GREPWISE

What they actually guess

Every login attempt recorded on an exposed server, counted. Two account names account for most of the traffic, and the passwords are the short obvious ones rather than anything sophisticated.

86 login attempts. Two usernames cover three quarters of them.

People imagine attackers enumerating clever account names. The recorded attempts say otherwise, and the shape of the list has a direct consequence for how you configure a server.

Eighty six attempts. Root, forty times. Admin, twenty five. Together that is three quarters of everything that arrived. Then a long tail of names tried once or twice. The passwords are just as unremarkable: admin, password, one two three four five six seven eight, and the same again shorter. Nothing sophisticated, because sophistication is not needed at this volume.

That makes the countermeasure obvious. Disable direct root login and the single largest slice becomes unusable no matter how many times it is tried. Require keys and the rest stops mattering too.

Disable root login and the largest slice stops mattering.

#linux#security#ssh#passwords#sysadmin

❯ Disable root login and the largest slice stops mattering.

cd ..