So today I come to you with a confession, I discovered one of my boxen had been successfully attacked and the attacker had by the looks of things used it for launching DDoS attacks. I feel particularly stupid because the entire thing was my fault, I left the root password as root. Although I must stress I didn’t set it to this, I was using a pre-build debian install because the d-i installer was broken under arm and forgot to change the root password to something a little more secure.
Disclaimer
All content on this site are my own thoughts and opinions not those of my employer or projects I contribute to.
Archives
- Months
- December 2008 (3)
- November 2008 (5)
- October 2008 (2)
- September 2008 (1)
- August 2008 (1)
- July 2008 (5)
- June 2008 (5)
- May 2008 (3)
- April 2008 (5)
- March 2008 (3)
- February 2008 (2)
- January 2008 (4)
- Years
- Months
You should send your logs files into “You’ve been owned”, maybe they will give you £250 for your public humiliation
Sorry, I couldn’t resist
Pingback: Chris’ Blog » Blog Archive » Blocking SSH Brute Force attempts using iptables