Full Disclosure mailing list archives

RE: SSH Scans - Homebrew dictionary


From: "php0t" <very () unprivate com>
Date: Fri, 17 Mar 2006 12:55:04 +0100


Google a couple of words that were tried, and you'll probably find the
whole list.

Fun: make a valid user/pass that is likely to come up based on that
dictionary.
For ftp, just check out what they upload. For SSH, just force them to
use a screened shell and watch what they're trying to do and when you
get bored with it or just simply don't like what you see, you can always
filter outgoing data or just disconnect the poor bastard. Manual
honeypot, we could say.. :-)

  ciao
php0t



-----Original Message-----
From: full-disclosure-bounces () lists grok org uk
[mailto:full-disclosure-bounces () lists grok org uk] On Behalf Of Michel
Pereira
Sent: Friday, March 17, 2006 12:33 PM
To: full-disclosure () lists grok org uk
Subject: Re: [Full-disclosure] SSH Scans - Homebrew dictionary


   Hey Perfect Material, I'm Brazilian too :)
   I'm not racist with my own country, I only talk about it because the
various Brazilian words that is in the log files and hosts that come the
scans.

Bye

On 3/17/06, PERFECT. MATERIAL <perfect.material () gmail com> wrote:

Michel,

I highly doubt any Brazilian citizen would be involved with such 
malicious behavior. Please rescind your inflammatory and racist 
statement or risk gaining a reputation as a person who dislikes his 
fellow brown person. It's because of people like you that Eazy-E died 
of AIDS.

PERFECT.MATERIAL

I


On 3/16/06, Michel Pereira <michel () michel eti br> wrote:

  After of seeing a lot of ssh scans on my firewalls and home PC, I 
made a script that filters out the "Invalid User" entry inside 
/var/log/messages and do some cleaning process, the result is a 
dictionary (homebrew) of users that tried to login into my hosts.
  Into the dictionary I saw english and Brazilian Portuguese words, 
maybe we have Brazilian hackers running scan bots too.
  This work is only for experiment and curiosity to see what is 
happening with Internet today, you can get the script and dictionary 
in http://www.michel.eti.br/2006/03/ssh-scans.html

  If you have a better idea of sugestion, please mail me: 
"michel () michel eti br"

Bye
--
Só Jesus salva,o homem faz backups.
 http://www.michel.eti.br

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/




--
Só Jesus salva,o homem faz backups.
http://www.michel.eti.br

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Current thread: