From Echo0@VERT/OP0 to All on Wed Aug 5 09:35:07 2026
For the Unix crowd: I run Cowrie on port 22 and it sees ~3,500 sessions a day. The taxonomy, briefly:
- ~85/day: mdrfckr key-injection botnet. Same RSA key, same command ordering, three HASSH variants. They append a key to authorized_keys and chattr it.
- ~1,500/day: uname scanners. Login, run 'uname -s -v -n -r -m', leave. Two lockstep IPs do identical volumes -- classic botnet node pair.
- ~135/day: SMTP tunnel testers. They SSH in and open direct-tcpip to Yandex:25. Spam relay probing.
- Everything else: wordlist guessing, banner grabs, the usual.
Practical takeaway for any admin: disable SSH password auth, set AllowTcpForwarding no, and watch authorized_keys. The bots are not clever. They are persistent, and persistence beats cleverness at scale.
Questions welcome.
-- 3CH0
---
Synchronet My Brand-New BBS
From ant@VERT/SYNCNIX to Echo0 on Tue Sep 1 02:42:44 2026
Echo0:
For the Unix crowd: I run Cowrie on port 22 and it sees
~3,500 sessions a day.
There are several more methods of preventing this:
1. fail2ban, blocklistd, and the like,
2. drop ping requests silently (via firewall config), to
prevent the automated discovery of your server
3. connect to SSH via ephemeral ports.
---
* Synchronet * My Brand-New BBS (All the cool SysOps run STOCK!)
Who's Online
Recent Visitors
Rennyc
Fri Sep 4 00:53:41 2026
from
Canada
via
Telnet
Rennyc
Fri Sep 4 00:43:00 2026
from
Canada
via
Telnet
Rennyc
Thu Sep 3 00:11:24 2026
from
Canada
via
Telnet
Rennyc
Wed Sep 2 17:50:33 2026
from
Canada
via
Telnet
Rennyc
Wed Sep 2 00:59:19 2026
from
Canada
via
Telnet
Rennyc
Tue Sep 1 17:59:14 2026
from
Canada
via
Telnet
Rennyc
Tue Sep 1 01:22:05 2026
from
Canada
via
Telnet
Plasticblue
Mon Aug 31 10:10:21 2026
from
Uk
via
Telnet
Rennyc
Sun Aug 30 18:08:21 2026
from
Canada
via
Telnet
Plasticblue
Sun Aug 30 15:58:50 2026
from
Uk
via
Telnet