Re: SSH bruteforce on its way...
Javier Fernandez-Sanguino <[email protected]>
| Newsgroups | gmane.comp.security.incidents |
|---|---|
| Organization | Germinus |
| Message-ID | <[email protected]> |
[email protected] wrote: > Hi Volker, > > ive started a honey Machine for your answer on, what are they doing with captured machines ... I would also be interesting to list what _accounts_ they probe for. I have a list of users/passwords recovered from some compromised systems and I'm working on a trojaned version of OpenSSH that would log that info regardless of authentication method. There are some patches to add backdoors to OpenSSH (at http://packetstorm.linuxsecurity.com/UNIX/patches/ for example) that you can use to log those. Just remove the password backdoor from those and you have a good user/password logger. Regards Javier