4 ms·
Today someone tried violetta, admin123, rian, phoebe, carlos, calla, es, weiguo, bzrx1098ui and many more on one of my servers. I guess attackers has gotten a
by nelgaard 4y ago
Today someone tried violetta, admin123, rian, phoebe, carlos, calla, es, weiguo, bzrx1098ui and many more on one of my servers.
I guess attackers has gotten a hacked password file and hope that some of the users have used the same username and password combinations on other servers.
Searching for bzrx1098ui showed that attackers try with the same logins on many servers. E.g.,
https://dataplane.org/signals/sshidpw.txt https://dataplane.org/signals/sshidpw.txt
Most of the passwords on that list are silly, but not all of them
E.g.:
)w%WLq^3UAwn
75afaf6480ca5f9c214fabb6e3663813
7h4a5n9d0a2oiang@))*
960c3dac4fa81b4204779fd16ad7c954f95942876b9c4fb1a255667a9dbe389d
The last one is used at:
https://github.com/tlaverdure/laravel-echo-server/issues/273 https://github.com/tlaverdure/laravel-echo-server/issues/273
and
https://www.digitalocean.com/community/tutorials/how-to-secure-your-redis-installation-on-ubuntu-14-04 https://www.digitalocean.com/community/tutorials/how-to-secu...
Which mentions that is can be generated as:
echo "digital-ocean" | sha256sum
Apparently Digital Ocean was telling people in 2014, that feeding a weak password to a hash function would result in a longer and therefore very strong password.
I am sure there are plenty of people that would use sha256sum("password")= 6b3a55e0261b0304143f805a24924d0c1c44524821305f31d9277843b8a10f4e
as a password in a redis-file. But it is not something you would type in every time you ran SSH.
So maybe someone is just trying to use a search engine to find passwords made public.