Harvesting SSH Credentials: Insights from My Honeypot Network

(uphillsecurity.com)

16 points | by whatbackup 1 hour ago

3 comments

  • 0cf8612b2e1e 28 minutes ago
    Do most installations create a git user account with login permissions?
    • inigyou 2 minutes ago
      There's no such thing as an account with or without login permissions. Normally you need a git account. And that means you can log in to it. You can use ForceCommand to make it so you can only run the git server, but if a mistake is made with this configuration then you can log in or port forward or X forward or file transfer as git.
  • asveikau 51 minutes ago
    Having a root password of "toor" is very clever. Nobody will figure that one out.
    • sisve 30 minutes ago
      Did you check out the statistics on the site? They listed 1233456, 12345, 1234,123 and 1 on the toplist of password.

      If we are going to be clever we should follow the statistics and go for 12 that where not on the toplist!!

      • youareinsuffera 21 minutes ago
        Or even better, 21. Reverse it to add another layer of obfuscation.
        • whatbackup 8 minutes ago
          You are right.

          12 - Rank 318

          21 - Rank 523

          I'm surprised that '12' is so low on the list.

    • erulastiel 42 minutes ago
      toor was a default password for many devices for decades.
      • pudgywalsh 1 minute ago
        Slackware used it in the late 90s IIRC.
      • asveikau 35 minutes ago
        I've used unix-like OS's for 28 years and I don't remember coming across it as a password.

        It is a common username (see: https://en.wikipedia.org/wiki/Toor_(Unix) ), the machine I am typing this on has it.

        • PyWoody 10 minutes ago
          It was the default password for the root user in Kali Linux for a while.
  • daneel_w 31 minutes ago
    No "credentials" are being "harvested" here. It's all worthless data, save for the statistics.