[vox] interesting probes

Gandalf Parker gandalf at any1can.net
Mon Apr 26 07:51:54 PDT 2010


I tend to run my servers in a semi-honeypot mode. Mostly by allowing both 
ssh and telnet to watch the results.

Lately in the ssh probes, Ive noticed a change. In the top few it seems 
that oracle has taken the lead from such standards as admin, test, user, 
ftpuser, and ssh (ssh used as a login). Im not sure why the shift but I 
thought it worth mentioning.

BTW I highly recommend that if you have a computer online, and you plan to 
add a service, check your historical logs. The auth.log and web logs can 
give you a heads up if there is a commonly known problem you should 
research.

Gandalf  Parker





More information about the vox mailing list