The First Honeypot That Fooled a Software Engineer

▶ Watch (4:35)

In 2016, Ryan Mitchell saw an SSH entry on the Wall of Sheep at the Packet Hacking Village. Username root, password eight characters starting with P. She logged in. The server felt off – files appeared when listed but vanished when catted, no editors installed. She was not in bash. A Python program was sending fake prompts. The whole thing ran as a low-level user inside a Docker container. That server held a base64 challenge. Solving it gave credentials for another server. Five challenges later she was the weekend’s only winner.

What an SSH Honeypot Is and Why Cowrie

▶ Watch (7:33)

Low-interaction honeypots like Dionaea support many protocols (SMB, FTP, HTTP, MySQL, TFTP) but only offer a banner and handshake. Medium-interaction honeypots like Cowrie support SSH and Telnet and fake bash commands. They keep a fake file system – you can ls, cat, touch files. High-interaction setups use a real operating system in a throwaway container. Mitchell became obsessed with Cowrie because of its out-of-the-box configuration and excellent documentation. The Packet Hacking Village used it for years.

Building the Walkthrough Workshops (2018–2025)

▶ Watch (9:57)

In 2018, the Packet Hacking Village launched walkthrough workshops in a tiny area next to the DJ speakers. Ten chairs, ten laptops, a projector balanced on boxes. The first command needed network – Defcon internet went down. They rebuilt everything: Docker images with Cowrie preinstalled, no external dependencies. PDFs became dynamic HTML pages. Every hour the images refreshed. All seats filled. By 2020 the workshop had a steady stream of students. In 2022 three new workshops launched (password cracking, network OS, botnet building). In 2025 there are 50+ machines with continuous cycling and a ticketing system.

Honeypot Challenges: From Water Heists to Song Recognition

▶ Watch (18:52)

In 2017, Mitchell co‑developed a multi‑server challenge with a story: an evil corporation stealing Lake Tahoe’s water. A fake security guard took coffee breaks – while he slept, players could log in. A jump box’s IP changed with the clock minute. In 2019, notes with an IP appeared around the con. SSH root at that IP revealed five answers: Lullaby, Lemon Drops, Star, Chimney Tops, Bluebirds. The final answer was “Somewhere Over the Rainbow.” In 2022, for Defcon’s 30th anniversary, she built a grid‑based game set in a 1992 Seattle. Players navigated a map of downtown, solved a Game of Life glider puzzle, then hacked the Gibson inside a 3‑D cube with guard NPCs who asked networking questions.

2025 Challenge: A Markov Chain AI Worm

▶ Watch (27:34)

The 2025 challenge imagines a generative AI worm that escaped and rewrites all data on the internet. Players SSH into a server where unrecognized commands are forwarded to an assistant named “M.” M speaks cryptically and refuses direct help. Three servers use the OpenAI Assistants API. The fourth does not – it returns text generated by a Markov chain built from bi‑grams of a specific source. Mitchell wrote a couple dozen sentences by hand, then the script selects them randomly. LLMs cannot obey finite‑state grammar rules, so a Markov chain was the only way to produce stilted, refrigerator‑magnet poetry consistently.

Why She Keeps Building Honeypot Games

▶ Watch (33:28)

Mitchell has a full‑time job, two kids, and takes vacation to attend Defcon. She writes code on vacation. Her motivation: preserving the element of surprise, absurdity, and play in hacker culture. Taking a serious tool like an SSH honeypot and making it fun. She wants people to find or build something nobody expected. The 2025 challenge runs at honeypotquest.com. Winners get a copy of her book Unlocking Python.

Notable Quotes

I was nowhere near bash. I was simply exchanging messages with a Python program that was sending strings back to me that looked like a bash prompt. Ryan Mitchell · ▶ 6:00

SSH honeypots really need existential dread. Ryan Mitchell · ▶ 27:39

It’s not a very serious competition. This is not like CTF. There are no black badges. It’s just fun and I accept beer as bribes. Ryan Mitchell · ▶ 27:30

I’m trying to keep alive a part of hacker culture that I think is sometimes lost. And that is the element of surprise of absurdity and play. Ryan Mitchell · ▶ 33:46

Key Takeaways

  • SSH honeypots can power interactive puzzles, not just malware collection.
  • Walkthrough workshops scaled by moving to offline Docker images.
  • A Markov chain generates better rule‑based text than an LLM for fixed‑grammar challenges.

About the Speaker(s)

Ryan Mitchell is a staff member at the Packet Hacking Village and the author of Unlocking Python (Wiley), Web Scraping with Python (O’Reilly), and multiple courses on LinkedIn Learning including Python Essential Training. She holds a master’s degree in software engineering from Harvard University Extension School and has worked as principal software engineer and data scientist on the search and artificial intelligence teams at the Gerson Lehrman Group for the last six years.