Live data from Hacker News

Brute.Fail: Watch brute force attacks fail in real time

brute.fail

11–20 of 268 posts

Re: Brute.Fail: Watch brute force attacks fail in real time

#11
post #5

Man, that one Brazilian IP really going hard

it bugs me that they're not trying the passwords in lexigraphical order :-D

also, who has sshd without `PermitRootPassword=no`? they need to broaden their horizons and try `admin`, `ec2-user`, and `ubuntu` /s

Re: Brute.Fail: Watch brute force attacks fail in real time

#13

Seems like some of them are residential IP addresses! I guess parts of a botnet or a compromised device?

"residential proxy" is a very popular black market service, since it's less straightforward for website owners to block than other common vpn termination points. These applications market themselves as free VPN services, get loaded by special offers bolted onto legitimate software installers, or are added to trojanized pirate distributions of popular applications.

Re: Brute.Fail: Watch brute force attacks fail in real time

#14
post #6

This is fun to watch, seeing all the passwords is pretty interesting. Just curious, why x out the IP at all?

> Just curious, why x out the IP at all? Trying to avoid being a jerk. The sources are likely hacked boxes where the owner has no idea.

And since they don't get called out, they won't get an idea. Unless the infection is retargeted against themselves.

Re: Brute.Fail: Watch brute force attacks fail in real time

#15
post #11
post #5

Man, that one Brazilian IP really going hard

it bugs me that they're not trying the passwords in lexigraphical order :-D also, who has sshd without `PermitRootPassword=no`? they need to broaden their horizons and try `admin`, `ec2-user`, and `ubuntu` /s

Who still allows password-based login for any SSH account, root or not? Keys, certificates, or Kerberos for all users.

Re: Brute.Fail: Watch brute force attacks fail in real time

#16
Oh that’s pretty fucking cool.

Is code available anywhere?

I run a slowly growing network of SSH honeypots that do central logging (Greylog), that I’ve been meaning to document the setup of for here somewhen.

Bolting something like this onto that would be pretty funny.

Re: Brute.Fail: Watch brute force attacks fail in real time

#19
post #6

Earlier quoted context omitted.

> Just curious, why x out the IP at all? Trying to avoid being a jerk. The sources are likely hacked boxes where the owner has no idea.

And since they don't get called out, they won't get an idea. Unless the infection is retargeted against themselves.

I also scan the internet quite a bit. Trust me, they (or the ISP rather) are getting a few emails an hour.
Post reply on HN