huntback blog
Field notes on deception, fraud and CVEs
Practical writing on catching attacks, detecting fraud at the front door, and reading real-world exploitation.
Fraud
How to detect VPN and proxy users at signup
A practical guide to spotting VPN, proxy, Tor and datacenter traffic at login and signup, and what to do with it.
2026-09-22 · 6 min
CVECVE-2024-4577 explained: the PHP-CGI RCE attackers keep spraying
What CVE-2024-4577 is, why it matters, how attackers exploit it in the wild, and how to tell if you are being targeted.
2026-09-20 · 5 min
DeceptionWhy honeypots catch attacks with zero false positives
Deception flips the security signal-to-noise problem. Any interaction with a decoy is hostile, so there is nothing to triage away.
2026-09-18 · 6 min
FraudHow to detect Tor exit nodes at login
Tor anonymises the source of a login. Here is how to detect exit nodes reliably and decide what to do about them.
2026-09-16 · 4 min
Threat intelA GreyNoise alternative built on your own decoys
Internet-noise feeds tell you an IP is scanning the internet. First-party decoys tell you how you are being attacked, and let you hunt back.
2026-09-12 · 5 min