hours ago

against ollama · data updated 5 minutes ago

1715
probes today
1715
probes this week
1715
since counting began
27
ssh attackers this week

Probes per day · last 7 days

Ollama + n8n + Langfuse probes. SSH brute-force sources counted separately (27 this week).

Top requested paths

  1. /\etc/passwd768 variants768
  2. /\etc/passwd%00.jpg192 variants192
  3. /\etc/passwd%00index.htm192 variants192
  4. /\etc/passwd%23vt/test192 variants192
  5. /\\\\\\%u0020../%u0020../%u0020../%u0020../%u0020../%u0020../etc/passwd64 variants64
  6. /\\\\\\%u002e%u002e/%u002e%u002e/%u002e%u002e/%u002e%u002e/%u002e%u002e/%u002e%u002e/etc/passwd32 variants32
  7. /\\\\\\%u002e./%u002e./%u002e./%u002e./%u002e./%u002e./etc/passwd32 variants32
  8. /\\\\\\%u002e%u002e%u002f%u002e%u002e%u002f%u002e%u002e%u002f%u002e%u002e%u002f%u002e%u002e%u002f%u002e%u002e%u002fetc/passwd28 variants28
  9. /\\\\\\%u002e%u002e%u005c%u002e%u002e%u005c%u002e%u002e%u005c%u002e%u002e%u005c%u002e%u002e%u005c%u002e%u002e%u005cetc/passwd28 variants28
  10. /\\\\\\%u0020../%u0020../%u0020../%u0020../%u0020../%u0020../etc/passwd%00.jpg16 variants16

Top user agents

  1. Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36; ClaudeBot/1.0; +claudebot@anthropic.com)3

What you're looking at

A small VM running default, unauthenticated installs of Ollama (:11434), n8n (:5678) and Langfuse (:3000) — no honeypot trickery, just the same setup mistakes teams make by accident. The counts above come from the services' own request logs. Source IPs are never stored or shown; we keep only timestamp, service, method, path and user agent.

One caveat: Ollama's access log doesn't record user agents, and Langfuse only logs failed requests — so the real numbers are higher than what you see here.

Think yours is safer?

Scan your stack