Threat Level: green Handler on Duty: Yee Ching Tok

SANS ISC: SSH Password attacks using domain name elements as userid SANS ISC InfoSec Forums

Participate: Learn more about our honeypot network

Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!
SSH Password attacks using domain name elements as userid

A reader (Thanks Jim!) mentioned earlier today that his SSH logs were showing access attempts utilising elements of the reverse DNS name of the IP address being accessed.  For example using results in the userids isc, sans and org. This may be cause a number of hosting providers use the domain name itself as the userid for shell access for customers.  In light of the breach at dreamhost earlier this week this may be what is going on. 

If you are noticing the same in your logs and you can share some log lines please send some in as I'd be interested in taking a peek.

Mark H



392 Posts
ISC Handler
Jan 27th 2012
There has been some analysis of SSH Brute Force attacks by Steven J. Murdoch which identified the same trend of using domain name elements. The blog post covering the analysis of the usernames and passwords used are at and he may have raw log data he can share.


Sign Up for Free or Log In to start participating in the conversation!