Based on reader feedback, I decided to take a&#;x26;#;xc2;&#;x26;#;xa0;look at usernames submitted to honeypots. The usernames that are seen on a daily basis look very familiar.&#;x26;#;xc2;&#;x26;#;xa0;They tend to come from default user accounts, such as “administrator” on Windows systems or&#;x26;#;xc2;&#;x26;#;xa0;”root” on Linux systems. The knowledge of a default user account can help in brute force attacks. If the username is already known, only&#;x26;#;xc2;&#;x26;#;xa0;the password needs to be guessed. This shouldn&#;x26;#;39;t be too much of a problem to users as long as strong passwords are chosen&#;x26;#;xc2;&#;x26;#;xa0;or other authentication methods such as&#;x26;#;xc2;&#;x26;#;xa0;public key authentication is used. Setting up public key authentication is also referenced in our DShield setup instructions for a Raspberry Pi [2].&#;x26;#;xc2;&#;x26;#;xa0;
Continue reading Common usernames submitted to honeypots, (Tue, Sep 5th)→