|
|
|
|
|
by gighi
4425 days ago
|
|
Yes, I didn't put it in the article because it was getting too long otherwise, but the attacker immediately tried brute-forcing the root account, and after a handful of common passwords ("qwerty", "qwerty123", "pizza" among those) he found "password". I was able to find all the attempts by looking at the I/O activity of the sshd process, and also the syslog activity recorded every attempt. |
|