Get the latest tech news
Ping Storms at GreyNoise
GreyNoise has been seeing crazy noise storms full of pings for years. I may have figured out what some of them are.
Basically, they watch and monitor activity that hits lots of hosts randomly – network mapping, port scanning, doorknob rattling. Don’t get me wrong – I love the idea, and have already imagined a half-dozen approaches using pseudorandom keystreams and encrypted data… But if I can come up with a much better way to do this, then anything that actual, professional, you know, SPIES, could do, would probably not be something we’d even notice. I spent some time trying to get them to show up in Wireshark itself, thinking that maybe I’ll see obvious patterns in the “BD 58” fields, but I just couldn’t get them to be recognized, no matter what I did to tweak the timestamp data.
Or read this on Hacker News