GREPWISE

A bot broke in and checked whether I was real

Captured on a server exposed this morning. After a successful login the bot profiled the hardware, then ran a sequence that writes a file, makes it executable and runs it, to work out whether the shell was genuine before committing.

A bot got in. First it checked whether I was real.

I put a server online this morning and recorded every keystroke that reached it. First contact came after twelve minutes. When a login finally succeeded, nothing was destroyed. The machine got interviewed instead.

This is the log itself, one line per event, timestamps included. Failed attempts as root, one every few minutes. Then, at eight thirty and forty four seconds, one gets through. One second later the first command arrives. It reads the hardware and looks for a graphics card, which is capacity assessment rather than vandalism. Then it writes a small file, makes it executable and runs it, purely to find out whether this shell is genuine or a trap.

Modern attackers screen their targets. If the box looks fake, they move on. Nothing here was retyped for the camera; the strings come out of the log with grep.

This is the raw log, not a reconstruction.

#linux#security#honeypot#ssh#sysadmin

❯ This is the raw log, not a reconstruction.

cd ..