Wall of shame: latest 5 SSH password attacks.

Lately my logs have been flooded by SSH password database attacks. Kids who try this probably think they are true 31337 h4x0rs now that they have downloaded that little brute force tool - all by themselves! One day, when they get a little older, they might realize this type of attack is so lame (sorry, l4m3 that is!), that they should be very much 4sh4m3d!

I don't like lugging an SSH key around (wrong, I know), so I refuse to disable password authentication just for these kids. Instead, I installed an excellent countermeasure named fail2ban. It works so well, I decided to show the results here for all to see, using small php and shell scripts. Note that the listed IP's are not necessarily actual h4x0r IP addresses. Most of them appear to be machines that have been compromised themselves.

Compromised machines probably have users named info, service, mysql, student, root, test etc... or ahmed, alan, albert, alberto, alex, alfred, ali, alice, allan, andi, andrew... (you get the idea) with guessable passwords. Anyone out of ideas to name their child, drop me a line and I'll send you some logs from before I installed fail2ban... :-)

UPDATE: Recently, things have become a bit more grim and grown beyond the scr1pt k1dd13 realm, as these types of attacks are now commonly used to install Trojans for use in botnets. Besides obvious uses like sending spam or 'hacking' even more machines like yours, these botnets can be a powerful tool in destructive DoS attacks and such. Your machine may be actively participating in computer terrorism without you even knowing!

On 08-12 12:19  ( ) from China launched an attempt.
On 08-12 12:16 ( ) from Singapore launched an attempt.
On 08-12 10:39 190-48-108-233.speedy.com.ar ( ) from Argentina launched an attempt.
On 08-12 09:59  ( ) from China launched an attempt.
On 08-12 09:43 ( ) from ddress not found launched an attempt.

