Re: SSH bruteforce on its way...

[email protected]
Newsgroups gmane.comp.security.incidents
Message-ID <[email protected]>
On Fri, 21 Oct 2005 18:05:27 -0000, [email protected] said:
> I didn't think it was possible to determine valid usernames by themselves?  You
> either have a valid username AND password or not.

So you take the list of 30-40 "installed by default" userids, add a list of 100
or so common first names/last names, prepend/append a single letter (i.e.
starting with "john" and "smith", also try "jsmith" and "johns").  Then try
each of those with a list of common passwords.  If you're *really* 31337, you
apply the SSH timing hole to possibly identify valid userids - but it really
isn't needed because it's just as cheap to just try all 40,000 combinations of
userid/password (remember, you're doing this from somebody else's compromised
system).
signature.asc (application/pgp-signature, 226 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2 (GNU/Linux)
Comment: Exmh version 2.5 07/13/2001

iD8DBQFDXaLqcC3lWbTT17ARApsUAJ9qERpvdFy+km09E3VTyg8argKnoACgpAw+
FuD9LhZ0bhndKl3v/FrXOtM=
=gQ+k
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.