Register   Login       Forum   Search   Help  

Post new topic Reply to topic
The Web Hosting Forum > Security > Daily Hacking Attempts the Norm?

Author Thread
Thermit
Site Admin


Joined: 11 Aug 2004
Posts: 272
Daily Hacking Attempts the Norm?  Reply with quote  

Since becoming a host, one of the things that surprised me the most is the regularity of attempts to gain unauthorized access to my server.

It's a daily affair.

Anyone else familiar with this kind of thing?

quote:

Failed logins from these:
adm/password from 140.116.72.125: 4 Time(s)
admin/password from 220.70.167.67: 20 Time(s)
andrew/password from 210.177.195.245: 11 Time(s)
angel/password from 210.177.195.245: 10 Time(s)
apache/password from 140.116.72.125: 2 Time(s)
barbara/password from 210.177.195.245: 10 Time(s)
ben/password from 210.177.195.245: 11 Time(s)
betty/password from 210.177.195.245: 10 Time(s)
billy/password from 210.177.195.245: 10 Time(s)
black/password from 210.177.195.245: 10 Time(s)
blue/password from 210.177.195.245: 10 Time(s)
brandon/password from 210.177.195.245: 10 Time(s)
brian/password from 210.177.195.245: 10 Time(s)
buddy/password from 210.177.195.245: 10 Time(s)
carmen/password from 210.177.195.245: 11 Time(s)
charlie/password from 210.177.195.245: 10 Time(s)
chem/password from 172.137.216.65: 1 Time(s)
cyrus/password from 140.116.72.125: 6 Time(s)
daniel/password from 210.177.195.245: 11 Time(s)
david/password from 210.177.195.245: 11 Time(s)
dog/password from 210.177.195.245: 10 Time(s)
emily/password from 210.177.195.245: 10 Time(s)
eric/password from 210.177.195.245: 10 Time(s)
god/password from 210.177.195.245: 10 Time(s)
green/password from 210.177.195.245: 10 Time(s)
guest/password from 220.70.167.67: 10 Time(s)
henry/password from 210.177.195.245: 10 Time(s)
horde/password from 140.116.72.125: 6 Time(s)
host/password from 172.137.216.65: 1 Time(s)
iceuser/password from 140.116.72.125: 6 Time(s)
irc/password from 140.116.72.125: 4 Time(s)
jane/password from 140.116.72.125: 1 Time(s)
jane/password from 210.177.195.245: 10 Time(s)
jason/password from 210.177.195.245: 11 Time(s)
jeremy/password from 210.177.195.245: 10 Time(s)
joe/password from 210.177.195.245: 10 Time(s)
johnny/password from 210.177.195.245: 10 Time(s)
jordan/password from 210.177.195.245: 12 Time(s)
justin/password from 210.177.195.245: 11 Time(s)
larisa/password from 210.177.195.245: 10 Time(s)
lion/password from 210.177.195.245: 11 Time(s)
lp/password from 210.177.195.245: 10 Time(s)
lucy/password from 210.177.195.245: 10 Time(s)
magic/password from 210.177.195.245: 11 Time(s)
mail/password from 210.177.195.245: 10 Time(s)
maria/password from 210.177.195.245: 10 Time(s)
market/password from 210.177.195.245: 10 Time(s)
matt/password from 140.116.72.125: 4 Time(s)
matthew/password from 210.177.195.245: 11 Time(s)
max/password from 210.177.195.245: 10 Time(s)
michael/password from 210.177.195.245: 12 Time(s)
money/password from 172.137.216.65: 1 Time(s)
mysql/password from 140.116.72.125: 2 Time(s)
nathan/password from 210.177.195.245: 11 Time(s)
nicholas/password from 210.177.195.245: 10 Time(s)
nicole/password from 210.177.195.245: 11 Time(s)
nobody/password from 140.116.72.125: 11 Time(s)
operator/password from 140.116.72.125: 2 Time(s)
operator/password from 210.177.195.245: 10 Time(s)
patrick/password from 140.116.72.125: 19 Time(s)
pub/password from 210.177.195.245: 10 Time(s)
red/password from 210.177.195.245: 10 Time(s)
robin/password from 210.177.195.245: 10 Time(s)
rolo/password from 140.116.72.125: 6 Time(s)
root/password from 140.116.72.125: 42 Time(s)
root/password from 220.70.167.67: 30 Time(s)
rose/password from 210.177.195.245: 10 Time(s)
shell/password from 210.177.195.245: 10 Time(s)
stephen/password from 210.177.195.245: 10 Time(s)
steven/password from 210.177.195.245: 10 Time(s)
surprise/password from 172.137.216.65: 1 Time(s)
system/password from 210.177.195.245: 10 Time(s)
test/password from 140.116.72.125: 9 Time(s)
test/password from 220.70.167.67: 20 Time(s)
tom/password from 210.177.195.245: 10 Time(s)
user/password from 220.70.167.67: 10 Time(s)
vampire/password from 210.177.195.245: 10 Time(s)
william/password from 210.177.195.245: 10 Time(s)
www-data/password from 140.116.72.125: 2 Time(s)
www/password from 140.116.72.125: 6 Time(s)
wwwrun/password from 140.116.72.125: 4 Time(s)
yellow/password from 210.177.195.245: 10 Time(s)



Post Fri Dec 03, 2004 2:50 pm
 View user's profile Send private message
Euler



Joined: 02 Sep 2004
Posts: 109
 Reply with quote  

Yes. I get them all throughout each day. I used to get rather angry about it. Years ago I became so obsessed, I wrote a script that would recognize the footprints left (in /var/log/messages) by one of these attempts, and then blurt back a big old spoofed, monstrously deformed ARP packet carrying the payload: F U C K O F F Y O U. The whole thing was silly. A misuse of the resource and of my time.

I have since changed my attitude. You know, strictly speaking, it's not illegal for a person to try your ports. It's not out of bounds for someone to try to open a door. No harm, no foul. As long as I'm doing my job, these monkeys can keep fiddling with my locks. It's like rain. Except this kind of rain doesn't help flowers grow or anything.

I guess I'm trying to say it's inevitable, it's large and it's pointless to begrudge it. Like bad weather. It just IS, so we build shelter.

Back when I used to obsess over this, I would chase down each IP that "fucked with me". I found that by far, most of the hack attempts came from China, Nippon, Taiwan, India, and the US.

One way of looking at this - trying to put on my largest mind - is that it's a sure sign of the International proliferation of internet technology. If, as Adams said, Man eventually chooses what's right, these people should eventually tire of the fruitlessness of their blackhat endeavors, and they will find bigger challenges and greener pastures in fulfiling the true mission of technology, which is to help, to augment human capability, not to exploit it.

So, in that view, it becomes a moral imperative to keep a tight and secure network. To ensure that hackers don't experience success so that they will turn back (each according to their internal compass) to the pursuit of constructive goals.


Post Fri Dec 03, 2004 5:18 pm
 View user's profile Send private message
Thermit
Site Admin


Joined: 11 Aug 2004
Posts: 272
 Reply with quote  

That's pretty funny! I wonder if they could even see and read the (english) message?

I agree with your sentiment. It's a moral responsibilty to not tempt our fellow man into doing wrong. For example, leaving the keys in your car is not only stupid, it's a temptation that others could do without.

Another lesson is to never ever ever use "password" as your password Wink , since that seems to be the only one I've ever seen these "monkeys" try. I'm sure it's fairly automated though.


Post Fri Dec 03, 2004 8:10 pm
 View user's profile Send private message

Post new topic Reply to topic
Forum Jump:
Jump to:  

All times are GMT.
The time now is Wed Feb 08, 2012 9:59 pm
  Display posts from previous: