An attacker recently gained access to my honeypot, and began uploading hack tools using wget.
While his hack tools did not actually infect anything, I retained a copy for evaluation, and even gained access to his FTP server which contained all of his tools.
The available tools in this attacker's bag of tricks is quite interesting.
This Blog has Moved!
This blog is moving to
Thank you for visiting! Content will remain here for archival purposes.
A look at a simple SSH probe and password crack
Here's an annotated look at how an attacker using a SSH password cracker compromises servers.
First the attacker probes to see if SSH is accepting connections. Most likely the scanner also attempted to fingerprint the IP address to identify the operating system. This is most likely an automated process on a compromised system.
2011-10-05 05:08:56-0400 [kippo.core.honeypot.HoneyPotSSHFactory] New connection: 221.176.11.13:35868 (192.168.1.165:22) [session: 0]
2011-10-05 05:08:56-0400 [HoneyPotTransport,0,221.176.11.13] connection lost
Next the attacker begins attempting to crack the SSH password for the root user. Once again these attempts are automated, and use a cracking tool which is based upon SSH-2.0-libssh-0.11.
Ingredients:
Hacking,
Honeypots,
Linux,
Project Picnic Basket
Flash Drives: Helping Spread Malware since Y2K
Flash drives are an ever growing threat in the computer industry. They are quickly becoming one of the most targeted infection methods for malware.
Does your organization have a policy to address the vulnerabilities associated with USB Flash Drives?
In this case, Dilbert says it best.
See Also: ENISA USB Flash Drive Whitepaper hosted by Sandisk
Does your organization have a policy to address the vulnerabilities associated with USB Flash Drives?
In this case, Dilbert says it best.
See Also: ENISA USB Flash Drive Whitepaper hosted by Sandisk
Subscribe to:
Posts (Atom)
