So... the attacker accessed the server of a security consultant by "bruteforcing a username and password combination"... EDIT: Security newb here. It was a honeypot, aka a trap.
Hacker tries to compromise and resell an internet-facing Linux server
11–20 of 73 posts
Re: Hacker tries to compromise and resell an internet-facing Linux server
#12So... the attacker accessed the server of a security consultant by "bruteforcing a username and password combination"... EDIT: Security newb here. It was a honeypot, aka a trap.
Re: Hacker tries to compromise and resell an internet-facing Linux server
#13So... the attacker accessed the server of a security consultant by "bruteforcing a username and password combination"... EDIT: Security newb here. It was a honeypot, aka a trap.
Re: Hacker tries to compromise and resell an internet-facing Linux server
#14Re: Hacker tries to compromise and resell an internet-facing Linux server
#15So... the attacker accessed the server of a security consultant by "bruteforcing a username and password combination"... EDIT: Security newb here. It was a honeypot, aka a trap.
Re: Hacker tries to compromise and resell an internet-facing Linux server
#16Absolutely fascinating. I've been "in and around" the security community (not a part of) for years now, and never heard of a company offering a service like this. I love how he gives advise to the company at the end. I mean c'mon you get root access via dictionary attack within a quick timeframe and you don't think it is a honeypot?
Re: Hacker tries to compromise and resell an internet-facing Linux server
#17All of this is outside my experience, so I have to ask - how does the attack, as described, prove HutHos is the perpetrator? The poster was able to find the HutHos site owner's full information "in a few minutes", due to "poor operational security practices." Doesn't this raise the possibility that the HutHos server was compromised by the malware's true owner?
In other words, the simplest explanation is that Huthos is taking control of machines so that they can sell them to customers as their own VPS service.
Re: Hacker tries to compromise and resell an internet-facing Linux server
#18Re: Hacker tries to compromise and resell an internet-facing Linux server
#19Re: Hacker tries to compromise and resell an internet-facing Linux server
#20Absolutely fascinating. I've been "in and around" the security community (not a part of) for years now, and never heard of a company offering a service like this. I love how he gives advise to the company at the end. I mean c'mon you get root access via dictionary attack within a quick timeframe and you don't think it is a honeypot?
I rather doubt they actually care if the target server is a honeypot or not, it looks like they're just looking for free hosting.