They are not attacking your server
Login attempts recorded on an exposed Linux server. Several of the usernames are factory defaults for network hardware, not for servers, which shows the attempts are sprayed at every address rather than aimed at one machine.
These logins were never meant for a server.
Forty seven login attempts reached a plain Linux box of mine. You would expect root, admin, maybe a service account. Look at what actually arrived.
These are factory credentials for network hardware. One belongs to fibre routers, one to a single board computer, one to wireless gear. None of them exist on this machine and never could. Whoever sent them is not probing a server, they are walking the entire address space and trying every default they have collected, hoping something answers.
That is the useful part. There is no such thing as being too small to attack, because nothing here was aimed at you. If a device of yours still has its factory login, it is already on somebody’s list.
Anything with a default password is already on the list.
#linux#security#iot#sysadmin#selfhosting
❯ Anything with a default password is already on the list.