[vox] interesting probes
Gandalf Parker
gandalf at any1can.net
Mon Apr 26 07:51:54 PDT 2010
I tend to run my servers in a semi-honeypot mode. Mostly by allowing both
ssh and telnet to watch the results.
Lately in the ssh probes, Ive noticed a change. In the top few it seems
that oracle has taken the lead from such standards as admin, test, user,
ftpuser, and ssh (ssh used as a login). Im not sure why the shift but I
thought it worth mentioning.
BTW I highly recommend that if you have a computer online, and you plan to
add a service, check your historical logs. The auth.log and web logs can
give you a heads up if there is a commonly known problem you should
research.
Gandalf Parker
More information about the vox
mailing list