7 ms·
3 months and 1M SSH attempts later
- tdicola 11y agoIf you haven't already, get fail2ban setup on the box to slow down all the attacks. And disable password login and switch to certs instead.
- sneak 11y agoSSH key based auth does not use certificates. In the case of key-based-auth only, fail2ban is pointless.
- Xorlev 11y agoI wouldn't say pointless. It wastes an attacker's time if nothing else, otherwise you're essentially allowing that attacker to continue interacting with your server, and perhaps SSH isn't their only target.
- muppetman 11y agoI disagree. I run it because I drop all traffic from the /24 the scan comes from. Harsh, yes, but tough luck. It cuts down on unwanted network traffic.
- sneak 11y agoThat's a pretty significant denial of service you open yourself up to. If someone shows up bruteforcing you from randomly allocated AWS or Digital Ocean cloud instance public IPs that happen to land in the same /24 as other AWS- or DO-hosted services (Heroku comes to mind, but also any other monitoring, log aggregation, analytics, data processing, et c) your machine depends on, they've convinced your system to cut connectivity to them. Not the best setup...
- viraptor 11y agoActually it can use certificates. Not X509, but still simplified ones.
- vacri 11y agofail2ban also reduces spam in your auth log and prods the bot to move along to the next target.
- bigiain 11y agoIt can quite easily protect against things other than failed ssh attempts - I used to regularly configure it to blackhole IPs failing to log in correctly to WordPress backends... Anything else the box does that uses some form of authentication that writes out failures to a log file can be hooked up to fail2ban.
- WillieStevenson 11y agotdicola: To authenticate myself, I use an ssh key. However, the goal of this project was to log all attacks over ssh. So setting up fail2ban and disabling password login would prohibit this collection of data. I have a massive password in place, so I'm not worried in the least.
- rmdoss 11y agoBetter yet, deploy OSSEC there. I would recommend it with the latest patches from here: https://dcid.me/ossec/ https://dcid.me/ossec/
- matt_wulfeck 11y agoIt's just another thing you need running on the server that must stay patched forever. In my opinion less is better. RSA/4096-bit key encryption only. I don't even care if you use the root user. The ability for someone to crack a 4096-bit key is impossible in practice, and if your SSH server has a bug then it doesn't matter what fancy things you have setup.
- rmdoss 11y agoIt is fine for a 1-man server, but if you have multiple users and you have to be on top of things, then you need a bit more than that. Specially to look at successful logins and audit where they come from. This is a good blog post on the subject: https://blog.sucuri.net/2016/03/server-security-anomaly-behaviour-with-ossec.html https://blog.sucuri.net/2016/03/server-security-anomaly-beha...
- logotype 11y agoChange the SSH port...
- windowsworkstoo 11y agoThe point was to have a look at what kind of attacks are launched on the general internet, so the point was to be attacked. Also, changing the port does basically nothing these days, with stuff like Shodan around constantly port-scanning.
- WillieStevenson 11y agoLike I mentioned above, changing the SSH port would only lessen the attempts on my box. I am interested in collecting as much data as possible.
- deleted 11y ago[deleted]
- achillean 11y agoPlease don't rely on that alone: https://blog.shodan.io/hiding-in-plain-sight/ https://blog.shodan.io/hiding-in-plain-sight/
- voltagex_ 11y agostrangely, searching Shodan for product:ssh port:443 finds nothing - when I know there are boxes around running sslh or similar to run both SSH and HTTPS on the same port. Seems like you can hide in plain sight when the scanner has no idea you're there.
- achillean 11y agohttps://www.shodan.io/search?query=port%3A80+openssh https://www.shodan.io/search?query=port%3A80+openssh It's really just a matter of time. There are many things you can do to protect yourself and changing the port is one of them, but if you rely on it you're going to have a bad time.
- 11y ago
- cddotdotslash 11y agoJust FYI, I wouldn't log into any systems using credentials you find through this. A lot of people are obviously using credentials stolen from previous dumps, so there might be valid ones in there. Logging into a public facing router using stolen credentials is definitely a crime.
- WillieStevenson 11y agoJust like it's a crime trying to ssh into a box that is not yours right? And besides I didn't do anything to the router. I was simply pointing out that you should change your default credentials and hide your router. ... should be a crime to not change the default credentials.
- simoncion 11y agoDid you attempt to notify that poor schmuck who stood up that AirRouter with the default username and password?
- WillieStevenson 11y agoDamn it. I should of. I don't know how I would do that now though. He probably got pwned of the internet by now. lol.
- abrookewood 11y agoDude, it's not funny. You're coming across like a script kiddie and it's not welcome here. You've just posted the credentials to someone's site that has probably been compromised and you're treating it like a joke. Go back and redact the IP addresses of those sites & devices before you get yourself into trouble.
- simoncion 11y agoUm. I guaran-damn-tee you that the router in question was compromised within a day or seven of it being stood up. The default credentials on every bit of UBNT hardware that I've used grant access to both the web UI and admin SSH access. So, the access attempts that WillieStevenson has noticed coming from that IP are most likely coming from the router itself. I can't see any reasonable reason for redacting the IPs that are making those access attempts, and I see no reason at all for redacting static, factory default usernames and passwords.
- ChuckMcM 11y agoJust for fun I ran an SSH server on a RasPi to basically allow any login and to simulate a Linux shell. And then captured the various things that people tried. If you're wondering what the "standard set" of script kiddy tricks are, I highly recommend it.
- ambiate 11y ago15 years ago, that standard set used to be wget something from packetstormsecurity.org. If no wget: curl it. If no curl: just lynx it. else: move on to the next vulnerable server. Script kiddies were quite lazy back then. I feel old at thirty.
- x0 11y agoHasn't changed for the most part. Though it's either exploit db, some creepy looking .pw site you've never heard of, and once or twice, the zips that github provides. And sometimes they'll just scp their stuff onto the box.
- tlrobinson 11y ago"World's worst hacker" is pretty amusing: https://www.youtube.com/watch?v=oJagxe-Gvpw https://www.youtube.com/watch?v=oJagxe-Gvpw
- ambiate 11y agoIts interesting how many HN users seem to be missing the point of a honeypot. He set this up deliberately to understand the frequency/types of attacks on a random machine on the internet. From my past experience, most of those CN computers are actually US zero day'd/patched running root kits/worms. It just happens to be that CN computers are more likely to be unpatched/running ancient software.
- noobermin 11y ago>From my past experience I'm curious how you know this for sure.
- ambiate 11y agoI plead the fifth. CFAA/RICO/Patriot Act. My hint would be: before decentralized worms, there were IRC hubs. The 'owners' would typically use their native language for the various commands (I know English is used in more than the US, but..). Most of the time, they wouldn't even hide their host name on the IRC server. I guess from a 'being legal' POV: anyone could infect themselves with the same root kit that's on a honeypot and find out quite a bit about the organizers.
- Godel_unicode 11y agoOr just read any botnet takedown report, this is exactly what botnets do. Why bother looking for 0day when root:toor or cisco:cisco works?
- rando289 11y agowhat is a CN computer?
- alanh 11y agoCN = china. So, computers based in china, although I am at a loss as to what the thread parent is saying exactly about "CN computers actually being US". Same with "zero day'd/patched" — aren’t those opposite notions?
- Godel_unicode 11y ago> "Hahahahahaha, a successful login" Congratulations, you just violated the computer fraud and abuse act. Also, bravo for laying out for every reader of this post where they can find the vulnerable router and the credentials they can use to join you in breaking the law. This is the exact opposite of responsible disclosure; people like the author are why we will never get a less draconian cfaa. Thanks for that.
- abrookewood 11y agoMy thoughts exactly ... and he posted the IP addresses, passwords & usernames of the sites he was able to access. Stupid.
- xupybd 11y ago>Congratulations, you just violated the computer fraud and abuse act. How can that be illegal? Granted publishing it should be, but simply testing if someone has left the default password?
- ambiate 11y agoCFAA is very broad. "intentionally accesses a computer without authorization or exceeds authorized access, and thereby obtains— C) information from any protected computer;" A court could see "ambiate was authorized to use the work printer for printing -- ambiate hacked the printer to find out the fax machine number and sent a fax" in an absurd world. This random internet person was never authorized to access this public router. Even if its set to a default username/password. That's the broadness the CFAA. Just because you set your password to 'password99', doesn't mean you get more protections than the person who leaves their Cisco router set to 'cisco'.
- xupybd 11y agoThanks for the info. Interesting, I can see the merit in having broad legal protection to stop people from malicious activity. But that does seem a little too broad.
- 11y ago
- est 11y agoI changed my SSH login banner text to > Permission denied, please try again. To confuse people. No matter failed or successful login, the prompt text will always be like that.
- Godel_unicode 11y agoYou deny them permission, then grant them permission to try again?
- est 11y agoNo matter failed or successful login, the prompt text will always be > Permission denied, please try again
- yeukhon 11y agoShowing off stuff like this is considered stupid, childish and idiotic. Based on the cache version of his publication, I am extremely tempted to report this to the proper authority. Not only you should stop publishing this kind of information, you should stop your project.
- simoncion 11y ago> Showing off stuff like this is considered stupid, childish and idiotic. ... Not only you should stop publishing this kind of information, you should stop your project. I strongly disagree with both sentences.
- pdkl95 11y ago> He's still going at it 100,000 ssh attempts later. I got hit with >100,000 on my main desktop a few years ago when I was procrastinating fixing my heavy-handed fail2ban config. I noticed what was happening first from the lag it was causing. It turns out >10 SSH password attempts/second can eat up a significant portion of my 3GHz "Yorkfield"[1] CPU. It wasn't hard to discover the problem: the logfile was rapidly filling with failed SSH password attempts. This is particularly useless as I have used PasswordAuthentication no for many years. There is no chance that the script was going to gain access, but the system load from the rejections was terrible. So yes, I fixed fail2ban and added a few more "instant-ban" rules against anybody that tries password authentication, but the real fix that was moving sshd to a random port. Invalid SSH connection attempts dropped to approximately zero immediately. It's trivial to find with a port scan, but in practice almost nobody has even bothered. It's probably like the old joke where two hiker see a grizzly bear and one stops to re-tie his shoes. "You can't outrun a grizzly!" "I only have to outrun you." [1] Q9650 (E0); it still works great, even if it's starting to show its age
- tlrobinson 11y agoOut of curiosity, why is your desktop exposed directly to the internet (no NAT/firewall) at all?
- pdkl95 11y agoNAT doesn't provide security, and a ssh server isn't useful if you filter that port at the firewall.
- julie1 11y agoMasquerading private address with you GW public address and limit connection to outhoing one when ingress filtering is correctly done on your firewall/ISP side is quite efficient. Using private address is just a convenient way to set up easy invariant templates for FW rules. No more, no less. If you add the fact that ISP used to not route RFC 1918, it used to work quite efficiently.
- obisw4n 11y agoI think more cloud providers should do something like what Google Compute Cloud does, they have SSHGuard on their images by default so IPs get blocked after too many failed attempts.