this post was submitted on 13 Mar 2024
1018 points (96.9% liked)
Memes
45619 readers
482 users here now
Rules:
- Be civil and nice.
- Try not to excessively repost, as a rule of thumb, wait at least 2 months to do it if you have to.
founded 5 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
I remember in college editing OpenSSH source code to instead of return wrong password to a root shell prompt just to stop brute force attacks
@Pacmanlives
Couldn't you just disable root login in the sshd config?
Oh all of my configs are deny root ssh login or without-password. I noticed a significant decrease in scans when returning a root prompt when I did that. This was also in the mid 2000s so who knows how things would be in this day in age for a reduction in scans
@Pacmanlives
So it was a fake root prompt which tricked the bots into believing that they logged in successfully but in reality the prompt could do nothing on the system?
Correct
But... arent they logged in as root then? Wdym with "prompt" i am lost
A honeypot!