logoalt Hacker News

Harvesting SSH Credentials: Insights from My Honeypot Network

32 pointsby whatbackuptoday at 5:45 PM24 commentsview on HN

Comments

dspilletttoday at 9:45 PM

That doesn't look to me like it would find many real credentials. It is collecting the credentials that automated bots are trying to use, some of them, perhaps many of them, will be credentials that someone somewhere is using for something, but unless you are planning an Internet wide scan yourself using those credentials to try login to something is likely to be fruitless.

show 1 reply
ufmacetoday at 9:01 PM

I'd be more curious to know what these SSH scanner bots actually do if they manage to log in. Automated recon, install spambot/cryptominer/phishing site, something else?

show 4 replies
pastagetoday at 8:52 PM

Last time I saw this an obscure single letter root password was still "secure", now days seems like almost all non-alphanumeric chars works. % is my new root password it still has not been brute forced.

daneel_wtoday at 6:58 PM

No "credentials" are being "harvested" here. It's all worthless data, save for the statistics.

0cf8612b2e1etoday at 7:01 PM

Do most installations create a git user account with login permissions?

show 1 reply
asveikautoday at 6:38 PM

Having a root password of "toor" is very clever. Nobody will figure that one out.

show 2 replies