They broke in and did nothing
Fifteen days on a single honeypot: 61,751 failed logins, 36,978 sessions that got in, and only 556 sessions that typed even one command. Most credential guessing is not an attack in progress. It is inventory being collected, to be used or sold later.
Thirty-six thousand nine hundred successful logins. Five hundred and fifty-six of them typed anything at all.
A break-in sounds like an event. Something gets installed, something gets stolen, something breaks.
Fifteen days on one machine. Sixty-one thousand failed attempts, and thirty-six thousand nine hundred and seventy-eight sessions that got in.
Of those, five hundred and fifty-six typed a single command. Eight hundred and twenty-seven commands in total, across all of them.
That is one and a half percent. The other ninety-eight and a half percent logged in, saw that the password worked, and disconnected.
They were not here to use the server. They were here to confirm the password and write it down. Someone else uses it later, or buys it.
A working password is worth something before anyone uses it.
#linux#security#ssh#infosec#sysadmin
❯ A working password is worth something before anyone uses it.