Man, that one Brazilian IP really going hard
also, who has sshd without `PermitRootPassword=no`? they need to broaden their horizons and try `admin`, `ec2-user`, and `ubuntu` /s
11–20 of 268 posts
Man, that one Brazilian IP really going hard
also, who has sshd without `PermitRootPassword=no`? they need to broaden their horizons and try `admin`, `ec2-user`, and `ubuntu` /s
Seems like some of them are residential IP addresses! I guess parts of a botnet or a compromised device?
This is fun to watch, seeing all the passwords is pretty interesting. Just curious, why x out the IP at all?
> Just curious, why x out the IP at all? Trying to avoid being a jerk. The sources are likely hacked boxes where the owner has no idea.
Man, that one Brazilian IP really going hard
it bugs me that they're not trying the passwords in lexigraphical order :-D also, who has sshd without `PermitRootPassword=no`? they need to broaden their horizons and try `admin`, `ec2-user`, and `ubuntu` /s
Is code available anywhere?
I run a slowly growing network of SSH honeypots that do central logging (Greylog), that I’ve been meaning to document the setup of for here somewhen.
Bolting something like this onto that would be pretty funny.
I kinda want to know the server's address so I can send a "hello_hn" message in the passwords there.
I kinda want to know the server's address so I can send a "hello_hn" message in the passwords there.
Earlier quoted context omitted.
> Just curious, why x out the IP at all? Trying to avoid being a jerk. The sources are likely hacked boxes where the owner has no idea.
And since they don't get called out, they won't get an idea. Unless the infection is retargeted against themselves.