home.social

#passwordguessing — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #passwordguessing, aggregated by home.social.

fetched live
  1. oh, somebot is in trouble:

    May 25 13:26:54 skapet sshd-session[30936]: Failed password for invalid user Can't open exe from 2a02:4780:10:8ba4::1 port 34842 ssh2
    May 25 13:26:56 skapet sshd-session[92221]: Failed password for invalid user Can't open exe from 2a02:4780:10:8ba4::1 port 34856 ssh2

    #ssh #sshgropers #passwordgroping #passwordguessing #bots #botnets #cybercrime

  2. Yes, this happened:

    May 23 09:54:39 skapet sshd-session[44948]: Failed password for invalid user root/1234567 from 109.248.231.249 port 52134 ssh2

    Must have worked *somewhere* at least *once*, right?

    #cybercrime #ssh #passwordgroping #passwordguessing #morons #scriptkiddies

  3. yes, this happened:

    Apr 8 23:46:59 skapet sshd-session[69515]: Failed none for invalid user Can't locate List/Util.pm in @INC (you may need to install the List from 175.199.67.164 port 51226 ssh2

    (and several times more, of course)
    #ssh #bot #botnet #passwordgroping #passwordguessing #sshgropers #cybercrime #security

    Background: "Badness, Enumerated by Robots" nxdomain.no/~peter/badness_enu and links therein

  4. A kiddie and their script, part N of N!

    Mar 9 17:54:52 skapet sshd-session[97161]: Failed password for invalid user %company% from 20.83.3.189 port 17677 ssh2

    #scriptkiddies #sshgropers #passwordguessing #cybercrime #ssh #security

    And if you need some reading material, nxdomain.no/~peter/hailmary_le (or g-tracked bsdly.blogspot.com/2013/10/the)

  5. Friends,

    It feels like it was in a different century, but at the beginning of the #russia-#ukraine full scale war I speculated that you could predict development in conflict based on the intensity of attempted #cyberattacks, see nxdomain.no/~peter/Predicting_. The data now covers four years.

    I ponder whether it's worth using the data (linked in the article) to see how these things correlate.

    I'd love to hear your thoughts.

    #ssh #passwordguessing #cybercrime #passwordgropers #hailmarycloud

  6. A mention elsewhere of the insufferable ssh password guessers has me reprise my "The Hail Mary Cloud and the Lessons Learned" nxdomain.no/~peter/hailmary_le piece, with a note added at the end about endlessh as a possible refinement (yes, I use it) #ssh #passwords #passwordguessing #passwordgroping #endlessh #openbsd #freebsd #pf #packetfilter #security #cybercrime

  7. Over at LinkedIn, somebody posted the results of putting a Linux server with sshd exposted to the internet for 30 days recently.

    In that particular area, not much seems to have changed since the early years of this century when the events chronicled here nxdomain.no/~peter/hailmary_le (or if you prefer Big G's trackers, bsdly.blogspot.com/2013/10/the) occurred.

    #ssh #passwordguessing #rootlogin #weakspaswords #passwordgroping #cybercrime

  8. Possibly not blogworthy, but: One puzzling side effect of running greytrapping (as chronicled in nxdomain.no/~peter/eighteen_ye) is seeing the uptick in password guessing using even the obviously generated gibberish local parts, and the sheer volume of tries (see nxdomain.no/~peter/should_i_st and links therein). #greytrapping #passwordguessing #passwordgroping #spamd #ssh #pop3gropers

  9. just got to love these:

    Oct 4 00:04:31 portal sshd-session[37449]: Failed password for invalid user { from 114.111.54.188 port 49944 ssh2

    #ssh #passwords #passwordguessing #passwordgroping #cybercrime #bots

  10. Friends, it finally happened. On August 7th, 2025, the number of spamtraps intended to fool spammers rolled past the number of inhabitants in my home country of Norway. It's time for a retrospective.

    Eighteen Years of Greytrapping - Is the Weirdness Finally Paying Off? nxdomain.no/~peter/eighteen_ye (tracked bsdly.blogspot.com/2025/08/eig)

    #greytrapping #spam #antispam #greylisting #blocklist #openbsd #freebsd #smtp #email #ssh #passwords #passwordguessing #pop3 #security #networking #cybercrime

  11. Happy

    'Logging in as users
    "<"
    and
    ">
    day'

    to all who celebrate!

    Aug 11 12:48:53 freebeast sshd-session[32113]: Invalid user "<" from 46.246.3.247 port 36834
    Aug 11 11:57:32 freebeast sshd-session[88]: Invalid user "> from 46.246.3.247 port 8731

    #ssh #passwordgropers #cybercrime #passwordguessing #passwords #security

  12. [Again for those on the other side of the pond] -

    Friends, it finally happened. On August 7th, 2025, the number of spamtraps rolled past the number of people in my home country. It's time for a retrospective.

    Eighteen Years of Greytrapping - Is the Weirdness Finally Paying Off? nxdomain.no/~peter/eighteen_ye (tracked bsdly.blogspot.com/2025/08/eig)

    #greytrapping #spam #antispam #greylisting #blocklist #openbsd #freebsd #smtp #email #ssh #passwords #passwordguessing #pop3 #security #networking #cybercrime

  13. Friends, it finally happened. On August 7th, 2025, the number of spamtraps intended to woo the unwary spammer rolled past the number of inhabitants in my home country of Norway. It's time for a retrospective.

    Eighteen Years of Greytrapping - Is the Weirdness Finally Paying Off? nxdomain.no/~peter/eighteen_ye (tracked bsdly.blogspot.com/2025/08/eig)

    #greytrapping #spam #antispam #greylisting #blocklist #openbsd #freebsd #smtp #email #ssh #passwords #passwordguessing #pop3 #security #networking #cybercrime

  14. Eighteen Years of Greytrapping - Is the Weirdness Finally Paying Off? nxdomain.no/~peter/eighteen_ye (tracked bsdly.blogspot.com/2025/08/eig)

    Friends, it finally happened. On August 7th, 2025, the number of spamtraps intended to woo the unwary spammer rolled past the number of inhabitants in my home country of Norway.

    It's time for a retrospective.

    #greytrapping #spam #antispam #greylisting #blocklist #openbsd #freebsd #smtp #email #ssh #passwords #passwordguessing #pop3 #security #networking #cybercrime

  15. Eighteen Years of Greytrapping - Is the Weirdness Finally Paying Off? nxdomain.no/~peter/eighteen_ye (tracked bsdly.blogspot.com/2025/08/eig)

    With the imaginary friends, also known as spamtraps, now more numerous than the inhabitants of their virtual landlord's home country, a greytrapping retrospective is in order.

    #greytrapping #spam #antispam #greylisting #blocklist #openbsd #freebsd #smtp #email #ssh #passwords #passwordguessing #pop3 #security #networking #cybercrime

  16. I've heard of one-LETTER user names before, but trying ' as a user name takes a very special kind of ... something.

    Jul 23 07:45:42 skapet sshd-session[12400]: Failed password for invalid user ' from 161.132.40.50 port 41338 ssh2

    #sshgropers #cybercrime #cyberfail #passwordgropers #passwordguessing

  17. Should I Stop Caring and Let IP Address Reputation Sort Them Out? nxdomain.no/~peter/should_i_st

    How long does data on misbehaving hosts on the Internet stay relevant in an IP Address Reputation context?

    Link to poll within (on for a week, 4 days left, please *do* vote).

    #security #passwordguessing #antispam #sshgropers #pop3gropers #blacklists #blocklists #bruteforcers #spam #cybercrime #ipreputation

    (repost for the CET-ish crowd, some still in holiday mode, and with graphics of sorts added)

  18. Psychologists may be able to explain what happened here:

    May 13 14:04:14 skapet sshd-session[88955]: Failed password for invalid user FAKESSH from 213.178.90.84 port 41918 ssh2

    (meh, nxdomain.no/~peter/hailmary_le and links therein *might* be relevant) #passwordgropers #ssh #passwordguessing #cybercrime #security

  19. It will not be a surprise that the ovenight haul of new groped-for user IDs today included, almost #hailmary style, a bunch of vaguely #cryptocurrencly related ones, nxdomain.no/~peter/tuliptrader, log extract nxdomain.no/~peter/tuliptrader. Do #cryptptulipcookers actually run as users with passwords anywhere?

    Of course all of those are in the list of imaginary friends, see nxdomain.no/~peter/hailmary_le and nxdomain.no/~peter/badness_enu for background. #sshgropers #passwordguessing #cryptotulips #scams #cybercrime

  20. So this happened:

    Jan 30 03:07:16 skapet sshd-session[94311]: Failed password for invalid user "> from 165.231.182.56 port 15613 ssh2

    I wonder if we are seeing a variant of "gropefor database down, feeding raw html to the ssh gropebot" scenario again such as in nxdomain.no/~peter/so_somebody #sshgropers #sshd #passwordguessing #passwordgroping #passwords #cybercrime

  21. Friday night follies included several attemtpts from [email protected] to deliver spam to one of the imaginary friends at nxdomain.no/~peter/traplist.sh as well as somebot attempting to ssh in as user <space>, which for #shell reasons will not be able to join the 500k+ #spamtraps

    All while you were sleeping. #spamd #cybercrime #antispam #sshgropers #passwordguessing

  22. Some of my friends here will fully understand the pleasure of, after generating 1k public spamtraps over a certain pattern, seeing the selfsame turn up soon after as things the passwords gropers try desperately for ([email protected]) #passwords #passwordgropers #passwordguessing #cybercrime #cyberscum

  23. Another one for the #ssh #password #groper #blooper reel:

    Nov 4 15:24:12 portal sshd-session[16361]: Failed password for invalid user user1!2@3#4$ from 185.11.61.88 port 40254 ssh2

    #sshgropers #passwordguessing #cybercrime

    (also to be added posthaste, with a domain appended, to the list of imaginary friends at nxdomain.no/~peter/traplist.sh) #spamtraps

  24. If you found the #hailmary tag confusing in the previous, the summary article from some years back will possibly make for reading up on that particular weirdness during the long evenings ahead - "The Hail Mary Cloud and the Lessons Learned" nxdomain.no/~peter/hailmary_le or prettified, tracked bsdly.blogspot.com/2013/10/the #passwordgropers #passwords #passwordguessing #ssh #cybercrime

  25. I'm at a loss for words -

    Oct 29 19:59:39 skapet sshd-session[60243]: Failed password for invalid user root/123456 from 138.68.79.186 port 39166 ssh2

    #ssh #passwordgropers #passwordguessing #sshgropers #hailmary #cybercrime

  26. The topic of #ipv6 support came up at work (as it does sometimes) and a colleague asked, how popular is that protocol, really?

    My best data source is the bruteforcers+webtrash data (twice hourly dump nxdomain.no/~peter/bruteforcer, see nxdomain.no/~peter/badness_enu for explanation, alternatively prettified and G-tracked bsdly.blogspot.com/2018/08/bad) and it looks like roughly seven percent of the source addresses for undesirable activity are IPv6, the rest old fashioned #IPv4. #passwordguessing #bruteforcers

  27. The #sshgropers are really throwing everything at the wall these days:

    Aug 18 14:36:54 skapet sshd-session[71375]: Failed password for invalid user GNU/Linux from 4.247.176.60 port 39582 ssh2

    #ssh #passwordgropers #passwordguessing #bruteforce #passwords #cybercrime

    Also see nxdomain.no/~peter/hailmary_le (prettier, G-tracked: bsdly.blogspot.com/2013/10/the) and badness_enumerated_by_robots.html (prettified, G-tracked bsdly.blogspot.com/2018/08/bad)