Harvesting SSH Credentials: Insights from My Honeypot Network

(uphillsecurity.com)

16 points | by whatbackup 2 hours ago ago

11 comments

  • 0cf8612b2e1e 27 minutes ago

    Do most installations create a git user account with login permissions?

    • inigyou 2 minutes ago

      There's no such thing as an account with or without login permissions. Normally you need a git account. And that means you can log in to it. You can use ForceCommand to make it so you can only run the git server, but if a mistake is made with this configuration then you can log in or port forward or X forward or file transfer as git.

  • asveikau an hour ago

    Having a root password of "toor" is very clever. Nobody will figure that one out.

    • sisve 30 minutes ago

      Did you check out the statistics on the site? They listed 1233456, 12345, 1234,123 and 1 on the toplist of password.

      If we are going to be clever we should follow the statistics and go for 12 that where not on the toplist!!

      • youareinsuffera 20 minutes ago

        Or even better, 21. Reverse it to add another layer of obfuscation.

        • whatbackup 8 minutes ago

          You are right.

          12 - Rank 318

          21 - Rank 523

          I'm surprised that '12' is so low on the list.

    • erulastiel 42 minutes ago

      toor was a default password for many devices for decades.

      • pudgywalsh a minute ago

        Slackware used it in the late 90s IIRC.

      • asveikau 35 minutes ago

        I've used unix-like OS's for 28 years and I don't remember coming across it as a password.

        It is a common username (see: https://en.wikipedia.org/wiki/Toor_(Unix) ), the machine I am typing this on has it.

        • PyWoody 9 minutes ago

          It was the default password for the root user in Kali Linux for a while.

  • daneel_w 30 minutes ago

    No "credentials" are being "harvested" here. It's all worthless data, save for the statistics.