Live honeypot
Bot watch
We keep a box on the internet running Ollama, n8n and Langfuse with no authentication — the exact misconfigurations this scanner flags. Nobody uses it. Everything below is unsolicited traffic from bots and attackers. Updated every 15 minutes.
Last probe
3 hours ago
Probes per day · last 7 days
Ollama + n8n + Langfuse probes. SSH brute-force sources counted separately (27 this week).
Top requested paths
- /\etc/passwd768 variants768
- /\etc/passwd%00.jpg192 variants192
- /\etc/passwd%00index.htm192 variants192
- /\etc/passwd%23vt/test192 variants192
- /\\\\\\%u0020../%u0020../%u0020../%u0020../%u0020../%u0020../etc/passwd64 variants64
- /\\\\\\%u002e%u002e/%u002e%u002e/%u002e%u002e/%u002e%u002e/%u002e%u002e/%u002e%u002e/etc/passwd32 variants32
- /\\\\\\%u002e./%u002e./%u002e./%u002e./%u002e./%u002e./etc/passwd32 variants32
- /\\\\\\%u002e%u002e%u002f%u002e%u002e%u002f%u002e%u002e%u002f%u002e%u002e%u002f%u002e%u002e%u002f%u002e%u002e%u002fetc/passwd28 variants28
- /\\\\\\%u002e%u002e%u005c%u002e%u002e%u005c%u002e%u002e%u005c%u002e%u002e%u005c%u002e%u002e%u005c%u002e%u002e%u005cetc/passwd28 variants28
- /\\\\\\%u0020../%u0020../%u0020../%u0020../%u0020../%u0020../etc/passwd%00.jpg16 variants16
Top user agents
- Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36; ClaudeBot/1.0; +claudebot@anthropic.com)3
What you're looking at
A small VM running default, unauthenticated installs of Ollama (:11434), n8n (:5678) and Langfuse (:3000) — no honeypot trickery, just the same setup mistakes teams make by accident. The counts above come from the services' own request logs. Source IPs are never stored or shown; we keep only timestamp, service, method, path and user agent.
One caveat: Ollama's access log doesn't record user agents, and Langfuse only logs failed requests — so the real numbers are higher than what you see here.
Think yours is safer?
Scan your stack