Most common account names used in ssh brute force attacks

Posted by Charles Stewart on Server Fault See other posts from Server Fault or by Charles Stewart
Published on 2010-04-06T09:23:00Z Indexed on 2010/04/06 9:23 UTC
Read the original article Hit count: 511

Filed under:
|
|

Does anyone maintain lists of the most frequently guessed account names that are used by attackers brute-forcing ssh?

For your amusement, from my main server's logs over the last month (43 313 failed ssh attempts), with root not getting as far as sshd:

cas@txtproof:~$ grep -e sshd /var/log/auth* | awk ' { print $8 }' | sort | uniq -c | sort | tail -n 13
     32 administrator
     32 stephen
     34 administration
     34 sales
     34 user
     35 matt
     35 postgres
     38 mysql
     42 oracle
     44 guest
     86 test
     90 admin
  16513 checking

© Server Fault or respective owner

Related posts about brute-force-attacks

Related posts about ssh