PaulDotCom mailing list archives

F'ing with SSH Goons


From: gbugbear at gmail.com (Tim Mugherini)
Date: Tue, 9 Dec 2008 06:53:14 -0500

I'm all for keeping it simple

Login banner with the middle finger

T

On 12/9/08, David A. Gershman <dagershman_dgt at dagertech.net> wrote:

How about a auto-login script that grabs their IP and returns the
favor...or some other DoS type irritation.

Personally I don't screw with them at all, instead, I have a monitor
which detects the attack and blocks their IP *completely* from the
server.  They think they crashed it but my users are still good to
go...everyone's happy.  Maybe if they "succeed" enough times they'll get
bored and stop???  *sigh* I can dream can't I?



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hej all



So for fun yesterday I put ssh back on port 22 from my usual obscure
port. Within 5hrs I had someone dictionary attacking my box from the UK
(surprise surprise it wasn't China).

Now I'm all about defense and generally not into inviting trouble,
however, I was wondering if there is anything fun you can do with those
types.

I was thinking of creating a common user name with a blank passwd and
then sending a tty message to them after they went interactive, because
honestly it would make me smile a lot just to see them logoff in fright
after seeing me see them.

That is fun and all but does any one know of other fun stuff for
screwing with these jokers?




all the best

/adese
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.9 (Darwin)

iEYEARECAAYFAkk93J8ACgkQSsV9wg1YVSIVOwCfYbEt0n7+LQUqQFpTbtIysFp0
REIAoL288FBwSm/UsHpvVDOq+aRGaFbm
=iriR
-----END PGP SIGNATURE-----
_______________________________________________
Pauldotcom mailing list
Pauldotcom at mail.pauldotcom.com
http://mail.pauldotcom.com/cgi-bin/mailman/listinfo/pauldotcom
Main Web Site: http://pauldotcom.com



---------------
David A. Gershman
gershman at dagertech.net
http://dagertech.net/gershman/
"It's all about the path!" --d. gershman
_______________________________________________
Pauldotcom mailing list
Pauldotcom at mail.pauldotcom.com
http://mail.pauldotcom.com/cgi-bin/mailman/listinfo/pauldotcom
Main Web Site: http://pauldotcom.com


-- 
Sent from my mobile device


Current thread: