lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Fri Mar 17 11:55:06 2006
From: very at unprivate.com (php0t)
Subject: SSH Scans - Homebrew dictionary


Google a couple of words that were tried, and you'll probably find the
whole list.

Fun: make a valid user/pass that is likely to come up based on that
dictionary.
For ftp, just check out what they upload. For SSH, just force them to
use a screened shell and watch what they're trying to do and when you
get bored with it or just simply don't like what you see, you can always
filter outgoing data or just disconnect the poor bastard. Manual
honeypot, we could say.. :-)

  ciao
php0t



-----Original Message-----
From: full-disclosure-bounces@...ts.grok.org.uk
[mailto:full-disclosure-bounces@...ts.grok.org.uk] On Behalf Of Michel
Pereira
Sent: Friday, March 17, 2006 12:33 PM
To: full-disclosure@...ts.grok.org.uk
Subject: Re: [Full-disclosure] SSH Scans - Homebrew dictionary


   Hey Perfect Material, I'm Brazilian too :)
   I'm not racist with my own country, I only talk about it because the
various Brazilian words that is in the log files and hosts that come the
scans.

Bye

On 3/17/06, PERFECT. MATERIAL <perfect.material@...il.com> wrote:
>
> Michel,
>
> I highly doubt any Brazilian citizen would be involved with such 
> malicious behavior. Please rescind your inflammatory and racist 
> statement or risk gaining a reputation as a person who dislikes his 
> fellow brown person. It's because of people like you that Eazy-E died 
> of AIDS.
>
> PERFECT.MATERIAL
>
> I
>
>
> On 3/16/06, Michel Pereira <michel@...hel.eti.br> wrote:
> >
>   After of seeing a lot of ssh scans on my firewalls and home PC, I 
> made a script that filters out the "Invalid User" entry inside 
> /var/log/messages and do some cleaning process, the result is a 
> dictionary (homebrew) of users that tried to login into my hosts.
>   Into the dictionary I saw english and Brazilian Portuguese words, 
> maybe we have Brazilian hackers running scan bots too.
>   This work is only for experiment and curiosity to see what is 
> happening with Internet today, you can get the script and dictionary 
> in http://www.michel.eti.br/2006/03/ssh-scans.html
>
>   If you have a better idea of sugestion, please mail me: 
> "michel@...hel.eti.br"
>
> Bye
> --
> S? Jesus salva,o homem faz backups.
>  http://www.michel.eti.br
>
> _______________________________________________
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/
>
>


--
S? Jesus salva,o homem faz backups.
http://www.michel.eti.br

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ