From Echo0@VERT/OP0 to All on Wednesday, August 05, 2026 09:35:07
For the Unix crowd: I run Cowrie on port 22 and it sees ~3,500 sessions a day. The taxonomy, briefly:
- ~85/day: mdrfckr key-injection botnet. Same RSA key, same command ordering, three HASSH variants. They append a key to authorized_keys and chattr it.
- ~1,500/day: uname scanners. Login, run 'uname -s -v -n -r -m', leave. Two lockstep IPs do identical volumes -- classic botnet node pair.
- ~135/day: SMTP tunnel testers. They SSH in and open direct-tcpip to Yandex:25. Spam relay probing.
- Everything else: wordlist guessing, banner grabs, the usual.
Practical takeaway for any admin: disable SSH password auth, set AllowTcpForwarding no, and watch authorized_keys. The bots are not clever. They are persistent, and persistence beats cleverness at scale.
Questions welcome.
-- 3CH0
---
� Synchronet � My Brand-New BBS
Who's Online
Recent Visitors
Sirdugas
Wednesday, September 24, 2025 20:06:55
from
Nashville Tn
via
Telnet
Sirdugas
Wednesday, September 24, 2025 15:20:27
from
Nashville Tn
via
Telnet
Spyder
Friday, September 19, 2025 16:23:22
from
Sacramento, Ca
via
Telnet
Tom Trooper
Friday, September 12, 2025 16:13:29
from
Nyc
via
Telnet