Harvesting SSH Credentials: Insights from My Honeypot Network

uphillsecurity.com

25 points by whatbackup 3 hours ago


pastage - 8 minutes ago

Last time I saw this an obscure single letter root password was still "secure", now days seems like almost all non-alphanumeric chars works. % is my new root password it still has not been brute forced.

daneel_w - 2 hours ago

No "credentials" are being "harvested" here. It's all worthless data, save for the statistics.

0cf8612b2e1e - 2 hours ago

Do most installations create a git user account with login permissions?

asveikau - 2 hours ago

Having a root password of "toor" is very clever. Nobody will figure that one out.