<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Telnet · Diary of a Lost Honeypot</title><link>https://blog.efespain.com/en/tags/telnet/</link><description>A honeypot in some corner of the network. Every infection, a story worth telling.</description><generator>Hugo</generator><language>en</language><managingEditor>eFeSpain</managingEditor><webMaster>eFeSpain</webMaster><copyright>2026 eFeSpain</copyright><lastBuildDate>Tue, 01 Sep 2026 12:00:00 +0000</lastBuildDate><atom:link href="https://blog.efespain.com/en/tags/telnet/index.xml" rel="self" type="application/rss+xml"/><item><title>Introduced by its enemy</title><link>https://blog.efespain.com/en/chapter-21/</link><pubDate>Tue, 01 Sep 2026 12:00:00 +0000</pubDate><guid>https://blog.efespain.com/en/chapter-21/</guid><description>An automated scanner found the honeypot's telnet and, eighteen seconds later, there was a binary inside. The password was «telnet». The loader it dropped comes with two operator typos, one of which breaks an entire infection. And when I finally put a name to the family —IranBot, a Mirai fork with a public dossier— it turned out that name had been written on this blog since August: a rival bot had put it there, in the list of competitors it uninstalls on arrival.</description></item></channel></rss>