#passwordguessing — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #passwordguessing, aggregated by home.social.
-
oh, somebot is in trouble:
May 25 13:26:54 skapet sshd-session[30936]: Failed password for invalid user Can't open exe from 2a02:4780:10:8ba4::1 port 34842 ssh2
May 25 13:26:56 skapet sshd-session[92221]: Failed password for invalid user Can't open exe from 2a02:4780:10:8ba4::1 port 34856 ssh2#ssh #sshgropers #passwordgroping #passwordguessing #bots #botnets #cybercrime
-
Yes, this happened:
May 23 09:54:39 skapet sshd-session[44948]: Failed password for invalid user root/1234567 from 109.248.231.249 port 52134 ssh2
Must have worked *somewhere* at least *once*, right?
#cybercrime #ssh #passwordgroping #passwordguessing #morons #scriptkiddies
-
yes, this happened:
Apr 8 23:46:59 skapet sshd-session[69515]: Failed none for invalid user Can't locate List/Util.pm in @INC (you may need to install the List from 175.199.67.164 port 51226 ssh2
(and several times more, of course)
#ssh #bot #botnet #passwordgroping #passwordguessing #sshgropers #cybercrime #securityBackground: "Badness, Enumerated by Robots" https://nxdomain.no/~peter/badness_enumerated_by_robots.html and links therein
-
A kiddie and their script, part N of N!
Mar 9 17:54:52 skapet sshd-session[97161]: Failed password for invalid user %company% from 20.83.3.189 port 17677 ssh2
#scriptkiddies #sshgropers #passwordguessing #cybercrime #ssh #security
And if you need some reading material, https://nxdomain.no/~peter/hailmary_lessons_learned.html (or g-tracked https://bsdly.blogspot.com/2013/10/the-hail-mary-cloud-and-lessons-learned.html)
-
Friends,
It feels like it was in a different century, but at the beginning of the #russia-#ukraine full scale war I speculated that you could predict development in conflict based on the intensity of attempted #cyberattacks, see https://nxdomain.no/~peter/Predicting_developments_in_real_world_conflict_from_patterns_of_failed_logins.html. The data now covers four years.
I ponder whether it's worth using the data (linked in the article) to see how these things correlate.
I'd love to hear your thoughts.
#ssh #passwordguessing #cybercrime #passwordgropers #hailmarycloud
-
A mention elsewhere of the insufferable ssh password guessers has me reprise my "The Hail Mary Cloud and the Lessons Learned" https://nxdomain.no/~peter/hailmary_lessons_learned.html piece, with a note added at the end about endlessh as a possible refinement (yes, I use it) #ssh #passwords #passwordguessing #passwordgroping #endlessh #openbsd #freebsd #pf #packetfilter #security #cybercrime
-
Over at LinkedIn, somebody posted the results of putting a Linux server with sshd exposted to the internet for 30 days recently.
In that particular area, not much seems to have changed since the early years of this century when the events chronicled here https://nxdomain.no/~peter/hailmary_lessons_learned.html (or if you prefer Big G's trackers, https://bsdly.blogspot.com/2013/10/the-hail-mary-cloud-and-lessons-learned.html) occurred.
#ssh #passwordguessing #rootlogin #weakspaswords #passwordgroping #cybercrime
-
Possibly not blogworthy, but: One puzzling side effect of running greytrapping (as chronicled in https://nxdomain.no/~peter/eighteen_years_of_greytrapping.html) is seeing the uptick in password guessing using even the obviously generated gibberish local parts, and the sheer volume of tries (see https://nxdomain.no/~peter/should_i_stop_caring_and_let_ip_reputation_sort_them_out.html and links therein). #greytrapping #passwordguessing #passwordgroping #spamd #ssh #pop3gropers
-
On a similar note, idle minds might wonder what "luax" is - log excerpt https://nxdomain.no/~peter/who_or_what_is_luax.txt #luax #ssh #sshgropers #passwordgroping #passwordguessing #cybercrime #security #bots
-
just got to love these:
Oct 4 00:04:31 portal sshd-session[37449]: Failed password for invalid user { from 114.111.54.188 port 49944 ssh2
#ssh #passwords #passwordguessing #passwordgroping #cybercrime #bots
-
It's heartwarming to a greying geek that a 5000+ words retrospective on greytrapping is turning out to be popular - https://nxdomain.no/~peter/eighteen_years_of_greytrapping.html (tracked https://bsdly.blogspot.com/2025/08/eighteen-years-of-greytrapping-is.html)
#greytrapping #spam #antispam #greylisting #blocklist #openbsd #freebsd #smtp #email #ssh #passwords #passwordguessing #pop3 #security #networking #cybercrime
-
It's now been a week since my population of spamtraps rolled past the number of inhabitants in my home country of Norway. Here is the retrospective:
Eighteen Years of Greytrapping - Is the Weirdness Finally Paying Off? https://nxdomain.no/~peter/eighteen_years_of_greytrapping.html (tracked https://bsdly.blogspot.com/2025/08/eighteen-years-of-greytrapping-is.html)
#greytrapping #spam #antispam #greylisting #blocklist #openbsd #freebsd #smtp #email #ssh #passwords #passwordguessing #pop3 #security #networking #cybercrime @nostarch
-
Friends, it finally happened. On August 7th, 2025, the number of spamtraps intended to fool spammers rolled past the number of inhabitants in my home country of Norway. It's time for a retrospective.
Eighteen Years of Greytrapping - Is the Weirdness Finally Paying Off? https://nxdomain.no/~peter/eighteen_years_of_greytrapping.html (tracked https://bsdly.blogspot.com/2025/08/eighteen-years-of-greytrapping-is.html)
#greytrapping #spam #antispam #greylisting #blocklist #openbsd #freebsd #smtp #email #ssh #passwords #passwordguessing #pop3 #security #networking #cybercrime
-
Happy
'Logging in as users
"<"
and
">
day'to all who celebrate!
Aug 11 12:48:53 freebeast sshd-session[32113]: Invalid user "<" from 46.246.3.247 port 36834
Aug 11 11:57:32 freebeast sshd-session[88]: Invalid user "> from 46.246.3.247 port 8731#ssh #passwordgropers #cybercrime #passwordguessing #passwords #security
-
[Again for those on the other side of the pond] -
Friends, it finally happened. On August 7th, 2025, the number of spamtraps rolled past the number of people in my home country. It's time for a retrospective.
Eighteen Years of Greytrapping - Is the Weirdness Finally Paying Off? https://nxdomain.no/~peter/eighteen_years_of_greytrapping.html (tracked https://bsdly.blogspot.com/2025/08/eighteen-years-of-greytrapping-is.html)
#greytrapping #spam #antispam #greylisting #blocklist #openbsd #freebsd #smtp #email #ssh #passwords #passwordguessing #pop3 #security #networking #cybercrime
-
Friends, it finally happened. On August 7th, 2025, the number of spamtraps intended to woo the unwary spammer rolled past the number of inhabitants in my home country of Norway. It's time for a retrospective.
Eighteen Years of Greytrapping - Is the Weirdness Finally Paying Off? https://nxdomain.no/~peter/eighteen_years_of_greytrapping.html (tracked https://bsdly.blogspot.com/2025/08/eighteen-years-of-greytrapping-is.html)
#greytrapping #spam #antispam #greylisting #blocklist #openbsd #freebsd #smtp #email #ssh #passwords #passwordguessing #pop3 #security #networking #cybercrime
-
Eighteen Years of Greytrapping - Is the Weirdness Finally Paying Off? https://nxdomain.no/~peter/eighteen_years_of_greytrapping.html (tracked https://bsdly.blogspot.com/2025/08/eighteen-years-of-greytrapping-is.html)
Friends, it finally happened. On August 7th, 2025, the number of spamtraps intended to woo the unwary spammer rolled past the number of inhabitants in my home country of Norway.
It's time for a retrospective.
#greytrapping #spam #antispam #greylisting #blocklist #openbsd #freebsd #smtp #email #ssh #passwords #passwordguessing #pop3 #security #networking #cybercrime
-
Eighteen Years of Greytrapping - Is the Weirdness Finally Paying Off? https://nxdomain.no/~peter/eighteen_years_of_greytrapping.html (tracked https://bsdly.blogspot.com/2025/08/eighteen-years-of-greytrapping-is.html)
With the imaginary friends, also known as spamtraps, now more numerous than the inhabitants of their virtual landlord's home country, a greytrapping retrospective is in order.
#greytrapping #spam #antispam #greylisting #blocklist #openbsd #freebsd #smtp #email #ssh #passwords #passwordguessing #pop3 #security #networking #cybercrime
-
I've heard of one-LETTER user names before, but trying ' as a user name takes a very special kind of ... something.
Jul 23 07:45:42 skapet sshd-session[12400]: Failed password for invalid user ' from 161.132.40.50 port 41338 ssh2
#sshgropers #cybercrime #cyberfail #passwordgropers #passwordguessing
-
Should I Stop Caring and Let IP Address Reputation Sort Them Out? https://nxdomain.no/~peter/should_i_stop_caring_and_let_ip_reputation_sort_them_out.html
How long does data on misbehaving hosts on the Internet stay relevant in an IP Address Reputation context?
Link to poll within (on for a week, 4 days left, please *do* vote).
#security #passwordguessing #antispam #sshgropers #pop3gropers #blacklists #blocklists #bruteforcers #spam #cybercrime #ipreputation
(repost for the CET-ish crowd, some still in holiday mode, and with graphics of sorts added)
-
Psychologists may be able to explain what happened here:
May 13 14:04:14 skapet sshd-session[88955]: Failed password for invalid user FAKESSH from 213.178.90.84 port 41918 ssh2
(meh, https://nxdomain.no/~peter/hailmary_lessons_learned.html and links therein *might* be relevant) #passwordgropers #ssh #passwordguessing #cybercrime #security
-
It will not be a surprise that the ovenight haul of new groped-for user IDs today included, almost #hailmary style, a bunch of vaguely #cryptocurrencly related ones, https://nxdomain.no/~peter/tuliptraders.txt, log extract https://nxdomain.no/~peter/tuliptraders-sshlog.txt. Do #cryptptulipcookers actually run as users with passwords anywhere?
Of course all of those are in the list of imaginary friends, see https://nxdomain.no/~peter/hailmary_lessons_learned.html and https://nxdomain.no/~peter/badness_enumerated_by_robots.html for background. #sshgropers #passwordguessing #cryptotulips #scams #cybercrime
-
So this happened:
Jan 30 03:07:16 skapet sshd-session[94311]: Failed password for invalid user "> from 165.231.182.56 port 15613 ssh2
I wonder if we are seeing a variant of "gropefor database down, feeding raw html to the ssh gropebot" scenario again such as in https://nxdomain.no/~peter/so_somebody_is_throwing_html_at_your_sshd.html #sshgropers #sshd #passwordguessing #passwordgroping #passwords #cybercrime
-
Friday night follies included several attemtpts from [email protected] to deliver spam to one of the imaginary friends at https://nxdomain.no/~peter/traplist.shtml as well as somebot attempting to ssh in as user <space>, which for #shell reasons will not be able to join the 500k+ #spamtraps
All while you were sleeping. #spamd #cybercrime #antispam #sshgropers #passwordguessing
-
Some of my friends here will fully understand the pleasure of, after generating 1k public spamtraps over a certain pattern, seeing the selfsame turn up soon after as things the passwords gropers try desperately for ([email protected]) #passwords #passwordgropers #passwordguessing #cybercrime #cyberscum
-
Another one for the #ssh #password #groper #blooper reel:
Nov 4 15:24:12 portal sshd-session[16361]: Failed password for invalid user user1!2@3#4$ from 185.11.61.88 port 40254 ssh2
#sshgropers #passwordguessing #cybercrime
(also to be added posthaste, with a domain appended, to the list of imaginary friends at https://nxdomain.no/~peter/traplist.shtml) #spamtraps
-
If you found the #hailmary tag confusing in the previous, the summary article from some years back will possibly make for reading up on that particular weirdness during the long evenings ahead - "The Hail Mary Cloud and the Lessons Learned" https://nxdomain.no/~peter/hailmary_lessons_learned.html or prettified, tracked https://bsdly.blogspot.com/2013/10/the-hail-mary-cloud-and-lessons-learned.html #passwordgropers #passwords #passwordguessing #ssh #cybercrime
-
I'm at a loss for words -
Oct 29 19:59:39 skapet sshd-session[60243]: Failed password for invalid user root/123456 from 138.68.79.186 port 39166 ssh2
#ssh #passwordgropers #passwordguessing #sshgropers #hailmary #cybercrime
-
The topic of #ipv6 support came up at work (as it does sometimes) and a colleague asked, how popular is that protocol, really?
My best data source is the bruteforcers+webtrash data (twice hourly dump https://nxdomain.no/~peter/bruteforcers.txt, see https://nxdomain.no/~peter/badness_enumerated_by_robots.html for explanation, alternatively prettified and G-tracked https://bsdly.blogspot.com/2018/08/badness-enumerated-by-robots.html) and it looks like roughly seven percent of the source addresses for undesirable activity are IPv6, the rest old fashioned #IPv4. #passwordguessing #bruteforcers
-
The #sshgropers are really throwing everything at the wall these days:
Aug 18 14:36:54 skapet sshd-session[71375]: Failed password for invalid user GNU/Linux from 4.247.176.60 port 39582 ssh2
#ssh #passwordgropers #passwordguessing #bruteforce #passwords #cybercrime
Also see https://nxdomain.no/~peter/hailmary_lessons_learned.html (prettier, G-tracked: https://bsdly.blogspot.com/2013/10/the-hail-mary-cloud-and-lessons-learned.html) and badness_enumerated_by_robots.html (prettified, G-tracked https://bsdly.blogspot.com/2018/08/badness-enumerated-by-robots.html)