Re: SSH bruteforce on its way...

Javier Fernandez-Sanguino <[email protected]>
Newsgroups gmane.comp.security.incidents
Organization Germinus
Message-ID <[email protected]>
[email protected] wrote:

> Hi Volker,
> 
> ive started a honey Machine for your answer on, what are they doing with captured machines ...

I would also be interesting to list what _accounts_ they probe for. I 
have a list of users/passwords recovered from some compromised systems 
and I'm working on a trojaned version of OpenSSH that would log that 
info regardless of authentication method. There are some patches to 
add backdoors to OpenSSH (at 
http://packetstorm.linuxsecurity.com/UNIX/patches/ for example) that 
you can use to log those. Just remove the password backdoor from those 
and you have a good user/password logger.

Regards

Javier
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.