Common usernames submitted to honeypots, (Tue, Sep 5th)

Based on reader feedback, I decided to take a&#;x26;#;xc2;&#;x26;#;xa0;look at usernames submitted to honeypots. The usernames that are seen on a daily basis look very familiar.&#;x26;#;xc2;&#;x26;#;xa0;They tend to come from default user accounts, such as “administrator” on Windows systems or&#;x26;#;xc2;&#;x26;#;xa0;”root” on Linux systems. The knowledge of a default user account can help in brute force attacks. If the username is already known, only&#;x26;#;xc2;&#;x26;#;xa0;the password needs to be guessed. This shouldn&#;x26;#;39;t be too much of a problem to users as long as strong passwords are chosen&#;x26;#;xc2;&#;x26;#;xa0;or other authentication methods such as&#;x26;#;xc2;&#;x26;#;xa0;public key authentication is used. Setting up public key authentication is also referenced in our DShield setup instructions for a Raspberry Pi [2].&#;x26;#;xc2;&#;x26;#;xa0;

Continue reading Common usernames submitted to honeypots, (Tue, Sep 5th)→

Posted in Uncategorized

What is the origin of passwords submitted to honeypots?, (Sat, Sep 2nd)

We use passwords just about everywhere in our daily lives. It&#;x26;#;39;s difficult to think of an online service where we don&#;x26;#;39;t have a need to enter some kind of credentials to access our content. DShield honeypots collect a variety of data, including passwords, that are submitted from SSH and telnet attacks.

Continue reading What is the origin of passwords submitted to honeypots?, (Sat, Sep 2nd)→

Posted in Uncategorized

The low, low cost of (committing) cybercrime, (Thu, Aug 31st)

Those of us who teach security awareness courses are often asked “Why would someone target ME?” or “Why would someone target OUR organization?”. Though these sentiments aren’t nearly as common as they used to be, since even mainstream media seem to cover cyber-attacks on at least a weekly basis, and – as a result – even non-IT specialists are becoming aware of the ubiquity of cyber-attacks, such questions still come up, both when teaching “regular” employees as well as when it comes to board-level security trainings.

Continue reading The low, low cost of (committing) cybercrime, (Thu, Aug 31st)→

Posted in Uncategorized