5 ms·
Still being attacked constantly. I gotta admit that I am a bit confused with the user names chosen: CISCO, User, adempiere, admin1, adminstrator, alarm, alem,
by protomyth 4y ago
Still being attacked constantly. I gotta admit that I am a bit confused with the user names chosen:
CISCO, User, adempiere, admin1, adminstrator, alarm, alem, amanda, ansible, apache2, apc, arma3server, as, assembla, azure, azureuser, bamboo, bilbomeakine, bill, blackvoid, carlos, cds, centos, chinochan, cloud, cloudera, codeship, contributor, csgo, csgoserver, csserver, debian, default, demo, deployer, dev, device, devops, docker, dominion, ec2, ec2-user, ecs, elastic, elasticsearch, elsearch, engineer, es, esuser, eurek, for, ftp, ftp_admin, ftp_user, ftpadmin, ftpserver, ftptest, ftpuser, git, gitlab, glassfish, gmodserver, gpadmin, grav, grid, guest, hadoop, hduser, hostmetrics, jboss, jenkins, jira, john, joomla, junkbust, kafka, kevin, kibana, kubernetes, lighthouse, linkl, linkxess, localadmin, mail, marketing, mc, mcserv, mcserver, michael, mike, minecraft, momo, mongodb, netgear, netscreen, nexus, odoo, office, opc, oper, oracle, osm, osmc, pi, port, postgres, pvm, r00t, redmine, rust, rustserver, sanlang, secscan, service, spark, sphinx, squid, steam, steve, suhelper, super, support, svn, svpilot, systemd, systems, systemx, tbnet, teamspeak3, telecomadmin, test, test2, test3, test4, test6, test7, testftp, testuser, tomcat, ts3, ts3bot, ts3server, ubnt, ubuntu, uftp, upload, uploader, user, usuario, uucp, vagrant, vpn, vpnssh, web, webadmin, weblogic, wordpress, wp, wy, xbmc, xinyi, z, zabbix, zerotier-one, zyfwp
I get the basic service names, but what the heck is going on with "z" and "kevin"?
- klhutchins 4y agoIt probably worked once
- jareklupinski 4y agoah yes, the elders of the internet: amanda, bill, carlos, eurek, john, kevin, michael (mike), steve, and zyfwp
- nelgaard 4y agoToday someone tried violetta, admin123, rian, phoebe, carlos, calla, es, weiguo, bzrx1098ui and many more on one of my servers. I guess attackers has gotten a hacked password file and hope that some of the users have used the same username and password combinations on other servers. Searching for bzrx1098ui showed that attackers try with the same logins on many servers. E.g., https://dataplane.org/signals/sshidpw.txt https://dataplane.org/signals/sshidpw.txt Most of the passwords on that list are silly, but not all of them E.g.: )w%WLq^3UAwn 75afaf6480ca5f9c214fabb6e3663813 7h4a5n9d0a2oiang@))* 960c3dac4fa81b4204779fd16ad7c954f95942876b9c4fb1a255667a9dbe389d The last one is used at: https://github.com/tlaverdure/laravel-echo-server/issues/273 https://github.com/tlaverdure/laravel-echo-server/issues/273 and https://www.digitalocean.com/community/tutorials/how-to-secure-your-redis-installation-on-ubuntu-14-04 https://www.digitalocean.com/community/tutorials/how-to-secu... Which mentions that is can be generated as: echo "digital-ocean" | sha256sum Apparently Digital Ocean was telling people in 2014, that feeding a weak password to a hash function would result in a longer and therefore very strong password. I am sure there are plenty of people that would use sha256sum("password")= 6b3a55e0261b0304143f805a24924d0c1c44524821305f31d9277843b8a10f4e as a password in a redis-file. But it is not something you would type in every time you ran SSH. So maybe someone is just trying to use a search engine to find passwords made public.
- throwaway29303 4y agoZ? Maybe from the russians with their Z symbol[0]? It depends on how recent that Z logging is. And kevin could be a homage to Kevin Mitnick[0]. Or maybe it's common in a certain region? Just my 2 cents. [0] - https://en.wikipedia.org/wiki/Z_(military_symbol) https://en.wikipedia.org/wiki/Z_(military_symbol) [1] - https://en.wikipedia.org/wiki/Kevin_Mitnick https://en.wikipedia.org/wiki/Kevin_Mitnick