Dumb brute force attacks slowing down, dying off

Powered by SC Magazine
 

Hail Mary, it’s happening again.

The number of “lame” brute force Secure Shell (SSH) attacks are in decline as honeypots over the weekend detected fewer attempts against them.

SANS Institute analyst Tom Liston noticed the strange activity when a string of IP addresses tried to access his SSH box with the username 'root' and password 'ihatehackers'.

The attacks are typically slow between bouts.

The strange attacks were similarly detected by Norwegian system administrator Peter Hansteen in 2008. The traffic was composed of Linux machines compromised by the dt_ssh5_malware bug and joined together in what he dubbed a “Hail Mary Cloud”.

In 2009, Hansteen received 6000 attack attempts from 770 IP addresses over four days.

More recently, his machines received 4773 failed intrusion attempts using 944 usernames from 338 separate addresses at the time.

But known brute force attacks of the same style over the last three years had been sent from thousands of IP addresses, indicating the number of infected machines in the cloud may be dwindling, Hansteen said.

Hansteen published a list of offending IP addresses and urged administrators to check and compare their traffic logs.

Liston publishes attacks against his honepot under the Twitter account @netmenaces and will soon update the feed to include the SSH attacks.

Copyright © SC Magazine, Australia


Dumb brute force attacks slowing down, dying off
 
 
 
Top Stories
First look: Microsoft Outlook for iOS
[Update] Office productivity suite for iOS completed with Outlook.
 
NewSat defaults on $26m in overdue Lockheed payments
Jabiru-1 satellite build hits further hurdles.
 
IBM denies plans to cut 112k jobs
But admits to further restructuring.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest Comments
Polls
Who do you trust most to protect your private data?







   |   View results
Your bank
  36%
 
Your insurance company
  5%
 
A technology company (Google, Facebook et al)
  9%
 
Your telco, ISP or utility
  8%
 
A retailer (Coles, Woolworths et al)
  4%
 
A Federal Government agency (ATO, Centrelink etc)
  18%
 
An Australian law enforcement agency (AFP, ASIO et al)
  14%
 
A State Government agency (Health dept, etc)
  7%
TOTAL VOTES: 3086

Vote
Do you support the abolition of the Office of the Information Commissioner?

   |   View results
I support shutting down the OAIC.
  27%
 
I DON'T support shutting the OAIC.
  73%
TOTAL VOTES: 982

Vote