Full Disclosure mailing list archives
RE: SSH Scans - Homebrew dictionary
From: "php0t" <very () unprivate com>
Date: Fri, 17 Mar 2006 12:55:04 +0100
Google a couple of words that were tried, and you'll probably find the whole list. Fun: make a valid user/pass that is likely to come up based on that dictionary. For ftp, just check out what they upload. For SSH, just force them to use a screened shell and watch what they're trying to do and when you get bored with it or just simply don't like what you see, you can always filter outgoing data or just disconnect the poor bastard. Manual honeypot, we could say.. :-) ciao php0t -----Original Message----- From: full-disclosure-bounces () lists grok org uk [mailto:full-disclosure-bounces () lists grok org uk] On Behalf Of Michel Pereira Sent: Friday, March 17, 2006 12:33 PM To: full-disclosure () lists grok org uk Subject: Re: [Full-disclosure] SSH Scans - Homebrew dictionary Hey Perfect Material, I'm Brazilian too :) I'm not racist with my own country, I only talk about it because the various Brazilian words that is in the log files and hosts that come the scans. Bye On 3/17/06, PERFECT. MATERIAL <perfect.material () gmail com> wrote:
Michel, I highly doubt any Brazilian citizen would be involved with such malicious behavior. Please rescind your inflammatory and racist statement or risk gaining a reputation as a person who dislikes his fellow brown person. It's because of people like you that Eazy-E died of AIDS. PERFECT.MATERIAL I On 3/16/06, Michel Pereira <michel () michel eti br> wrote:After of seeing a lot of ssh scans on my firewalls and home PC, I made a script that filters out the "Invalid User" entry inside /var/log/messages and do some cleaning process, the result is a dictionary (homebrew) of users that tried to login into my hosts. Into the dictionary I saw english and Brazilian Portuguese words, maybe we have Brazilian hackers running scan bots too. This work is only for experiment and curiosity to see what is happening with Internet today, you can get the script and dictionary in http://www.michel.eti.br/2006/03/ssh-scans.html If you have a better idea of sugestion, please mail me: "michel () michel eti br" Bye -- Só Jesus salva,o homem faz backups. http://www.michel.eti.br _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
-- Só Jesus salva,o homem faz backups. http://www.michel.eti.br _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/ _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- SSH Scans - Homebrew dictionary Michel Pereira (Mar 16)
- Re: SSH Scans - Homebrew dictionary PERFECT . MATERIAL (Mar 16)
- Re: SSH Scans - Homebrew dictionary Michel Pereira (Mar 17)
- RE: SSH Scans - Homebrew dictionary php0t (Mar 17)
- Re: SSH Scans - Homebrew dictionary Dave Korn (Mar 17)
- Re: SSH Scans - Homebrew dictionary Michel Pereira (Mar 17)
- Re: SSH Scans - Homebrew dictionary Fajar Edisya Putera (Mar 17)
- <Possible follow-ups>
- RE: SSH Scans - Homebrew dictionary Michael L. Benjamin (Mar 16)
- Re: SSH Scans - Homebrew dictionary PERFECT . MATERIAL (Mar 16)